Loading market data...

Phishing Campaign Hits 885,000 Phone Numbers, Rapid7 Warns

Phishing Campaign Hits 885,000 Phone Numbers, Rapid7 Warns

Cybersecurity firm Rapid7 has uncovered a phishing campaign that targets 885,000 phone numbers, redirecting victims to fake wallet provider websites in an attempt to steal their cryptocurrency holdings. The campaign, disclosed this week, appears to be a broad sweep rather than a precise strike — casting a wide net across a massive phone list.

How the scam works

According to Rapid7, the attackers send messages to the targeted phone numbers, luring recipients to spoofed wallet sites that mimic legitimate providers. Once a victim lands on one of these pages and enters their credentials or seed phrase, the funds are gone. The scale of the phone number list is notable — nearly a million potential entry points for a single campaign.

Why 885,000 phone numbers

Phone-based phishing, sometimes called smishing, isn't new, but the size of this list stands out. Rapid7 didn't specify how the numbers were gathered, but a list that large suggests either a data breach or a purchased marketing database that got repurposed. For investors, the practical takeaway is blunt: don't click wallet links sent via text.

What investors should do

Rapid7's advice is straightforward — always navigate to wallet providers by typing the URL directly or using a saved bookmark, never through a link in a message. Anyone who receives a suspicious text should report it to their carrier and the wallet provider. The campaign is ongoing, and the affected phone numbers are already out there.

The firm hasn't said how many victims have fallen for the trap, or whether any specific wallet providers are being impersonated. That leaves a lingering question: how many of those 885,000 people will click before the campaign runs its course.