What Happened to Black Basta's Playbook? The Automated Teams Phishing Threat Hitting Executives episode artwork

EPISODE · Apr 29, 2026 · 26 MIN

What Happened to Black Basta's Playbook? The Automated Teams Phishing Threat Hitting Executives

from ShadowTalk: Powered by ReliaQuest · host ReliaQuest

Black Basta disbanded in February 2025, but their playbook didn't go with them. In March 2026, 77% of observed incidents targeted executives and directors, and attackers moved from first contact to malicious script execution in as little as 12 minutes. The tactic has been automated, refined, and is now running faster than most SOCs can respond. Join hosts Alexandra and John as they discuss:How attackers leverage Microsoft Teams phishing to target high-privilege accounts with alarming speedWhy automation is compressing attack timelines and sharpening target selectionThe controls that can stop it, from help desk verification to automated containment workflows Two questions your organization should be asking right now:When IT requests remote access to a senior leader's endpoint, is identity verified through a channel separate from the one the request came from?Do your highest-privilege accounts have dedicated automated containment workflows — or are they the gap in your response playbook?Resources: https://linktr.ee/ReliaQuestShadowTalkJohn Dilgen: Cyber Threat Intelligence Analyst at ReliaQuest, where he specializes in researching cyber threats impacting ReliaQuest customers. With a strong technical background, he previously served as an Incident Response Analyst and Trainer at ReliaQuest.Alexandra Moore: Manager of Threat Intelligence at ReliaQuest, where she leads intelligence analysis and customer dissemination to help organizations understand and respond to emerging cyber threats. Prior to this, she established and scaled monitoring across Russian-language cybercriminal platforms at Digital Shadows, building collection and analytical coverage to support digital risk protection capabilities.

Episode metadata supplied by the publisher feed · Published Apr 29, 2026

Embed this episode

Black Basta disbanded in February 2025, but their playbook didn't go with them. In March 2026, 77% of observed incidents targeted executives and directors, and attackers moved from first contact to malicious script execution in as little as 12 minutes. The tactic has been automated, refined, and is now running faster than most SOCs can respond. Join hosts Alexandra and John as they discuss: How attackers leverage Microsoft Teams phishing to target high-privilege accounts with alarming s...

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

What Happened to Black Basta's Playbook? The Automated Teams Phishing Threat Hitting Executives

0:00 26:36

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of ShadowTalk: Powered by ReliaQuest?

This episode is 26 minutes long.

When was this ShadowTalk: Powered by ReliaQuest episode published?

This episode was published on April 29, 2026.

Can I download this ShadowTalk: Powered by ReliaQuest episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!