Episode
What Happened to Black Basta's Playbook? The Automated Teams Phishing Threat Hitting Executives
- Published
- Apr 29, 2026
- Duration seconds
- 1596
- Processing state
not_requested
Actions
POST https://stenobird.com/v1/public/podcasts/shadowtalk-powered-by-reliaquest-61547/episodes/what-happened-to-black-basta-s-playbook-the-automated-teams-phishing-threat-hitting-executives/transcription-requests
Idempotently request low-priority transcript generation for this episode.GET https://stenobird.com/podcast/shadowtalk-powered-by-reliaquest-61547/what-happened-to-black-basta-s-playbook-the-automated-teams-phishing-threat-hitting-executives.md
Read the agent-friendly Markdown representation of this episode resource.
Summary
Black Basta disbanded in February 2025, but their playbook didn't go with them. In March 2026, 77% of observed incidents targeted executives and directors, and attackers moved from first contact to malicious script execution in as little as 12 minutes. The tactic has been automated, refined, and is now running faster than most SOCs can respond. Join hosts Alexandra and John as they discuss: How attackers leverage Microsoft Teams phishing to target high-privilege accounts with alarming s...