Identity, phishing and impersonation
Campaigns that seek credentials, divert payments or pressure a person into acting.
- Lookalike domains
- MFA fatigue
- Executive fraud
The Observatory follows digital threats that may affect citizens, non-profits, schools and small organisations in Belgium. It collects lawful open sources, adds context, states uncertainty and publishes understandable measures.
IBCSC is an independent non-profit, not the national CSIRT. It conducts no covert surveillance, criminal investigation or access to a system without authorisation.An address, screenshot or technical identifier is not enough. The analysis must establish what was observed, who may be affected and which action is reasonable.
A domain, URL, vulnerability, message or observed behaviour.
The data is dated, sourced, deduplicated and linked to a technical context.
Relevance, possible impact, exposure, confidence and urgency are separated.
A preventive measure, check, update or referral is proposed.
The Observatory does not try to cover everything. It focuses its resources on mechanisms frequently encountered by citizens and organisations with limited means.
Campaigns that seek credentials, divert payments or pressure a person into acting.
Vendor advisories, referenced vulnerabilities and public configurations that may require an update or reduced exposure.
Infection chains, attachments, loaders, encryption, data theft and signs useful for prevention.
Events that may disrupt a website, email or essential service, without speculating about who caused them.
Risks introduced by a provider, library, cloud dependency or poorly controlled third-party access.
Use of AI to scale phishing, imitate an identity, fabricate content or bypass instructions.
The process follows the logic of the ENISA Cybersecurity Threat Landscape methodology, adapted to the Institute’s citizen mission and resources.
Define the question, audience, expected decision and what remains out of scope.
Gather only sources that are necessary, lawfully accessible and relevant to the question.
Date, normalise, deduplicate, classify and preserve useful references.
Compare sources, seek contradictions and assess impact, exposure and confidence.
Choose the format, audience, level of detail and appropriate sharing restrictions.
Correct, enrich, expire or withdraw information as new observations arrive.
An alert is not considered final by default. It must be possible to correct, re-date or withdraw it when the context changes.
Source reliability and confidence in the analysis are different. The Observatory explains why a level was selected and what is still missing.
A signal exists, but its scope, cause or authenticity is not yet sufficiently corroborated.
Several independent elements converge and the risk mechanism is reasonably established.
An official source, the relevant vendor or direct evidence confirms the essential facts.
The patch is deployed, infrastructure has disappeared or new evidence contradicts the assessment.
No source is reliable by nature. Its competence, proximity to the event, track record and whether its claims can be checked are considered.
CCB, CERT.be, Safeonweb, CERT-EU, ENISA and other competent public bodies.
Confirmation and referralSecurity bulletins, release notes, remediation advisories and vendor CVD policies.
Product impact and patchEUVD, CVE and other references used to identify products, versions and records.
Normalisation and trackingResearch publications, sector CSIRTs, professional associations and documented technical analysis.
Context and corroborationVoluntarily shared messages, public websites, articles and observations available without intrusion.
Initial detectionThe level of detail depends on the audience. A citizen needs observable signs and immediate action; an organisation also needs versions, exposure and ownership.
An urgent signal presented without unnecessary detail or speculative attribution.
A structured explanation of a campaign, fraud mechanism or technique.
A summary that helps decide whether an update or compensating control is needed.
A cross-cutting view of observed signals without turning every occurrence into a general statistic.
Limited sharing when defensive details should not be made public.
IBCSC can explain and guide. Official channels remain the priority when a message is suspicious, an incident is ongoing or a vulnerability must be disclosed.
Forward suspicious emails to suspicious@safeonweb.be. Safeonweb also explains how to recognise fake messages.
Read the instructionsOrganisations experiencing a cyber incident can use the official form or contact the national CSIRT under the stated conditions.
Report an incidentResearch and reporting must remain necessary, proportionate and compliant with Belgian coordinated disclosure conditions.
Read the CVD procedureIf a person is in immediate danger, contact the competent emergency services. Do not send a password, private key or full copy of personal data in an ordinary report.
The Observatory works within a preventive and analytical framework. Intrusive methods, mass collection and premature publication would increase risk instead of reducing it.
IBCSC seeks partners able to provide a source, sector context, expertise or a clearly governed distribution channel.
Propose cooperationThese resources guide the work. Mentioning them does not imply affiliation or endorsement of IBCSC by the organisations concerned.
Read the published analysis or report a situation to IBCSC for initial guidance. For an incident, suspicious message or vulnerability, use the official channels above first.