WorkThe story, in brief

n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails - The Hacker News

AI workflow platforms are becoming the new attack surface. n8n webhooks have been abused since October 2025 to deliver malware at scale.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

As AI automation tools become critical infrastructure for businesses, they're becoming prime targets for threat actors. This n8n campaign reveals a systemic vulnerability in how enterprises trust and integrate AI workflow platforms—a gap that will force security and procurement decisions across leadership teams.

The key facts

5 to know
  1. n8n webhooks abused since October 2025

  2. Attack vector: phishing emails + device fingerprinting

  3. Threat actors exploiting trusted webhook infrastructure

  4. Multiple security firms covering (Cisco Talos, SC Media, CyberSecurityNews)

  5. Malware delivery through workflow automation platform

Go to the source

Reuters Technologynews.google.com

Publisher excerpt: n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails The Hacker News The n8n n8mare: How threat actors are misusing AI workflow automation Cisco Talos Blog AI workflow platform n8n abused for phishing and device fingerprinting SC Media Malware Delivered Through Trusted…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work