Hackers Exploit n8n Workflow Automation Platform for Phishing Attacks
n8n is a workflow automation platform that integrates with Slack, GitHub, Google Sheets and AI models. It also offers free developer accounts and cloud-based webhooks. Hackers can exploit its trusted SaaS domains to deliver content and evade conventional email filters, turning enterprise automation workflows into a new cybersecurity vulnerability.
Cisco Talos disclosed on April 15, 2026, that the attacks ran from at least October 2025 through March 2026. In March, malicious emails containing n8n webhook URLs surged by about 686% compared with January 2025. The attackers impersonated OneDrive notifications, deployed tampered Datto or ITarian remote monitoring and management tools to control computers, and used tracking pixels to collect device-identifying data.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.