Hackers Exploit Legitimate Apple and PayPal Invoice Emails in DKIM Replay Attacks
ID: d8258590-403e-5ba6-aa9f-565f69dd802a
STIX ID: report--d8258590-403e-5ba6-aa9f-565f69dd802a
Feed Name: cybersecurityNews.com
The report details DKIM replay attacks in which fraudsters create legitimate vendor invoices or dispute notifications (e.g., PayPal, App Store) that receive valid DKIM signatures, then forward those signed emails to many victims containing fraudulent support phone numbers in seller notes; because the messages are legitimately signed, they bypass DMARC/DMARC-aligned filters and land in inboxes, enabling large-scale financial social-engineering fraud. The article describes the attack mechanics, shows examples, cites Kaseya analysts' findings, and recommends defensive measures such as inspecting the envelope recipient versus the visible "To" header and verifying invoices via official portals rather than following contact details in emails.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
