Proofpoint phishing palaver plagues millions with 'perfectly spoofed' emails from IBM, Nike, Disney, others
ID: b4747533-e2ad-598a-b320-3ad3fe81ebb5
STIX ID: report--b4747533-e2ad-598a-b320-3ad3fe81ebb5
Feed Name: The Register (Security)
Guardio identified a large-scale phishing campaign called EchoSpoof that exploited an insecure-by-default Proofpoint Microsoft 365 routing feature to relay spoofed emails that carried valid SPF and DKIM for major brands (Disney, IBM, Nike, Best Buy, Coca-Cola). Running January–June and peaking at about 14 million messages in 24 hours (average ~3M/day), the campaign used OVH-hosted virtual servers and PowerMTA to phish users for credit card details; Proofpoint and Guardio mitigated the issue after notification but many abusive Microsoft tenants remained active at publication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
