logo

Proofpoint phishing palaver plagues millions with 'perfectly spoofed' emails from IBM, Nike, Disney, others

ID: b4747533-e2ad-598a-b320-3ad3fe81ebb5

STIX ID: report--b4747533-e2ad-598a-b320-3ad3fe81ebb5

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-07-30

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Guardio identified a large-scale phishing campaign called EchoSpoof that exploited an insecure-by-default Proofpoint Microsoft 365 routing feature to relay spoofed emails that carried valid SPF and DKIM for major brands (Disney, IBM, Nike, Best Buy, Coca-Cola). Running January–June and peaking at about 14 million messages in 24 hours (average ~3M/day), the campaign used OVH-hosted virtual servers and PowerMTA to phish users for credit card details; Proofpoint and Guardio mitigated the issue after notification but many abusive Microsoft tenants remained active at publication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.