logo

Stop Phishing Yourself: How Auto-Forwarding and Exchange Contacts Can Stab You in the Back

ID: ad31a333-cfc5-56c0-8d68-25237b6bcebc

STIX ID: report--ad31a333-cfc5-56c0-8d68-25237b6bcebc

Feed Name: Black Hills Infosec Blog

Threat Score
40/100

Date Published: 2023-09-21

Date Updated: 2026-04-27

Author: BHIS

...
...

This report details a phishing campaign where spoofed marketing emails, initially quarantined by O365 as phishing, were inadvertently forwarded to a Jira project via an Exchange Contact on an internal distribution list, resulting in Jira tickets containing malicious attachments (a credential-harvesting HTML). The SOC detected and removed the tickets the same day and implemented detections and a safer email-to-ticket configuration, with no evidence of user interaction or successful compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.