logo

Salesforce infrastructure abuse: Stopping email scams and spam sent via SFDC · Blog · Sublime Security

ID: 8ec0e9cd-5a96-5f9d-aa75-54e498a84537

STIX ID: report--8ec0e9cd-5a96-5f9d-aa75-54e498a84537

Feed Name: Sublime Security Blog

Threat Score
65/100

Date Published: 2025-11-21

Date Updated: 2026-05-01

...
...

Sublime's Attack Spotlight details multiple, active email campaigns that leverage legitimate Salesforce infrastructure to conduct spam, credential- and callback-phishing, and crypto wallet theft (including impersonation, redirect chains through Salesforce and free hosting like Cloudflare pages, and phishy CTAs). The report presents example messages, recurring signals (infrastructure abuse, redirects to free pages, brand impersonation, urgency, generic greetings), and the detection signals and AI-driven mitigations used to block these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.