Incident report: how a phishing campaign revealed BEC before exploitation
ID: 8fec6576-3a16-5862-bd25-9f52748e9f2b
STIX ID: report--8fec6576-3a16-5862-bd25-9f52748e9f2b
Feed Name: Expel Blog
Date Published: 2022-09-07
Date Updated: 2026-04-27
Author: Ben Soloway; Tyler Wood; David Oviatt; Harold Harding
Expel analysts triaged a large phishing campaign using Jotform-hosted fake document review pages and a browser extension that bookmarked and opened a credential harvester. Multiple submission alerts (89 reported) were aggregated, and sandboxing revealed credentials were posted to a newly created Canadian domain; Workbench and Defender ATP queries confirmed network submissions for two users and an Azure AD risky sign-in. The incident was escalated, customers were notified, credentials were reset, malicious domains and senders were blocked, and the case highlights the speed attackers move from credential theft to attempted access and the value of layered detection and automation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
