logo

The 11-Step Trap: How a Fake DHL OTP Trick Steals Your Password

ID: 01dbe20f-8b04-5ae2-b9b4-d4be33896e41

STIX ID: report--01dbe20f-8b04-5ae2-b9b4-d4be33896e41

Feed Name: securityonline.info

Threat Score
50/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Ddos

...
...

Forcepoint X‑Labs discovered a consumer-focused phishing campaign impersonating DHL that guides victims through a staged 11-step flow: a spoofed shipment email (with DKIM for the attacker domain), a locally generated “parcel-themed” OTP to build trust, and a pre-filled DHL-branded login page to harvest credentials and device telemetry. Stolen data is sent via EmailJS to an attacker mailbox and victims are redirected to the legitimate DHL site to avoid immediate detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.