logo

When Threat Actors Don’t Have a Viable Email Platform to Phish From, They Just Steal Yours

ID: d129fe1e-332a-534e-a24a-22a06173446c

STIX ID: report--d129fe1e-332a-534e-a24a-22a06173446c

Feed Name: KnowBe4 Blog

Threat Score
60/100

Date Published: 2024-02-28

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

The report details a phishing campaign dubbed "phishception" in which attackers impersonate SendGrid to hijack SendGrid customer accounts and then leverage the platform's legitimate sending reputation to distribute further phishing; attackers also use JSPen serverless pages to host dynamic phishing content and to probe MFA, increasing success and evasion. The write-up emphasizes user vigilance—scrutinizing sender addresses, email content, and destination URLs—and security awareness training as primary mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.