logo

Nespresso Domain Serves Up Steamy Cup of Phish, No Cream or Sugar

ID: 578c4fe7-0eab-5f14-8950-b45888571847

STIX ID: report--578c4fe7-0eab-5f14-8950-b45888571847

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2024-04-22

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

A phishing campaign is exploiting an open-redirect vulnerability on Nespresso's legitimate website to deliver a malicious HTML page mimicking a Microsoft login and harvest credentials via spoofed Bank of America emails; attackers rely on the trusted domain to evade security tools that inspect only initial links, and researchers reported the redirect remained unpatched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.