Disney, Nike, IBM Signatures Anchor 3M Fake Emails a Day
ID: af44f041-e98a-5024-8188-e5715cc93bc9
STIX ID: report--af44f041-e98a-5024-8188-e5715cc93bc9
Feed Name: Dark Reading
Researchers uncovered the EchoSpoofing campaign (Jan–mid‑2024) in which attackers sent millions of near‑undetectable phishing emails by forging sender headers on a private SMTP server and relaying them through Microsoft 365 to Proofpoint Secure Email Gateway customers that had a permissive setting enabled; Proofpoint later implemented fixes (including a vendor-specific outgoing header and stricter Office365 restrictions) which largely stopped the campaign, but the incident highlights risks from misconfigurations, the scale of brand‑impersonation scams, and the potential for more targeted spearphishing using similar flaws.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
