logo

IRONSCALES

ID: a731b6e8-ffcd-5d5b-96fc-d8192e5f9035

STIX ID: identity--a731b6e8-ffcd-5d5b-96fc-d8192e5f9035

Feed Type: rss

Earliest post: 2026-03-21

Latest post: 2026-05-29

IRONSCALES Threat Intelligence is an email-security-focused research hub that publishes analyses of real-world phishing, BEC, credential theft, and other email-based attacks, along with the tactics behind them.

01/01/2020
05/30/2026
Title Date Published Describes IncidentAuthorVisible
The $47,320 Invoice That Came With a W-9 and a Personal Bank Account2026-05-29True[email protected] (Audian Paxson)True
The Collections Notice From a Fortune 500 Lab: Compromised Thermo Fisher Account via Oracle Cloud Relay2026-05-28True[email protected] (Audian Paxson)True
The Contract Email That Wasn't Spelled the Way You Think: Unicode Homoglyphs, a QR Code, and a Marketing Gateway2026-05-27True[email protected] (Audian Paxson)True
The Zoho Sign Request That Passed Every Check Except the Reply-To: Government Impersonation via E-Sign Infrastructure2026-05-26True[email protected] (Audian Paxson)True
The FedEx Email That Salesforce Authenticated and Qualtrics Delivered: Data Harvesting Through Three Layers of Trust2026-05-25True[email protected] (Audian Paxson)True
The SOC Alert That Came From a Compromised FinTech: An Authenticated BlueVine Sender Delivering a Typosquat Link Buried in Operational Context2026-05-24True[email protected] (Audian Paxson)True
The Datadog Alert That Came From the Wrong Domain: Authenticated Brand Impersonation With All Links Pointing to Real Infrastructure2026-05-23True[email protected] (Audian Paxson)True
The Warranty Form With a Windows Executable Hidden Inside a GIF2026-05-21True[email protected] (Audian Paxson)True
The SharePoint Share That Passed Every Check: A Compromised M365 Tenant With DMARC Reject and Tokenized Links2026-05-20True[email protected] (Audian Paxson)True
The Webinar Invite That Came With an Apple Wallet Pass and a Three-Hop Redirect Chain2026-05-19True[email protected] (Audian Paxson)True
The Spreadsheet That Arrived Twice: CR/LF Filename Obfuscation and a Base64 Shadow Payload2026-05-18True[email protected] (Audian Paxson)True
The Bank Statement You Had to Unlock With Your Birthday: PII-Gated PDF Evasion From Authenticated Infrastructure2026-05-17True[email protected] (Audian Paxson)True
The Reply-To Was One Letter Off: How a Typosquat Domain Turned a Gmail BEC Into a Payment Diversion2026-05-16True[email protected] (Audian Paxson)True
Amazon Said You Owe $879. The Phone Number Was the Payload.2026-05-15True[email protected] (Audian Paxson)True
The .com That Wasn't the .org: TLD Confusion in a Payroll Email With an Empty Body2026-05-14True[email protected] (Audian Paxson)True
The Spreadsheet With No Macros and One Hidden Link: External Relationships in Office XML2026-05-13True[email protected] (Audian Paxson)True
A School Email That Passed Authentication Twice, Then Changed: Post-Signing Content Injection via Compromised .sch.uk Domain2026-05-12True[email protected] (Audian Paxson)True
The Teams Invite That Came From the Wrong Domain: Display-Name Impersonation With All-Legitimate Links2026-05-11True[email protected] (Audian Paxson)True
The .pro Domain That Built a Perfect M365 Tenant Just to Send One Google Docs Link2026-05-10True[email protected] (Audian Paxson)True
Perfect Authentication, Zero Payload: The Yahoo Free-Mail BEC That Microsoft Flagged but Didn't Block2026-05-09True[email protected] (Audian Paxson)True
The Government Email That Authenticated Itself After Transit2026-05-08True[email protected] (Audian Paxson)True
The PayPal Invoice That Passed Every Check Because PayPal Actually Sent It2026-05-07True[email protected] (Audian Paxson)True
A Generic Extortion Template, a Mailgun Relay, and a Domain Registered to Look Legitimate2026-05-06True[email protected] (Audian Paxson)True
The Unsubscribe Button Was the Payload: How a Fake Health Email Weaponized Opt-Out Compliance2026-05-05True[email protected] (Audian Paxson)True
A Fully Authenticated Bank Alert Hides Its Payload in a Phone Number2026-05-04True[email protected] (Audian Paxson)True
The Security Tool That Delivered the $48,500 Invoice Fraud2026-05-03True[email protected] (Audian Paxson)True
When Google Is the Phishing Infrastructure: Authenticated Credential Harvesting via Search Console2026-05-02True[email protected] (Audian Paxson)True
Insurance Claim PDF Hides JavaScript Behind AcroForm Fields and SendGrid Redirects2026-05-01True[email protected] (Audian Paxson)True
DocuSign Plus Invoice: A 12-Day-Old Domain and an esvalabs Redirect Chain That Scanners Missed2026-04-30True[email protected] (Audian Paxson)True
3 Messages on Hold: How an Authenticated Australian Domain Posed as a Security Center2026-04-29True[email protected] (Audian Paxson)True
Three Domains, One CEO: How a Payroll Group BEC Used Mailjet to Bypass Every Filter2026-04-28True[email protected] (Audian Paxson)True
RE: Christopher: How a Thread Hijack Rode Salesforce Marketing Cloud Into the Inbox2026-04-27True[email protected] (Audian Paxson)True
DocuSign Phish Weaponizes Google Maps as a Redirect Proxy to Amazon S32026-04-26True[email protected] (Audian Paxson)True
When the Phishing Kit Ships Early: Exposed Template Variables Reveal Attack Infrastructure2026-04-25True[email protected] (Audian Paxson)True
The Attachment Inside the Attachment: How Nested RFC822 Messages Evade Parser-Based Detection2026-04-24True[email protected] (Audian Paxson)True
Hungarian Bank, Nepali Domain, Broken Encoding: How a K&H Bank Phishing Kit Exposed Itself2026-04-23True[email protected] (Audian Paxson)True
Sign Here, Get Phished: Inside an Adobe Sign Lure With a Multi-Hop Redirect to Credential Theft2026-04-22True[email protected] (Audian Paxson)True
One Missing Letter, One Stolen Payment: A Reply-To Typosquat That Beat the Spam Score2026-04-21True[email protected] (Audian Paxson)True
The URL That Put adobe.com in the Wrong Place2026-04-20True[email protected] (Audian Paxson)True
The Zoho Invoice That Was Four Months Late (And Kept Its Receipts on Google Drive)2026-04-19True[email protected] (Audian Paxson)True
The PDF Scanner Couldn't Open the Attachment (But the Victim Could)2026-04-18True[email protected] (Audian Paxson)True
An Encrypted Attachment, an Empty Body, and a Scanner That Couldn't Look Inside2026-04-17True[email protected] (Audian Paxson)True
The DocuSign That Lived on an S3 Bucket (and Couldn't Decide Who Sent It)2026-04-16True[email protected] (Audian Paxson)True
Past Due Invoice, Future Wire Fraud: How a BEC Campaign Passed Every Authentication Check2026-04-16True[email protected] (Audian Paxson)True
The Childcare App That Passed Every Security Check (The Reply-To Header Didn't)2026-04-14True[email protected] (Audian Paxson)True
The Subdomain That Fused Two Trusted Brands Into One Convincing Lie2026-04-13True[email protected] (Audian Paxson)True
The Password Expiry Email That Hid Its Destination in a Base64 Fragment2026-04-12True[email protected] (Audian Paxson)True
Purpose-Built Look-Alike Sending Domain Passes Full Authentication to Impersonate Training Brand2026-04-11True[email protected] (Audian Paxson)True
The Timestamp That Gave It Away: Oracle Identity Cloud Phishing Targets K-12 with a Stale Timezone2026-04-10True[email protected] (Audian Paxson)True
The GitLab Alert That Passed Every Filter (Except One Detail Nobody Checked)2026-04-09True[email protected] (Audian Paxson)True

1–50 of 91