logo

The LinkedIn Invoice That Passed Every Email Check

ID: 02c4c522-eccd-598d-accf-3c1412885c32

STIX ID: report--02c4c522-eccd-598d-accf-3c1412885c32

Feed Name: IRONSCALES

Threat Score
72/100

Date Published: 2026-03-25

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

**Executive summary:** A high-risk Business Email Compromise campaign used a lookalike domain (linkedinreceivables-mail.com) registered days earlier and properly configured with SPF/DKIM/DMARC to pass email authentication; a minimalist one-line invoice query was sent to accounts-payable to initiate payment diversion, backed by attacker-controlled tracking subdomains and a UK-based relay IP, demonstrating that authentication alone does not prove sender legitimacy and recommending behavioral detection, monitoring of newly registered domains, and AP training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.