The LinkedIn Invoice That Passed Every Email Check
ID: 02c4c522-eccd-598d-accf-3c1412885c32
STIX ID: report--02c4c522-eccd-598d-accf-3c1412885c32
Feed Name: IRONSCALES
**Executive summary:** A high-risk Business Email Compromise campaign used a lookalike domain (linkedinreceivables-mail.com) registered days earlier and properly configured with SPF/DKIM/DMARC to pass email authentication; a minimalist one-line invoice query was sent to accounts-payable to initiate payment diversion, backed by attacker-controlled tracking subdomains and a UK-based relay IP, demonstrating that authentication alone does not prove sender legitimacy and recommending behavioral detection, monitoring of newly registered domains, and AP training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
