logo

The Audit Request That Passed Every Authentication Check: How a Compromised Nonprofit Account Weaponized URL Shorteners

ID: 03cf1689-3722-5606-b068-d4b02b7e4c96

STIX ID: report--03cf1689-3722-5606-b068-d4b02b7e4c96

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-03-24

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

A compromised nonprofit Microsoft 365 email account was used to inject a qrco.de shortener URL into a legitimate audit thread to harvest credentials and facilitate BEC; authentication checks (SPF/DKIM/DMARC/ARC) passed because the message originated from the real infrastructure, but behavioral AI and community intelligence detected the shortener-based quishing evasion and quarantined affected mailboxes. Indicators (malicious short URL, sender email, header anomalies, DKIM selector) and mitigation guidance are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.