logo

A Voicemail That Never Rang: How Attackers Chained Three ESPs to Launder Email Authentication

ID: 0bb7da3b-828c-50f4-af76-b10b2e1c72a3

STIX ID: report--0bb7da3b-828c-50f4-af76-b10b2e1c72a3

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: [email protected] (Audian Paxson)

...
...

This report describes a high-severity phishing campaign that impersonated a K‑12 staff member and used a chain of legitimate email services (SendGrid for delivery, Mailchimp for click-tracking, and ActiveCampaign Pages for the credential-harvesting landing page) to pass SPF/DKIM checks while evading DMARC alignment due to the victim domain's p=none policy; IOCs, MITRE ATT&CK mappings, and actionable mitigations are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.