logo

Two-Stage Bank Scam Splits the Link to Starve Scanners

ID: 14766b02-72c2-5fae-b4dd-6e3ae3dd8444

STIX ID: report--14766b02-72c2-5fae-b4dd-6e3ae3dd8444

Feed Name: IRONSCALES

Threat Score
75/100

Date Published: 2026-07-29

Date Updated: 2026-07-29

Author: [email protected] (Audian Paxson)

...
...

This high-severity BEC phishing incident used a legitimate ServiceNow outbound mailbox to send a split-delivery email asking a supplier for bank documents and promising a follow-up link; the first email contained no links or attachments so a legacy gateway scored it clean, but behavioral detection identified the pattern (first-time external sender, high-value financial request, instruction to expect a separate message) and quarantined it before the second-stage payload arrived.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.