Two-Stage Bank Scam Splits the Link to Starve Scanners
ID: 14766b02-72c2-5fae-b4dd-6e3ae3dd8444
STIX ID: report--14766b02-72c2-5fae-b4dd-6e3ae3dd8444
Feed Name: IRONSCALES
Threat Score
This high-severity BEC phishing incident used a legitimate ServiceNow outbound mailbox to send a split-delivery email asking a supplier for bank documents and promising a follow-up link; the first email contained no links or attachments so a legacy gateway scored it clean, but behavioral detection identified the pattern (first-time external sender, high-value financial request, instruction to expect a separate message) and quarantined it before the second-stage payload arrived.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
