logo

The Subdomain That Fused Two Trusted Brands Into One Convincing Lie

ID: 15c0bbc6-ea18-555e-8438-5bfdcdc8d6b3

STIX ID: report--15c0bbc6-ea18-555e-8438-5bfdcdc8d6b3

Feed Name: IRONSCALES

Threat Score
72/100

Date Published: 2026-04-13

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

Attackers provisioned a subdomain under Zix's secureemailportal.com (fidelityusa.secureemailportal.com) to send authenticated-looking spearphishing messages to a community bank's business banking inbox, leveraging Zix's DKIM/SPF/DMARC reputation while directing replies to an attacker-controlled domain (fidelity-usa.com); behavioral detection of sender/Reply-To divergence flagged and quarantined the messages before credential harvesting succeeded.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.