Every Auth Check Passed, and There Was No Link to Scan
ID: 2ce546b2-8dc2-50b8-82c1-d9d70a59f3d6
STIX ID: report--2ce546b2-8dc2-50b8-82c1-d9d70a59f3d6
Feed Name: IRONSCALES
A targeted BEC/phishing-for-information campaign used genuine tenant-generated helpdesk notifications (SPF/DMARC passing, DKIM absent) to send reply-only requests for vendor IDs, invoice numbers with amounts, partial bank digits and PO details to accounts payable staff. Because there was no link, attachment or credential page, reputation, sandbox and attachment-based controls could not detect the malicious ask; the document details behavioral indicators, MITRE mappings (T1598, T1656), and recommends out-of-band verification, vendor master change controls, and relationship-context detection to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
