logo

A Real Intuit Notification Link, Then a 7-Day-Old Domain

ID: 46ec23b5-6c6e-5ee2-9e56-434c449d6f51

STIX ID: report--46ec23b5-6c6e-5ee2-9e56-434c449d6f51

Feed Name: IRONSCALES

Threat Score
75/100

Date Published: 2026-08-22

Date Updated: 2026-08-22

Author: [email protected] (Audian Paxson)

...
...

A targeted credential-harvest phishing email used a single-button document-share template that resolved through a legitimate Intuit notification/click-tracking host and then forwarded to an attacker-controlled domain (account-maildocuments-xsaas.icu) registered seven days earlier; authentication passed but behavioral signals (single-action template, mismatched content, young terminal domain) triggered detection and four mailboxes were quarantined.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.