logo

One Dell Order, Two Companies, One Signature

ID: 49fe38e7-336d-5e32-af76-546b3d02222b

STIX ID: report--49fe38e7-336d-5e32-af76-546b3d02222b

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-09-18

Date Updated: 2026-09-18

Author: [email protected] (Audian Paxson)

...
...

A real Dell order acknowledgement was weaponised: attacker-controlled Microsoft 365 tenants submitted orders that Dell legitimately rendered and signed, then relayed the identical signed message through different second-hop tenants to multiple unrelated organisations. Because the vendor signature and headers remained intact, standard authentication (DKIM/DMARC/SPF) validated the message despite the signed recipient field revealing the message was not intended for the recipient; the only actionable content was a phone number embedded in address fields (callback phishing).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.