logo

The FedEx Email That Salesforce Authenticated and Qualtrics Delivered: Data Harvesting Through Three Layers of Trust

ID: 5f7dd801-d276-59d7-b138-19797bd721cb

STIX ID: report--5f7dd801-d276-59d7-b138-19797bd721cb

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

Author: [email protected] (Audian Paxson)

...
...

A spearphishing campaign impersonated FedEx by sending fully authenticated emails via Salesforce MTA with Qualtrics survey links requesting non-public shipment and contact details; all technical signals (SPF/DKIM/DMARC and URL scans) appeared legitimate, but social-engineering cues—unverifiable contact addresses, minor localization errors, and a hard deadline—indicate a data-harvesting operation designed to bypass standard gateway detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.