The FedEx Email That Salesforce Authenticated and Qualtrics Delivered: Data Harvesting Through Three Layers of Trust
ID: 5f7dd801-d276-59d7-b138-19797bd721cb
STIX ID: report--5f7dd801-d276-59d7-b138-19797bd721cb
Feed Name: IRONSCALES
Threat Score
A spearphishing campaign impersonated FedEx by sending fully authenticated emails via Salesforce MTA with Qualtrics survey links requesting non-public shipment and contact details; all technical signals (SPF/DKIM/DMARC and URL scans) appeared legitimate, but social-engineering cues—unverifiable contact addresses, minor localization errors, and a hard deadline—indicate a data-harvesting operation designed to bypass standard gateway detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
