logo

One Missing Letter, One Stolen Payment: A Reply-To Typosquat That Beat the Spam Score

ID: 5fc2a0d1-5717-504b-8ed5-bffc1a216245

STIX ID: report--5fc2a0d1-5717-504b-8ed5-bffc1a216245

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-04-21

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

An April 2026 invoice payment diversion (BEC) attempt used a one-letter typosquat Reply-To domain (leadsavingsofmissuori[.]com vs. leadsavingsofmissouri[.]com) plus an embedded malicious "Contact Us" link to redirect payment correspondence to attacker-controlled infrastructure; Microsoft assigned SCL=8 yet the message delivered until IRONSCALES' behavioral AI (Themis) detected the Reply-To mismatch and quarantined the email, illustrating how reputation-based filters and tenant allowlists can enable high-impact financial fraud despite high spam scores.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.