One Missing Letter, One Stolen Payment: A Reply-To Typosquat That Beat the Spam Score
ID: 5fc2a0d1-5717-504b-8ed5-bffc1a216245
STIX ID: report--5fc2a0d1-5717-504b-8ed5-bffc1a216245
Feed Name: IRONSCALES
An April 2026 invoice payment diversion (BEC) attempt used a one-letter typosquat Reply-To domain (leadsavingsofmissuori[.]com vs. leadsavingsofmissouri[.]com) plus an embedded malicious "Contact Us" link to redirect payment correspondence to attacker-controlled infrastructure; Microsoft assigned SCL=8 yet the message delivered until IRONSCALES' behavioral AI (Themis) detected the Reply-To mismatch and quarantined the email, illustrating how reputation-based filters and tenant allowlists can enable high-impact financial fraud despite high spam scores.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
