logo

The Reply-To Was One Letter Off: How a Typosquat Domain Turned a Gmail BEC Into a Payment Diversion

ID: 63b94efd-841b-56d3-b1a2-88cc7376296f

STIX ID: report--63b94efd-841b-56d3-b1a2-88cc7376296f

Feed Name: IRONSCALES

Threat Score
65/100

Date Published: 2026-05-16

Date Updated: 2026-05-16

Author: [email protected] (Audian Paxson)

...
...

A targeted invoice‑fraud phishing email impersonated a steel distributor credit manager: the message was sent from a legitimate Gmail path (SPF/DKIM/DMARC passed) but used a typosquatted Reply‑To domain (mill‑steels.com) to redirect responses to the attacker. The signature included real company links and a displayed employee name while the underlying mailto href pointed to a different account, revealing an incomplete copy of a legitimate signature; the email requested confirmation of updated banking details (payment diversion) and was quarantined after behavioral detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.