logo

Fake Google 'Open to Edit' Alert Hides a Kajabi Redirect and Targeted Credential Harvest

ID: 64d26352-7b7a-56f2-96e9-2073ef369a4d

STIX ID: report--64d26352-7b7a-56f2-96e9-2073ef369a4d

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-03-25

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

**Phishing campaign using platform laundering:** A Google Docs-style spearphishing email was sent from a likely compromised UK healthcare domain (SPF/DMARC passing) and routed users through Kajabi email redirects that contained a base64-encoded recipient email in the URL fragment, enabling targeted credential harvesting; IOCs and detection recommendations are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.