DKIM and DMARC Passed. The $97,500 Wire Was Fraud.
ID: 6ba5011d-a395-5178-8f34-c476635c936b
STIX ID: report--6ba5011d-a395-5178-8f34-c476635c936b
Feed Name: IRONSCALES
Threat Score
**Executive summary:** A business-email-compromise attack used a legitimately signed email (DKIM/DMARC pass via the organization's SendGrid stream) to deliver a fraudulent invoice demanding a same-day $97,500 wire; the fraud hinged on a mismatched Reply-To ([email protected]), a SendGrid tracking pixel for live-target confirmation, forged metadata to appear internal, and an urgent discount to coerce payment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
