logo

Perfect Authentication, Borrowed From a Real Mailbox

ID: 822d0066-d269-526c-87d2-f78ae5ee3619

STIX ID: report--822d0066-d269-526c-87d2-f78ae5ee3619

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: [email protected] (Audian Paxson)

...
...

A real employee mailbox at a utility company was apparently taken over and used to send authenticated phishing emails (SPF/DKIM/DMARC/ARC passed) to two mailboxes in mid-July 2026; the message promised a payment summary attachment but contained only a link to engastando.us/hmtl, which presents a human-verification gate that blocks automated scanners and is assessed as a credential-harvesting lure. The report provides IoCs (domain, URLs, subject, sender pattern), analysis of why authentication controls were bypassed by account takeover, and mitigation guidance to treat sender identity and payload independently.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.