Perfect Authentication, Borrowed From a Real Mailbox
ID: 822d0066-d269-526c-87d2-f78ae5ee3619
STIX ID: report--822d0066-d269-526c-87d2-f78ae5ee3619
Feed Name: IRONSCALES
A real employee mailbox at a utility company was apparently taken over and used to send authenticated phishing emails (SPF/DKIM/DMARC/ARC passed) to two mailboxes in mid-July 2026; the message promised a payment summary attachment but contained only a link to engastando.us/hmtl, which presents a human-verification gate that blocks automated scanners and is assessed as a credential-harvesting lure. The report provides IoCs (domain, URLs, subject, sender pattern), analysis of why authentication controls were bypassed by account takeover, and mitigation guidance to treat sender identity and payload independently.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
