logo

Perfect Authentication, Zero Payload: The Yahoo Free-Mail BEC That Microsoft Flagged but Didn't Block

ID: 83d35305-6767-563d-9845-c896cda85ed7

STIX ID: report--83d35305-6767-563d-9845-c896cda85ed7

Feed Name: IRONSCALES

Threat Score
65/100

Date Published: 2026-05-09

Date Updated: 2026-05-11

Author: [email protected] (Audian Paxson)

...
...

**Executive summary:** A threat actor sent a zero-payload phishing email from [email protected] using a display name that matched a known internal contact to elicit account-change details; SPF/DKIM/DMARC passed (compauth=100), Microsoft generated an impersonation safety tip (SFTY:9.25) but delivered the message, and Themis flagged it at 68% confidence—one mailbox was quarantined and the report confirmed phishing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.