logo

The Zoho Invoice That Was Four Months Late (And Kept Its Receipts on Google Drive)

ID: a229db59-fe05-5a58-b1d6-949a746191ac

STIX ID: report--a229db59-fe05-5a58-b1d6-949a746191ac

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-04-19

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

A targeted phishing email impersonating a Zoho Books invoice for a drone services vendor arrived months after its invoice date; while the payment button pointed to legitimate Zoho payment infrastructure, an anomalous Google Drive folder link included below the invoice is identified as the likely credential-harvesting payload. The message showed authentication degradation after transiting a Barracuda gateway (SPF softfail, DKIM fail, DMARC fail) and was flagged by Themis/IRONSCALES based on correlated behavioral and authentication anomalies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.