logo

The Government Email That Authenticated Itself After Transit

ID: a9542fae-5ad3-5344-9e15-749d20fd0a00

STIX ID: report--a9542fae-5ad3-5344-9e15-749d20fd0a00

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: [email protected] (Audian Paxson)

...
...

A compromised Pierce County Microsoft 365 account distributed a password-protected PDF (passcode included in the email body) that evaded automated scanners; Microsoft outbound signing caused SPF/DKIM/DMARC to pass at the receiver while the ARC seal showed cv=fail (authentication laundering). IRONSCALES flagged the behavior and quarantined four mailboxes; the report provides IOCs and MITRE ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.