Three Domains, One Invoice: The Payment Diversion That Authenticated Itself Through the Wrong Organization
ID: aed8ccc5-9ec4-5349-b8f1-163a56af3082
STIX ID: report--aed8ccc5-9ec4-5349-b8f1-163a56af3082
Feed Name: IRONSCALES
A Business Email Compromise (BEC) invoice-fraud campaign impersonated a clinical-research contact via display-name spoofing while sending from an attacker-controlled, authenticated domain ([email protected]). Replies were routed to a throwaway domain ([email protected]) and payment instructions directed to a mail-only domain ([email protected]); a SendGrid tracking pixel indicated active delivery monitoring. The report includes IOCs and MITRE technique mappings and notes that SPF/DKIM/DMARC passed for the attacker-owned sending domain, illustrating how authentication can be abused to lend credibility to payment diversion scams.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
