logo

Three Domains, One Invoice: The Payment Diversion That Authenticated Itself Through the Wrong Organization

ID: aed8ccc5-9ec4-5349-b8f1-163a56af3082

STIX ID: report--aed8ccc5-9ec4-5349-b8f1-163a56af3082

Feed Name: IRONSCALES

Threat Score
75/100

Date Published: 2026-04-18

Date Updated: 2026-06-04

Author: [email protected] (Audian Paxson)

...
...

A Business Email Compromise (BEC) invoice-fraud campaign impersonated a clinical-research contact via display-name spoofing while sending from an attacker-controlled, authenticated domain ([email protected]). Replies were routed to a throwaway domain ([email protected]) and payment instructions directed to a mail-only domain ([email protected]); a SendGrid tracking pixel indicated active delivery monitoring. The report includes IOCs and MITRE technique mappings and notes that SPF/DKIM/DMARC passed for the attacker-owned sending domain, illustrating how authentication can be abused to lend credibility to payment diversion scams.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.