logo

Three Domains, One CEO: How a Payroll Group BEC Used Mailjet to Bypass Every Filter

ID: b38b0926-2280-5a3e-85b0-1b2036ce1b25

STIX ID: report--b38b0926-2280-5a3e-85b0-1b2036ce1b25

Feed Name: IRONSCALES

Threat Score
72/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

A targeted Business Email Compromise attack impersonated the organization’s CEO to request fraudulent payroll bank changes; the attacker used three separate domains (sending via mycomparateur.fr authenticated through Mailjet, a reply-capture domain exceeo.com, and the CEO’s name in the display field) and enabled Mailjet tracking. Although SPF and DKIM validated the sending domain, behavioral detection flagged the mismatch between the display name and actual sending infrastructure and quarantined the message before payroll could act.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.