logo

NetSuite Sent the Invoice. Oracle Signed It. The Payment Token Was the Weapon.

ID: b45c5555-8abc-5fcb-a924-4543b0c58378

STIX ID: report--b45c5555-8abc-5fcb-a924-4543b0c58378

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-06-07

Date Updated: 2026-06-07

Author: [email protected] (Audian Paxson)

...
...

An invoice-phishing campaign abused Oracle NetSuite/Oracle Email Delivery to send fully authenticated invoice emails linking to a legitimate QIMA payment portal pre-filled with a payment token; SPF/DKIM/DMARC all passed so behavioral analysis (Themis/IRONSCALES) flagged and quarantined four mailboxes, leaving open whether the NetSuite account was compromised or the invoice was fabricated within the platform.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.