logo

A Fully Authenticated Bank Alert Hides Its Payload in a Phone Number

ID: c84a9c3e-293f-5704-b667-a72dbb92479b

STIX ID: report--c84a9c3e-293f-5704-b667-a72dbb92479b

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-05-04

Date Updated: 2026-05-11

Author: [email protected] (Audian Paxson)

...
...

A high-severity phishing campaign impersonated a major U.S. bank's password-change notification and bypassed SPF/DKIM/DMARC and Microsoft compauth=100 by using a callback phone number as the sole malicious vector; IRONSCALES detected it through behavioral signals (first-time sender, cross-mailbox hits, urgency/action mismatch). The report includes IoCs (sender address [email protected], phone (866) 475-0729, sending IP 205.220.177.171, X-Mailer 'Fifth Third Notification System'), maps the attack to MITRE techniques (vishing and phishing for information), and recommends treating callback numbers as untrusted, flagging first-time automated senders, correlating across mailboxes, user vishing training, and deploying behavioral detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.