She Clicked the Bid Invitation and Handed Her Credentials to a Netlify Phishing Page
ID: d0b0a89e-9b7f-5c77-b0fd-3ce1e884f152
STIX ID: report--d0b0a89e-9b7f-5c77-b0fd-3ce1e884f152
Feed Name: IRONSCALES
Threat Score
Attackers leveraged a compromised Microsoft 365 account at a legitimate Canadian construction firm to send authentic-looking procurement emails that redirected recipients to a Netlify-hosted ConstructConnect sign-in impersonation for credential harvesting; IRONSCALES' Adaptive AI detected href-display mismatches, landing-page behavior, and sender anomalies and quarantined affected mailboxes before clicks occurred.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
