logo

She Clicked the Bid Invitation and Handed Her Credentials to a Netlify Phishing Page

ID: d0b0a89e-9b7f-5c77-b0fd-3ce1e884f152

STIX ID: report--d0b0a89e-9b7f-5c77-b0fd-3ce1e884f152

Feed Name: IRONSCALES

Threat Score
75/100

Date Published: 2026-03-26

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

Attackers leveraged a compromised Microsoft 365 account at a legitimate Canadian construction firm to send authentic-looking procurement emails that redirected recipients to a Netlify-hosted ConstructConnect sign-in impersonation for credential harvesting; IRONSCALES' Adaptive AI detected href-display mismatches, landing-page behavior, and sender anomalies and quarantined affected mailboxes before clicks occurred.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.