logo

A SendGrid Phish, Signed by SendGrid, on a 15-Minute Domain

ID: d1c2c0e5-ca6a-5d74-a624-f4b23a593564

STIX ID: report--d1c2c0e5-ca6a-5d74-a624-f4b23a593564

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-08-11

Date Updated: 2026-08-11

Author: [email protected] (Audian Paxson)

...
...

A phishing credential-harvesting message impersonating a SendGrid subscription receipt was genuinely relayed and signed by SendGrid infrastructure so authentication passed; the malicious call-to-action resolved to a typosquatted domain (myconnsend-grid.com) registered 15 minutes 40 seconds before delivery and scanned as Clean because it had no history. Detection hinged on non-authentication signals: a syntactically invalid From header (noreply@sendgrid with no TLD), generic billing copy with no account details, first-time sender status, and behavioral scoring (Themis 86% credential theft), and the incident was automatically resolved as phishing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.