logo

When 'Release from Quarantine' Is the Attack

ID: eb8971dc-0a36-5d5f-9266-3a3e4ca38387

STIX ID: report--eb8971dc-0a36-5d5f-9266-3a3e4ca38387

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-03-27

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

The report details a high-risk phishing campaign impersonating email quarantine digests from serverdata.net: attackers sent messages with JWT-bearing "Allow"/"Manage" action links pointing to co.quarantine.serverdata.net while displaying legitimate-looking email addresses, enabling credential harvesting across multiple organizations and evading simple detection via realistic domain/authentication signals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.