logo

The Phishing Link That Started at Google.com and Ended at a Fake Disney+ Login

ID: ec8f254a-812f-5b11-a8f2-e1fe715eadf7

STIX ID: report--ec8f254a-812f-5b11-a8f2-e1fe715eadf7

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: [email protected] (Audian Paxson)

...
...

A phishing email used a Google redirect wrapper, an is.gd short link, and an Azure Front Door subdomain to serve a Disney+-branded credential-harvest page, deliberately laundering trust through widely trusted infrastructure so reputation-only URL filters never reached the malicious terminal host; IRONSCALES expanded the full redirect chain, identified the credential-harvest page, and provides IOCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.