logo

The Childcare App That Passed Every Security Check (The Reply-To Header Didn't)

ID: ee5f0d2f-59c1-5a1c-949d-2d926ea871a7

STIX ID: report--ee5f0d2f-59c1-5a1c-949d-2d926ea871a7

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-04-14

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

**Executive summary:** Attackers abused Brightwheel's legitimate email-sending infrastructure to deliver authenticated billing notifications to school staff that passed SPF/DKIM/DMARC but used an attacker-controlled Reply-To ([email protected]) to intercept replies and enable BEC-style social engineering; detection relied on behavioral signals such as display-name/address mismatches and a failed personalization token.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.