The Childcare App That Passed Every Security Check (The Reply-To Header Didn't)
ID: ee5f0d2f-59c1-5a1c-949d-2d926ea871a7
STIX ID: report--ee5f0d2f-59c1-5a1c-949d-2d926ea871a7
Feed Name: IRONSCALES
Threat Score
**Executive summary:** Attackers abused Brightwheel's legitimate email-sending infrastructure to deliver authenticated billing notifications to school staff that passed SPF/DKIM/DMARC but used an attacker-controlled Reply-To ([email protected]) to intercept replies and enable BEC-style social engineering; detection relied on behavioral signals such as display-name/address mismatches and a failed personalization token.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
