logo

No Links. No Attachments. No Malware. Just Five Sentences That Almost Started a Wire Fraud.

ID: f9281494-e5e7-5d79-9e56-2eb43bf51dda

STIX ID: report--f9281494-e5e7-5d79-9e56-2eb43bf51dda

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-03-21

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

A targeted BEC attack impersonating the CEO used a five-sentence, zero-payload email from a properly authenticated Zoho-hosted lookalike domain to request moving the conversation to a messaging app (an off-channel pivot); the message contained no links or attachments and passed SPF/DKIM/DMARC but was detected and auto-quarantined by IRONSCALES' behavioral AI. The report highlights the attack's reliance on social engineering rather than technical artifacts, maps the behavior to MITRE techniques (Internal Spearphishing, Impersonation, Phishing for Information), and recommends identity-aware detection, display-name checks, verification of off-channel requests, and inclusion of zero-payload scenarios in phishing simulations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.