logo

New DHL Phishing Scam Uses 11-Step Attack Chain to Steal Passwords

ID: c117b600-66e2-50ab-8f4d-23278083023f

STIX ID: report--c117b600-66e2-50ab-8f4d-23278083023f

Feed Name: HackRead

Threat Score
50/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Deeba Ahmed

...
...

Forcepoint X‑Labs discovered a phishing campaign impersonating DHL that lures victims with a spoofed waybill email, uses a fake OTP trick (locally generated six‑digit code) to build trust, then pre‑fills and captures credentials on a fake DHL login page. The kit also collects device telemetry and geolocation, exfiltrates the data via the EmailJS service to [email protected], and finally redirects victims to the real DHL site to avoid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.