logo

Nordstrom's email system abused to send crypto scams to customers

ID: dfa14383-1e67-5bbd-9a7f-bb821bdf53d5

STIX ID: report--dfa14383-1e67-5bbd-9a7f-bb821bdf53d5

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2026-03-18

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive summary:** Customers of Nordstrom received fraudulent St. Patrick’s Day emails sent from an official [email protected] address promising to double crypto deposits; the company warned the messages were unauthorized and reporting ties the incident to an Okta SSO compromise leading to misuse of Salesforce Marketing Cloud, with attackers collecting ~ $5,600 in cryptocurrency so far.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.