Proofpoint settings exploited to send millions of phishing emails daily
ID: ecc3ddca-cbf6-5436-8594-7b03d3831cfd
STIX ID: report--ecc3ddca-cbf6-5436-8594-7b03d3831cfd
Feed Name: Bleeping Computer
Guardio Labs discovered a massive phishing campaign called EchoSpoofing (Jan–Jun 2024) that exploited overly permissive Proofpoint Microsoft 365 relay configurations to send millions of DKIM/SPF-signed spoofed emails impersonating major brands to Fortune 100 targets; attackers used compromised/rogue Office 365 accounts, external VPS infrastructure, and permissive SPF includes to bypass filters until Proofpoint tightened settings and introduced additional anti-spoofing headers and onboarding controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
