logo

Proofpoint settings exploited to send millions of phishing emails daily

ID: ecc3ddca-cbf6-5436-8594-7b03d3831cfd

STIX ID: report--ecc3ddca-cbf6-5436-8594-7b03d3831cfd

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-07-29

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Guardio Labs discovered a massive phishing campaign called EchoSpoofing (Jan–Jun 2024) that exploited overly permissive Proofpoint Microsoft 365 relay configurations to send millions of DKIM/SPF-signed spoofed emails impersonating major brands to Fortune 100 targets; attackers used compromised/rogue Office 365 accounts, external VPS infrastructure, and permissive SPF includes to bypass filters until Proofpoint tightened settings and introduced additional anti-spoofing headers and onboarding controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.