Filter
Exclude
Time range
-
Near
#timestamp - #yall now, so I book a reservation and I specifically did NOT enter this email! #cybersecurity #email #emailsecurity ***#iamvanessaguillen-MD who then investigated by sending an email to that address; it did NOT bounce back. @MarriottIntl @Marriott
2
1
23
Anyone can send an email that looks like it came from you. Same name, same address. DMARC is what stops them. Here is the 2 minute, no jargon version. Start free: trustyourinbox.com #DMARC #EmailSecurity #Phishing
2
38
That email looks legitimate. But is it? Watch this quick breakdown of Business Email Compromise (BEC) and learn why one email can lead to costly mistakes. #CyberSecurity #BEC #EmailSecurity
2
โฐ Gmail email expiration times: 1 day temporary 1 week default 5 years permanent linkedin.com/pulse/gmail-conโ€ฆ #Gmail #ConfidentialMode #EmailSecurity
8
โ€ผ๏ธ๐—ฃ๐—›๐—œ๐—ฆ๐—›๐—œ๐—ก๐—š ๐—”๐—Ÿ๐—˜๐—ฅ๐—ง โ€“ ๐—™๐—ฎ๐—ธ๐—ฒ ๐—ฅ๐—ผ๐—ด๐—ฒ๐—ฟ๐˜€ ๐—ฌ๐—ฎ๐—ต๐—ผ๐—ผ ๐— ๐—ฎ๐—ถ๐—น ๐—Ÿ๐—ผ๐—ด๐—ถ๐—ป ๐—ฃ๐—ผ๐—ฟ๐˜๐—ฎ๐—น ๐Ÿ‡จ๐Ÿ‡ฆ (Rogers Yahoo Mail is an email service provided to Rogers customers in Canada, offering webmail access for personal and business communications.) Fake URL: hxxps://rogersmembermal.weebly[.]com/ โš ๏ธ The website impersonates a Rogers Yahoo Mail login portal and is designed to trick users into entering their email account credentials. โš ๏ธ The phishing page mimics the appearance of a legitimate Rogers Yahoo Mail authentication interface, attempting to harvest usernames, email addresses, passwords, and potentially multi-factor authentication information. โš ๏ธ This appears to be a credential-harvesting phishing site targeting Rogers customers. Stolen credentials could provide attackers with access to email accounts, contacts, personal communications, password reset links, and other linked online services. โš ๏ธ Red Flags: โ€ข Hosted on weebly[.]com instead of an official Rogers or Yahoo domain โ€ข Uses Rogers and Yahoo branding without authorization โ€ข Requests email credentials through a third-party website โ€ข No verified association with Rogers Communications or Yahoo infrastructure โ€ข Hosted on a platform frequently abused for phishing campaigns โ€ข Uses a deceptive domain name containing โ€œrogersโ€, โ€œmemberโ€, and โ€œmailโ€ to appear legitimate โ€ข Designed to imitate a legitimate webmail login portal โš ๏ธ Do NOT enter: โ€ข Rogers email addresses โ€ข Usernames โ€ข Passwords โ€ข MFA / OTP verification codes โ€ข Recovery codes โ€ข Personal information ๐Ÿ›ก๏ธ If you entered your credentials: โ€ข Change your Rogers Yahoo Mail password immediately โ€ข Review recent account login activity โ€ข Revoke suspicious sessions and devices โ€ข Enable or verify Multi-Factor Authentication (MFA) โ€ข Check email forwarding and recovery settings for unauthorized changes โ€ข Monitor linked accounts for suspicious password reset attempts โš ๏ธ Email accounts are high-value targets because they can be used to reset passwords for banking, social media, cloud storage, and other online services. Hosting: 74.115.51.9 โ€” Weebly, Inc. USA ๐Ÿ‡บ๐Ÿ‡ธ #Phishing #Rogers #Yahoo #RogersYahoo #EmailSecurity #CredentialTheft #CyberSecurity #ScamAlert #ThreatIntel
85
โ€ผ๏ธ๐—ฃ๐—›๐—œ๐—ฆ๐—›๐—œ๐—ก๐—š ๐—”๐—Ÿ๐—˜๐—ฅ๐—ง โ€“ ๐—™๐—ฎ๐—ธ๐—ฒ ๐—ซ๐—ณ๐—ถ๐—ป๐—ถ๐˜๐˜† ๐—Ÿ๐—ผ๐—ด๐—ถ๐—ป ๐—ฃ๐—ผ๐—ฟ๐˜๐—ฎ๐—น ๐Ÿ‡บ๐Ÿ‡ธ (Xfinity, a brand of Comcast, provides internet, television, mobile, and email services to millions of customers across the United States.) Fake URL: hxxps://xfin1tysupp0rtmail.weebly[.]com/ โš ๏ธ The website impersonates an Xfinity account login portal and is designed to trick users into entering their account credentials. โš ๏ธ The phishing page mimics Xfinityโ€™s authentication interface and may target customers attempting to access their email, internet, billing, or account management services. โš ๏ธ The domain uses character substitution (xfin1ty and supp0rt) to resemble the legitimate Xfinity brand, a common phishing technique used to deceive users. โš ๏ธ This appears to be a credential-harvesting phishing site targeting Xfinity customers. Stolen credentials could provide attackers with access to email accounts, personal information, billing details, and linked services. โš ๏ธ Red Flags: โ€ข Hosted on weebly[.]com instead of an official Xfinity domain โ€ข Uses a typosquatted domain name (xfin1tysupp0rtmail) to imitate Xfinity โ€ข Uses Xfinity branding and login elements without authorization โ€ข Requests credentials through a third-party website โ€ข No verified association with Xfinity or Comcast infrastructure โ€ข Hosted on a platform frequently abused for phishing campaigns โ€ข Designed to imitate a legitimate Xfinity sign-in portal โš ๏ธ Do NOT enter: โ€ข Xfinity usernames โ€ข Email addresses โ€ข Passwords โ€ข MFA / OTP verification codes โ€ข Recovery codes โ€ข Billing or personal information ๐Ÿ›ก๏ธ If you entered your credentials: โ€ข Change your Xfinity password immediately โ€ข Review recent account login activity โ€ข Revoke suspicious sessions and devices โ€ข Enable or verify Multi-Factor Authentication (MFA) โ€ข Check email forwarding and recovery settings for unauthorized changes โ€ข Monitor billing and account activity for suspicious behavior โš ๏ธ Email and telecommunications accounts are valuable targets for cybercriminals because they can be used to facilitate account takeovers, intercept communications, and reset passwords for other online services. Hosting: 74.115.51.9 โ€” Weebly, Inc. USA ๐Ÿ‡บ๐Ÿ‡ธ #Phishing #Xfinity #Comcast #Webmail #EmailSecurity #CredentialTheft #CyberSecurity #ScamAlert #ThreatIntel
86
โ€ผ๏ธ๐—ฃ๐—›๐—œ๐—ฆ๐—›๐—œ๐—ก๐—š ๐—”๐—Ÿ๐—˜๐—ฅ๐—ง โ€“ ๐—™๐—ฎ๐—ธ๐—ฒ ๐—”๐—ง&๐—ง ๐—”๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜ ๐—Ÿ๐—ผ๐—ด๐—ถ๐—ป ๐—ฃ๐—ผ๐—ฟ๐˜๐—ฎ๐—น ๐Ÿ‡บ๐Ÿ‡ธ (AT&T is one of the largest telecommunications providers in the United States, offering mobile, internet, television, and email services to millions of customers.) Fake URL: hxxps://aloi-0a8j.weebly[.]com/ โš ๏ธ The website impersonates an AT&T account login portal and is designed to trick users into entering their account credentials. โš ๏ธ The phishing page mimics AT&Tโ€™s authentication interface and may target customers attempting to access email, wireless, internet, or account management services. โš ๏ธ This appears to be a credential-harvesting phishing site targeting AT&T customers. Stolen credentials could allow attackers to access customer accounts, personal information, billing details, and linked services. โš ๏ธ Red Flags: โ€ข Hosted on weebly[.]com instead of an official AT&T domain โ€ข Uses AT&T branding and login elements without authorization โ€ข Requests credentials through a third-party website โ€ข No verified association with AT&T infrastructure โ€ข Hosted on a platform frequently abused for phishing campaigns โ€ข Uses a randomly generated subdomain name โ€ข Designed to imitate a legitimate AT&T sign-in portal โš ๏ธ Do NOT enter: โ€ข AT&T usernames โ€ข Email addresses โ€ข Passwords โ€ข MFA / OTP verification codes โ€ข Recovery codes โ€ข Billing or personal information ๐Ÿ›ก๏ธ If you entered your credentials: โ€ข Change your AT&T password immediately โ€ข Review recent account login activity โ€ข Revoke suspicious sessions and devices โ€ข Enable or verify Multi-Factor Authentication (MFA) โ€ข Review account recovery settings for unauthorized changes โ€ข Monitor billing and account activity for suspicious behavior โš ๏ธ Telecommunications and email accounts are frequently targeted by phishing campaigns because they can provide access to sensitive communications, personal data, and additional online services. Hosting: 74.115.51.9 โ€” Weebly, Inc. USA ๐Ÿ‡บ๐Ÿ‡ธ #Phishing #EmailSecurity #CredentialTheft #CyberSecurity #ScamAlert #ThreatIntel #AccountTakeover
82
โ€ผ๏ธ๐—ฃ๐—›๐—œ๐—ฆ๐—›๐—œ๐—ก๐—š ๐—”๐—Ÿ๐—˜๐—ฅ๐—ง โ€“ ๐—™๐—ฎ๐—ธ๐—ฒ ๐— ๐—ฒ๐—ฑ๐—ถ๐—ฎ๐—ฐ๐—ผ๐—บ ๐—ช๐—ฒ๐—ฏ๐—บ๐—ฎ๐—ถ๐—น ๐—Ÿ๐—ผ๐—ด๐—ถ๐—ป ๐—ฃ๐—ผ๐—ฟ๐˜๐—ฎ๐—น ๐Ÿ“ง (Mediacom provides internet, communications, and webmail services to customers across the United States.) Fake URL: hxxps://fflmmppnj.weebly[.]com/ โš ๏ธ The website impersonates a Mediacom Webmail login portal and is designed to trick users into entering their email account credentials. โš ๏ธ The phishing page mimics a legitimate Mediacom email sign-in interface, attempting to harvest usernames, email addresses, and passwords from unsuspecting visitors. โš ๏ธ This appears to be a credential-harvesting phishing campaign targeting Mediacom customers. Stolen email credentials can be used to access sensitive communications, reset passwords for other services, and facilitate account takeover attacks. โš ๏ธ Red Flags: โ€ข Hosted on weebly[.]com instead of an official Mediacom domain โ€ข Uses Mediacom branding and login elements without authorization โ€ข Requests email credentials through a third-party website โ€ข No verified association with Mediacom infrastructure โ€ข Hosted on a platform frequently abused for phishing campaigns โ€ข Uses a randomly generated subdomain name โ€ข Designed to imitate a legitimate webmail login page โš ๏ธ Do NOT enter: โ€ข Email addresses โ€ข Usernames โ€ข Passwords โ€ข MFA / OTP verification codes โ€ข Recovery codes โ€ข Personal information ๐Ÿ›ก๏ธ If you entered your credentials: โ€ข Change your Mediacom email password immediately โ€ข Review recent login activity โ€ข Revoke suspicious sessions and devices โ€ข Enable Multi-Factor Authentication (MFA) if available โ€ข Check for unauthorized forwarding rules โ€ข Monitor linked accounts for suspicious password reset activity โš ๏ธ Email accounts are high-value targets because they often serve as the recovery method for banking, social media, cloud storage, and business accounts. Hosting: 74.115.51.9 โ€” Weebly, Inc. USA ๐Ÿ‡บ๐Ÿ‡ธ #Phishing #Mediacom #Webmail #EmailSecurity #CredentialTheft #CyberSecurity #ScamAlert #ThreatIntel #AccountTakeover #USA
68
โ€ผ๏ธ๐—ฃ๐—›๐—œ๐—ฆ๐—›๐—œ๐—ก๐—š ๐—”๐—Ÿ๐—˜๐—ฅ๐—ง โ€“ ๐—™๐—ฎ๐—ธ๐—ฒ ๐—ซ๐˜๐—ฟ๐—ฎ ๐— ๐—ฎ๐—ถ๐—น ๐—Ÿ๐—ผ๐—ด๐—ถ๐—ป ๐—ฃ๐—ผ๐—ฟ๐˜๐—ฎ๐—น ๐Ÿ‡ณ๐Ÿ‡ฟ (Xtra Mail is a popular email service used by customers in New Zealand for personal and business communications.) Fake URL: hxxps://ffhfsh.weebly[.]com/ โš ๏ธ The website impersonates an Xtra Mail login portal and attempts to trick users into entering their email account credentials. โš ๏ธ The phishing page mimics a legitimate webmail sign-in experience and is designed to harvest usernames, email addresses, and passwords from unsuspecting users. โš ๏ธ This appears to be a credential-harvesting phishing campaign targeting Xtra Mail customers. Compromised email accounts can be used to access sensitive communications, reset passwords for other services, and facilitate further fraud. โš ๏ธ Red Flags: โ€ข Hosted on weebly[.]com instead of an official Xtra Mail domain โ€ข Uses Xtra Mail branding and login themes without authorization โ€ข Requests credentials through a third-party website โ€ข No verified association with Xtra Mail infrastructure โ€ข Hosted on a platform frequently abused for phishing campaigns โ€ข Designed to imitate a legitimate email login portal โ€ข Likely intended for account takeover and credential theft โš ๏ธ Do NOT enter: โ€ข Email addresses โ€ข Usernames โ€ข Passwords โ€ข MFA / OTP verification codes โ€ข Recovery codes โ€ข Personal information ๐Ÿ›ก๏ธ If you entered your credentials: โ€ข Change your Xtra Mail password immediately โ€ข Review recent login activity โ€ข Revoke suspicious sessions and devices โ€ข Enable Multi-Factor Authentication (MFA) if available โ€ข Check for unauthorized forwarding rules โ€ข Monitor linked accounts for suspicious password reset activity โš ๏ธ Email accounts are a primary target for attackers because access to a mailbox can enable compromise of banking, social media, cloud storage, and other online services. Hosting: 74.115.51.8 โ€” Weebly, Inc. USA ๐Ÿ‡บ๐Ÿ‡ธ #Phishing #XtraMail #Webmail #EmailSecurity #CredentialTheft #CyberSecurity #ScamAlert #ThreatIntel #AccountTakeover #NewZealand
70
๐Ÿ’ก Tip: Be cautious with unexpected .js files in emails, especially those disguised as purchase orders! JS.MonoGlyphRAT uses social engineering to gain access, making it crucial to verify sources before opening attachments. #EmailSecurity #StaySafe
8
โ€ผ๏ธ๐—ฃ๐—›๐—œ๐—ฆ๐—›๐—œ๐—ก๐—š ๐—”๐—Ÿ๐—˜๐—ฅ๐—ง โ€“ ๐—™๐—ฎ๐—ธ๐—ฒ ๐—ข๐—ฝ๐˜๐˜‚๐˜€๐—ก๐—ฒ๐˜ ๐—˜๐—บ๐—ฎ๐—ถ๐—น ๐—Ÿ๐—ผ๐—ด๐—ถ๐—ป ๐—ฃ๐—ผ๐—ฟ๐˜๐—ฎ๐—น ๐Ÿ‡ฆ๐Ÿ‡บ (OptusNet is an Australian internet and email service provider used by Optus customers for webmail and communication services.) Fake URL: hxxps://oplus.toddsurvey[.]com/kosta/app/id.php?sessionId=5d310d8aeb38&userId=379211&scope=all&valid=true Hosting: 185.224.196.146 โ€” Iomart Cloud Services Limited (Easyspace Limited), Ireland ๐Ÿ‡ฎ๐Ÿ‡ช โš ๏ธ The website impersonates an OptusNet Webmail login page and prompts visitors to โ€œLog in to access your email,โ€ attempting to steal email account credentials. โš ๏ธ The page appears designed to mimic a legitimate OptusNet authentication portal while being hosted on an unrelated third-party domain. โš ๏ธ This appears to be a credential-harvesting phishing site targeting Optus customers. Stolen credentials could provide attackers with access to email accounts, contacts, personal information, and password reset messages for other online services. โš ๏ธ Red Flags: โ€ข Hosted on toddsurvey[.]com instead of an official Optus or OptusNet domain โ€ข Uses OptusNet branding and login themes without authorization โ€ข Requests email credentials through a non-Optus website โ€ข Contains tracking/session parameters to identify targeted victims โ€ข No verified association with Optus infrastructure โ€ข Designed to imitate a legitimate webmail login portal โ€ข Likely intended for account takeover and credential theft โš ๏ธ Do NOT enter: โ€ข Email addresses โ€ข Usernames โ€ข Passwords โ€ข MFA/OTP verification codes โ€ข Recovery codes โ€ข Personal information ๐Ÿ›ก๏ธ If you entered your credentials: โ€ข Change your OptusNet password immediately โ€ข Review recent login activity โ€ข Enable or verify Multi-Factor Authentication (MFA) โ€ข Check account recovery settings and forwarding rules โ€ข Revoke suspicious sessions and devices โ€ข Monitor linked accounts for unauthorized access attempts โš ๏ธ Email accounts are often targeted because they can be used to reset passwords for banking, social media, cloud storage, and other critical services. #Phishing #Optus #OptusNet #Webmail #EmailSecurity #CredentialTheft #CyberSecurity #ScamAlert #ThreatIntel
60
โ€ผ๏ธ๐—ฃ๐—›๐—œ๐—ฆ๐—›๐—œ๐—ก๐—š ๐—”๐—Ÿ๐—˜๐—ฅ๐—ง โ€“ ๐—™๐—ฎ๐—ธ๐—ฒ ๐—ฌ๐—ฎ๐—ต๐—ผ๐—ผ ๐— ๐—ฎ๐—ถ๐—น ๐—Ÿ๐—ผ๐—ด๐—ถ๐—ป ๐—ฃ๐—ผ๐—ฟ๐˜๐—ฎ๐—น ๐ŸŒ (Yahoo Mail is one of the worldโ€™s most widely used email services, providing webmail access to millions of users globally.) Fake URL: hxxps://poijngh.weebly[.]com/ โš ๏ธ The website impersonates a Yahoo Mail login portal and is designed to trick users into entering their email account credentials. โš ๏ธ The phishing page mimics Yahooโ€™s authentication interface, attempting to harvest usernames, email addresses, passwords, and potentially multi-factor authentication information. โš ๏ธ This appears to be a credential-harvesting phishing site targeting Yahoo Mail users. Stolen credentials could provide attackers with access to emails, contacts, personal information, password reset links, and other linked online services. โš ๏ธ Red Flags: โ€ข Hosted on weebly[.]com instead of an official Yahoo domain โ€ข Uses Yahoo branding and login elements without authorization โ€ข Requests account credentials through a non-Yahoo URL โ€ข No verified association with Yahoo infrastructure โ€ข Hosted on a website-building platform frequently abused for phishing campaigns โ€ข Designed to imitate a legitimate Yahoo Mail sign-in page โš ๏ธ Do NOT enter: โ€ข Yahoo email addresses โ€ข Usernames โ€ข Passwords โ€ข MFA / OTP verification codes โ€ข Recovery codes โ€ข Personal information ๐Ÿ›ก๏ธ If you entered your credentials: โ€ข Change your Yahoo password immediately โ€ข Review recent account login activity โ€ข Revoke suspicious sessions and devices โ€ข Enable or verify Multi-Factor Authentication (MFA) โ€ข Check account recovery settings and email forwarding rules โ€ข Monitor linked accounts for suspicious password reset activity โš ๏ธ Email accounts are high-value targets because they can be used to reset passwords for other services and facilitate account takeover attacks. Hosting: 74.115.51.8 โ€” Weebly, Inc., USA ๐Ÿ‡บ๐Ÿ‡ธ #Phishing #YahooMail #Yahoo #EmailSecurity #CredentialTheft #CyberSecurity #ScamAlert #ThreatIntel #AccountTakeover
86
Recognition earned through innovation and persistence @Zoho Mail secures the SE Labs UK Security Award, highlighting excellence in enterprise email protection and trusted technology. ๐Ÿš€ #Zoho #ZohoMail #CyberSecurity #EmailSecurity #TechInnovation #EnterpriseTech #scoopearth
10
๐Ÿšจ Business Email Compromise (BEC) is one of the most costly cyber threats today. โœ… Verify requests โœ… Train employees โœ… Secure email systems ๐ŸŒ threatmatrix.co.uk ๐Ÿ“ง info@threatmatrix.co.uk #CyberSecurity #BEC #EmailSecurity #ThreatMatrix #CyberAwareness
4
Jun 12
๐Ÿšจ New ZeroBEC research: LX RAT is now appearing in a highly active ITR refund phishing campaign. The chain: phishing email โ†’ compromised redirector โ†’ Dropbox ZIP โ†’ AutoIt loader โ†’ sandbox evasion โ†’ persistence โ†’ LX RAT. Multiple leading SEGs were evaded. Research with @BhalgamaVedant . Full writeup: zerobec.com/blog/lx-rat-itr-โ€ฆ #EmailSecurity #ThreatIntel #Phishing #LXrat #MalwareResearch
3
1
223
Domain reputation is not enough. Content and behavioural analysis is where detection lives. Encrypted in. Encrypted out. Nothing kept in the middle. #PhishingBrief #ThreatIntel #DeviceCodePhishing #EvilTokens #EmailSecurity #InfoSec #SoEmailSecurity
6
The compliance questions hitting MSP clients are arriving earlier and from more directions than they used to. Cyber insurers want outbound controls documented at renewal. Healthcare clients are watching HIPAA enforcement climb on unauthorized disclosure. Financial-services examiners are asking how customer data is protected in transit. State privacy laws are now active in 20 states, with three more switched on this January. For years the honest MSP answer was some mix of native tooling and a third-party encryption tool stood up client-by-client. Neither is a service line. Both create work every time a client onboards or offboards. That math has finally changed. IRONSCALES Email Encryption was built for the multi-tenant model, so encryption fires by policy, logs the supervisory record an auditor or carrier will ask for, and opens cleanly for the recipient with one-time passcode access. No portal account. No password reset. No help-desk ticket. Learn more: hubs.la/Q04l4wVS0 #MSP #EmailSecurity #Compliance #EmailEncryption
1
2
18
Cleaner inboxes. Less spam. Easier email management. Thank you for the kind words, Eric. ๐Ÿ‘‰ spamhero.com #spamhero #testimonial #emailsecurity #cybersecurity
21