Anyone can send an email that looks like it came from you. Same name, same address.
DMARC is what stops them. Here is the 2 minute, no jargon version.
Start free: trustyourinbox.com#DMARC#EmailSecurity#Phishing
That email looks legitimate. But is it?
Watch this quick breakdown of Business Email Compromise (BEC) and learn why one email can lead to costly mistakes.
#CyberSecurity#BEC#EmailSecurity
โผ๏ธ๐ฃ๐๐๐ฆ๐๐๐ก๐ ๐๐๐๐ฅ๐ง โ ๐๐ฎ๐ธ๐ฒ ๐ฅ๐ผ๐ด๐ฒ๐ฟ๐ ๐ฌ๐ฎ๐ต๐ผ๐ผ ๐ ๐ฎ๐ถ๐น ๐๐ผ๐ด๐ถ๐ป ๐ฃ๐ผ๐ฟ๐๐ฎ๐น ๐จ๐ฆ
(Rogers Yahoo Mail is an email service provided to Rogers customers in Canada, offering webmail access for personal and business communications.)
Fake URL: hxxps://rogersmembermal.weebly[.]com/
โ ๏ธ The website impersonates a Rogers Yahoo Mail login portal and is designed to trick users into entering their email account credentials.
โ ๏ธ The phishing page mimics the appearance of a legitimate Rogers Yahoo Mail authentication interface, attempting to harvest usernames, email addresses, passwords, and potentially multi-factor authentication information.
โ ๏ธ This appears to be a credential-harvesting phishing site targeting Rogers customers. Stolen credentials could provide attackers with access to email accounts, contacts, personal communications, password reset links, and other linked online services.
โ ๏ธ Red Flags:
โข Hosted on weebly[.]com instead of an official Rogers or Yahoo domain
โข Uses Rogers and Yahoo branding without authorization
โข Requests email credentials through a third-party website
โข No verified association with Rogers Communications or Yahoo infrastructure
โข Hosted on a platform frequently abused for phishing campaigns
โข Uses a deceptive domain name containing โrogersโ, โmemberโ, and โmailโ to appear legitimate
โข Designed to imitate a legitimate webmail login portal
โ ๏ธ Do NOT enter:
โข Rogers email addresses
โข Usernames
โข Passwords
โข MFA / OTP verification codes
โข Recovery codes
โข Personal information
๐ก๏ธ If you entered your credentials:
โข Change your Rogers Yahoo Mail password immediately
โข Review recent account login activity
โข Revoke suspicious sessions and devices
โข Enable or verify Multi-Factor Authentication (MFA)
โข Check email forwarding and recovery settings for unauthorized changes
โข Monitor linked accounts for suspicious password reset attempts
โ ๏ธ Email accounts are high-value targets because they can be used to reset passwords for banking, social media, cloud storage, and other online services.
Hosting: 74.115.51.9 โ Weebly, Inc. USA ๐บ๐ธ
#Phishing#Rogers#Yahoo#RogersYahoo#EmailSecurity#CredentialTheft#CyberSecurity#ScamAlert#ThreatIntel
โผ๏ธ๐ฃ๐๐๐ฆ๐๐๐ก๐ ๐๐๐๐ฅ๐ง โ ๐๐ฎ๐ธ๐ฒ ๐ซ๐ณ๐ถ๐ป๐ถ๐๐ ๐๐ผ๐ด๐ถ๐ป ๐ฃ๐ผ๐ฟ๐๐ฎ๐น ๐บ๐ธ
(Xfinity, a brand of Comcast, provides internet, television, mobile, and email services to millions of customers across the United States.)
Fake URL: hxxps://xfin1tysupp0rtmail.weebly[.]com/
โ ๏ธ The website impersonates an Xfinity account login portal and is designed to trick users into entering their account credentials.
โ ๏ธ The phishing page mimics Xfinityโs authentication interface and may target customers attempting to access their email, internet, billing, or account management services.
โ ๏ธ The domain uses character substitution (xfin1ty and supp0rt) to resemble the legitimate Xfinity brand, a common phishing technique used to deceive users.
โ ๏ธ This appears to be a credential-harvesting phishing site targeting Xfinity customers. Stolen credentials could provide attackers with access to email accounts, personal information, billing details, and linked services.
โ ๏ธ Red Flags:
โข Hosted on weebly[.]com instead of an official Xfinity domain
โข Uses a typosquatted domain name (xfin1tysupp0rtmail) to imitate Xfinity
โข Uses Xfinity branding and login elements without authorization
โข Requests credentials through a third-party website
โข No verified association with Xfinity or Comcast infrastructure
โข Hosted on a platform frequently abused for phishing campaigns
โข Designed to imitate a legitimate Xfinity sign-in portal
โ ๏ธ Do NOT enter:
โข Xfinity usernames
โข Email addresses
โข Passwords
โข MFA / OTP verification codes
โข Recovery codes
โข Billing or personal information
๐ก๏ธ If you entered your credentials:
โข Change your Xfinity password immediately
โข Review recent account login activity
โข Revoke suspicious sessions and devices
โข Enable or verify Multi-Factor Authentication (MFA)
โข Check email forwarding and recovery settings for unauthorized changes
โข Monitor billing and account activity for suspicious behavior
โ ๏ธ Email and telecommunications accounts are valuable targets for cybercriminals because they can be used to facilitate account takeovers, intercept communications, and reset passwords for other online services.
Hosting: 74.115.51.9 โ Weebly, Inc. USA ๐บ๐ธ
#Phishing#Xfinity#Comcast#Webmail#EmailSecurity#CredentialTheft#CyberSecurity#ScamAlert#ThreatIntel
โผ๏ธ๐ฃ๐๐๐ฆ๐๐๐ก๐ ๐๐๐๐ฅ๐ง โ ๐๐ฎ๐ธ๐ฒ ๐๐ง&๐ง ๐๐ฐ๐ฐ๐ผ๐๐ป๐ ๐๐ผ๐ด๐ถ๐ป ๐ฃ๐ผ๐ฟ๐๐ฎ๐น ๐บ๐ธ
(AT&T is one of the largest telecommunications providers in the United States, offering mobile, internet, television, and email services to millions of customers.)
Fake URL: hxxps://aloi-0a8j.weebly[.]com/
โ ๏ธ The website impersonates an AT&T account login portal and is designed to trick users into entering their account credentials.
โ ๏ธ The phishing page mimics AT&Tโs authentication interface and may target customers attempting to access email, wireless, internet, or account management services.
โ ๏ธ This appears to be a credential-harvesting phishing site targeting AT&T customers. Stolen credentials could allow attackers to access customer accounts, personal information, billing details, and linked services.
โ ๏ธ Red Flags:
โข Hosted on weebly[.]com instead of an official AT&T domain
โข Uses AT&T branding and login elements without authorization
โข Requests credentials through a third-party website
โข No verified association with AT&T infrastructure
โข Hosted on a platform frequently abused for phishing campaigns
โข Uses a randomly generated subdomain name
โข Designed to imitate a legitimate AT&T sign-in portal
โ ๏ธ Do NOT enter:
โข AT&T usernames
โข Email addresses
โข Passwords
โข MFA / OTP verification codes
โข Recovery codes
โข Billing or personal information
๐ก๏ธ If you entered your credentials:
โข Change your AT&T password immediately
โข Review recent account login activity
โข Revoke suspicious sessions and devices
โข Enable or verify Multi-Factor Authentication (MFA)
โข Review account recovery settings for unauthorized changes
โข Monitor billing and account activity for suspicious behavior
โ ๏ธ Telecommunications and email accounts are frequently targeted by phishing campaigns because they can provide access to sensitive communications, personal data, and additional online services.
Hosting: 74.115.51.9 โ Weebly, Inc. USA ๐บ๐ธ
#Phishing#EmailSecurity#CredentialTheft#CyberSecurity#ScamAlert#ThreatIntel#AccountTakeover
โผ๏ธ๐ฃ๐๐๐ฆ๐๐๐ก๐ ๐๐๐๐ฅ๐ง โ ๐๐ฎ๐ธ๐ฒ ๐ ๐ฒ๐ฑ๐ถ๐ฎ๐ฐ๐ผ๐บ ๐ช๐ฒ๐ฏ๐บ๐ฎ๐ถ๐น ๐๐ผ๐ด๐ถ๐ป ๐ฃ๐ผ๐ฟ๐๐ฎ๐น ๐ง
(Mediacom provides internet, communications, and webmail services to customers across the United States.)
Fake URL: hxxps://fflmmppnj.weebly[.]com/
โ ๏ธ The website impersonates a Mediacom Webmail login portal and is designed to trick users into entering their email account credentials.
โ ๏ธ The phishing page mimics a legitimate Mediacom email sign-in interface, attempting to harvest usernames, email addresses, and passwords from unsuspecting visitors.
โ ๏ธ This appears to be a credential-harvesting phishing campaign targeting Mediacom customers. Stolen email credentials can be used to access sensitive communications, reset passwords for other services, and facilitate account takeover attacks.
โ ๏ธ Red Flags:
โข Hosted on weebly[.]com instead of an official Mediacom domain
โข Uses Mediacom branding and login elements without authorization
โข Requests email credentials through a third-party website
โข No verified association with Mediacom infrastructure
โข Hosted on a platform frequently abused for phishing campaigns
โข Uses a randomly generated subdomain name
โข Designed to imitate a legitimate webmail login page
โ ๏ธ Do NOT enter:
โข Email addresses
โข Usernames
โข Passwords
โข MFA / OTP verification codes
โข Recovery codes
โข Personal information
๐ก๏ธ If you entered your credentials:
โข Change your Mediacom email password immediately
โข Review recent login activity
โข Revoke suspicious sessions and devices
โข Enable Multi-Factor Authentication (MFA) if available
โข Check for unauthorized forwarding rules
โข Monitor linked accounts for suspicious password reset activity
โ ๏ธ Email accounts are high-value targets because they often serve as the recovery method for banking, social media, cloud storage, and business accounts.
Hosting: 74.115.51.9 โ Weebly, Inc. USA ๐บ๐ธ
#Phishing#Mediacom#Webmail#EmailSecurity#CredentialTheft#CyberSecurity#ScamAlert#ThreatIntel#AccountTakeover#USA
โผ๏ธ๐ฃ๐๐๐ฆ๐๐๐ก๐ ๐๐๐๐ฅ๐ง โ ๐๐ฎ๐ธ๐ฒ ๐ซ๐๐ฟ๐ฎ ๐ ๐ฎ๐ถ๐น ๐๐ผ๐ด๐ถ๐ป ๐ฃ๐ผ๐ฟ๐๐ฎ๐น ๐ณ๐ฟ
(Xtra Mail is a popular email service used by customers in New Zealand for personal and business communications.)
Fake URL: hxxps://ffhfsh.weebly[.]com/
โ ๏ธ The website impersonates an Xtra Mail login portal and attempts to trick users into entering their email account credentials.
โ ๏ธ The phishing page mimics a legitimate webmail sign-in experience and is designed to harvest usernames, email addresses, and passwords from unsuspecting users.
โ ๏ธ This appears to be a credential-harvesting phishing campaign targeting Xtra Mail customers. Compromised email accounts can be used to access sensitive communications, reset passwords for other services, and facilitate further fraud.
โ ๏ธ Red Flags:
โข Hosted on weebly[.]com instead of an official Xtra Mail domain
โข Uses Xtra Mail branding and login themes without authorization
โข Requests credentials through a third-party website
โข No verified association with Xtra Mail infrastructure
โข Hosted on a platform frequently abused for phishing campaigns
โข Designed to imitate a legitimate email login portal
โข Likely intended for account takeover and credential theft
โ ๏ธ Do NOT enter:
โข Email addresses
โข Usernames
โข Passwords
โข MFA / OTP verification codes
โข Recovery codes
โข Personal information
๐ก๏ธ If you entered your credentials:
โข Change your Xtra Mail password immediately
โข Review recent login activity
โข Revoke suspicious sessions and devices
โข Enable Multi-Factor Authentication (MFA) if available
โข Check for unauthorized forwarding rules
โข Monitor linked accounts for suspicious password reset activity
โ ๏ธ Email accounts are a primary target for attackers because access to a mailbox can enable compromise of banking, social media, cloud storage, and other online services.
Hosting: 74.115.51.8 โ Weebly, Inc. USA ๐บ๐ธ
#Phishing#XtraMail#Webmail#EmailSecurity#CredentialTheft#CyberSecurity#ScamAlert#ThreatIntel#AccountTakeover#NewZealand
๐ก Tip: Be cautious with unexpected .js files in emails, especially those disguised as purchase orders! JS.MonoGlyphRAT uses social engineering to gain access, making it crucial to verify sources before opening attachments. #EmailSecurity#StaySafe
โผ๏ธ๐ฃ๐๐๐ฆ๐๐๐ก๐ ๐๐๐๐ฅ๐ง โ ๐๐ฎ๐ธ๐ฒ ๐ข๐ฝ๐๐๐๐ก๐ฒ๐ ๐๐บ๐ฎ๐ถ๐น ๐๐ผ๐ด๐ถ๐ป ๐ฃ๐ผ๐ฟ๐๐ฎ๐น ๐ฆ๐บ
(OptusNet is an Australian internet and email service provider used by Optus customers for webmail and communication services.)
Fake URL: hxxps://oplus.toddsurvey[.]com/kosta/app/id.php?sessionId=5d310d8aeb38&userId=379211&scope=all&valid=true
Hosting: 185.224.196.146 โ Iomart Cloud Services Limited (Easyspace Limited), Ireland ๐ฎ๐ช
โ ๏ธ The website impersonates an OptusNet Webmail login page and prompts visitors to โLog in to access your email,โ attempting to steal email account credentials.
โ ๏ธ The page appears designed to mimic a legitimate OptusNet authentication portal while being hosted on an unrelated third-party domain.
โ ๏ธ This appears to be a credential-harvesting phishing site targeting Optus customers. Stolen credentials could provide attackers with access to email accounts, contacts, personal information, and password reset messages for other online services.
โ ๏ธ Red Flags:
โข Hosted on toddsurvey[.]com instead of an official Optus or OptusNet domain
โข Uses OptusNet branding and login themes without authorization
โข Requests email credentials through a non-Optus website
โข Contains tracking/session parameters to identify targeted victims
โข No verified association with Optus infrastructure
โข Designed to imitate a legitimate webmail login portal
โข Likely intended for account takeover and credential theft
โ ๏ธ Do NOT enter:
โข Email addresses
โข Usernames
โข Passwords
โข MFA/OTP verification codes
โข Recovery codes
โข Personal information
๐ก๏ธ If you entered your credentials:
โข Change your OptusNet password immediately
โข Review recent login activity
โข Enable or verify Multi-Factor Authentication (MFA)
โข Check account recovery settings and forwarding rules
โข Revoke suspicious sessions and devices
โข Monitor linked accounts for unauthorized access attempts
โ ๏ธ Email accounts are often targeted because they can be used to reset passwords for banking, social media, cloud storage, and other critical services.
#Phishing#Optus#OptusNet#Webmail#EmailSecurity#CredentialTheft#CyberSecurity#ScamAlert#ThreatIntel
โผ๏ธ๐ฃ๐๐๐ฆ๐๐๐ก๐ ๐๐๐๐ฅ๐ง โ ๐๐ฎ๐ธ๐ฒ ๐ฌ๐ฎ๐ต๐ผ๐ผ ๐ ๐ฎ๐ถ๐น ๐๐ผ๐ด๐ถ๐ป ๐ฃ๐ผ๐ฟ๐๐ฎ๐น ๐
(Yahoo Mail is one of the worldโs most widely used email services, providing webmail access to millions of users globally.)
Fake URL: hxxps://poijngh.weebly[.]com/
โ ๏ธ The website impersonates a Yahoo Mail login portal and is designed to trick users into entering their email account credentials.
โ ๏ธ The phishing page mimics Yahooโs authentication interface, attempting to harvest usernames, email addresses, passwords, and potentially multi-factor authentication information.
โ ๏ธ This appears to be a credential-harvesting phishing site targeting Yahoo Mail users. Stolen credentials could provide attackers with access to emails, contacts, personal information, password reset links, and other linked online services.
โ ๏ธ Red Flags:
โข Hosted on weebly[.]com instead of an official Yahoo domain
โข Uses Yahoo branding and login elements without authorization
โข Requests account credentials through a non-Yahoo URL
โข No verified association with Yahoo infrastructure
โข Hosted on a website-building platform frequently abused for phishing campaigns
โข Designed to imitate a legitimate Yahoo Mail sign-in page
โ ๏ธ Do NOT enter:
โข Yahoo email addresses
โข Usernames
โข Passwords
โข MFA / OTP verification codes
โข Recovery codes
โข Personal information
๐ก๏ธ If you entered your credentials:
โข Change your Yahoo password immediately
โข Review recent account login activity
โข Revoke suspicious sessions and devices
โข Enable or verify Multi-Factor Authentication (MFA)
โข Check account recovery settings and email forwarding rules
โข Monitor linked accounts for suspicious password reset activity
โ ๏ธ Email accounts are high-value targets because they can be used to reset passwords for other services and facilitate account takeover attacks.
Hosting: 74.115.51.8 โ Weebly, Inc., USA ๐บ๐ธ
#Phishing#YahooMail#Yahoo#EmailSecurity#CredentialTheft#CyberSecurity#ScamAlert#ThreatIntel#AccountTakeover
73,000 French govt employees had their Tchap messenger accounts breached, leaving sensitive info exposed. How vulnerable is your company's messaging platform?
Protect your inbox: soemailsecurity.com, can you afford to wait?
#emailsecurity#cybersecurity#dataprotection
The compliance questions hitting MSP clients are arriving earlier and from more directions than they used to.
Cyber insurers want outbound controls documented at renewal. Healthcare clients are watching HIPAA enforcement climb on unauthorized disclosure. Financial-services examiners are asking how customer data is protected in transit. State privacy laws are now active in 20 states, with three more switched on this January.
For years the honest MSP answer was some mix of native tooling and a third-party encryption tool stood up client-by-client. Neither is a service line. Both create work every time a client onboards or offboards.
That math has finally changed. IRONSCALES Email Encryption was built for the multi-tenant model, so encryption fires by policy, logs the supervisory record an auditor or carrier will ask for, and opens cleanly for the recipient with one-time passcode access. No portal account. No password reset. No help-desk ticket.
Learn more: hubs.la/Q04l4wVS0#MSP#EmailSecurity#Compliance#EmailEncryption