A large-scale fraud campaign that used an email routing error in the defenses of email security provider Proofpoint to send millions of messages impersonating well-known brands like Best Buy, IBM, Nike, and Walt Disney, among others, has been connected to an unidentified threat actor.
In order to trick receivers and steal money and credit card information, these emails mimicked genuine Proofpoint email relays with verified SPF and DKIM signatures, circumventing important security measures, according to a thorough study released by Guardio Labs researcher Nati Tal to The Hacker News.
The attack is called EchoSpoofing, according to the cybersecurity business. The activity is thought to have started in January 2024. The threat actor used the vulnerability to send up to three million emails every day on average read more about Proofpoint Email Routing Flaw Exploited to Send Millions of Spoofed Phishing Emails.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
