← All categories

Email Phishing & Brand Impersonation

22 posts

Credential harvest and brand-impersonation delivered by email — fake e-sign, account-lockout, and cloud-storage-abuse delivery.

Email Phishing & Brand Impersonation

Between March and July 2026, one email operator ran the same reply-chain phishing kit across six Google Cloud Storage surfaces, then abandoned Google entirely.

Published Jun 20, 2026Updated Jun 20, 2026
Email Phishing & Brand Impersonation

From mid-May through late June 2026, one operator ran a $50-reward credential-phishing operation hosted entirely on Google infrastructure.

Published Jun 17, 2026Updated Jun 23, 2026
Email Phishing & Brand Impersonation

In May 2026, analysts tracked a phishing operation that hides its lure inside genuine Meta partner-request emails, with no attacker-owned domain anywhere.

Published Jun 15, 2026Updated Jun 15, 2026
Email Phishing & Brand Impersonation

Since December 2025, a Brazilian operator has impersonated five US banks in email lures sent from a fully self-authenticated domain it owns outright.

Published Jun 3, 2026Updated Jul 28, 2026
Email Phishing & Brand Impersonation

Since March 2026 a phishing operator has sent iCloud account-lockout lures from email addresses on top-level domains that do not exist.

Published May 24, 2026Updated Jul 2, 2026
Email Phishing & Brand Impersonation

Since December 2025, one operator has run four phishing funnels from a single kit, staged on burn-and-rotate Linode Object Storage buckets.

Published May 5, 2026Updated Jul 22, 2026
Email Phishing & Brand Impersonation

Across three months in early 2026, six email scam operators leaned on the same evasion: the malicious link lived inside the attachment, not the email body.

Published Apr 29, 2026Updated May 5, 2026