Email Phishing & Brand Impersonation
22 postsCredential harvest and brand-impersonation delivered by email — fake e-sign, account-lockout, and cloud-storage-abuse delivery.
The Padded Port: Fingerprinting a Reply-Chain Phishing Kit
Between March and July 2026, one email operator ran the same reply-chain phishing kit across six Google Cloud Storage surfaces, then abandoned Google entirely.
Living Off Google: Firebase Auth Abuse in a Reward-Phishing Operation
From mid-May through late June 2026, one operator ran a $50-reward credential-phishing operation hosted entirely on Google infrastructure.
Meta Partner-Request Phishing With No Attacker Domain
In May 2026, analysts tracked a phishing operation that hides its lure inside genuine Meta partner-request emails, with no attacker-owned domain anywhere.
Creditável: Multi-Bank Impersonation on a Self-Authenticated Domain
Since December 2025, a Brazilian operator has impersonated five US banks in email lures sent from a fully self-authenticated domain it owns outright.
Bogus-TLD Cloud-Storage Phishing: Anatomy of a Full-Stack Evasion Tier
Since March 2026 a phishing operator has sent iCloud account-lockout lures from email addresses on top-level domains that do not exist.
Four Funnels, One Kit: Phishing on Linode Object Storage
Since December 2025, one operator has run four phishing funnels from a single kit, staged on burn-and-rotate Linode Object Storage buckets.
The Link Lives in the Attachment: A Multi-Operator Email Evasion Landscape
Across three months in early 2026, six email scam operators leaned on the same evasion: the malicious link lived inside the attachment, not the email body.