Attackers are leveraging n8n's webhook functionality, which exposes unique URLs on the *.app.n8n.cloud subdomain, to initiate workflows when triggered by incoming data.
Proofpoint's research highlights how threat actors leverage automated inbox rules, designed for legitimate organization, to hide security alerts, forward sensitive data, and mark messages as read.
The scam begins with a phishing email designed to appear as an official communication from the IRS, informing recipients they are eligible for a $5,000 financial grant supposedly from Elon Musk.