Proofpoint's analysis of 25 official FIFA World Cup partner domains revealed that 36% lack strong Domain-based Message Authentication, Reporting and Conformance (DMARC) protections.
These phishing emails often state that a user's storage limit has been exceeded or their account is blocked, threatening the permanent erasure of photos and videos by a specific date.
Attackers are leveraging n8n's webhook functionality, which exposes unique URLs on the *.app.n8n.cloud subdomain, to initiate workflows when triggered by incoming data.
Proofpoint's research highlights how threat actors leverage automated inbox rules, designed for legitimate organization, to hide security alerts, forward sensitive data, and mark messages as read.
The scam begins with a phishing email designed to appear as an official communication from the IRS, informing recipients they are eligible for a $5,000 financial grant supposedly from Elon Musk.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.