π¨ Someone impersonated our CEO to get finance to pay a fake invoice.
The tell? π the reply-to. 'From' showed our domain, but the reply-to went to an outside inbox.
Two seconds on the reply-to, or a wire you'll never get back. check out the full story below π
"unauthorized sign-in attempt flagged, your account may be at risk, respond before your account is locked, secure your account at https://t.co/f5R46FTh9w"
That's not a subject line that's a hostage note
New phishing tactic: attackers are abusing Google's no-reply addresses to send messages to victims that are from Google infrastructure. They can't control the autoresponse email body, so they put their message in the subject line.
Rating ways people find out about phishing:
Clicking a test email at work: 0/10 embarrassing
Your IT friend warning you: 7/10 appreciated
Finding out the hard way: -100/10 do not recommend
Haven: 10/10 no drama