Site navigation

SendGrid Phishing Campaign Targeting SMBs

Michael Edgar

,

SendGrid phishing
A new phishing campaign, which specifically targets SMBs, is on the radar after it was uncovered by Kaspersky. 

Kaspersky, a global security firm, discovered a sophisticated phishing campaign that utilises the email service provider (ESP) SendGrid to infiltrate client mailing lists and employs stolen credentials to send out convincing phishing emails.

Exploiting mailing lists is a common way cyber-criminals engage with customers since using legitimate tools for sending bulk emails amplifies the success rates of these attacks, prompting attackers to compromise companies’ accounts with ESPs.

In this attack, the phishing emails, appearing to originate from SendGrid, prompt recipients to enable two-factor authentication (2FA) to safeguard their accounts. However, the provided link redirects users to a counterfeit website mimicking the SendGrid login page, where their credentials are harvested.

 Despite the convincing appearance, a subtle warning sign lies in the phishing site’s domain, “sendgreds,” closely resembling the legitimate “sendgrid.”

“Using a reliable email service provider is important when it comes to your business’ reputation and safety,” said Roman Dedenok, a security expert at Kaspersky. “However, some sneaky scammers learned how to mimic reliable services, so it is crucial to check the emails that you receive properly.”


Recommended reading


To mitigate risk of falling victim to phishing attacks, Kaspersky recommended several measures: Provide staff with basic cybersecurity training, implement protection solutions for mail servers, as well as endpoint security solutions and dedicated anti-spam and anti-phishing solutions, especially for cloud services like Microsoft 365.

This comes on the backdrop of being named the most dominant and fastest growing internet crimes, according to research from Cloudflare. According to them, business email compromises, much like what we’re seeing with SendGrid, accounted for over £39.5 billion in losses last year.

Of compromises through emails, the most prevalent phishing method was malicious links, accounting for over a third (35.6%) of detected threats. 

A Twilio Spokesperson added: “Impersonating a site administrator, or other critical function, has proven an effective means of phishing across the industry, and Twilio SendGrid takes abuse of its platform and services very seriously. Twilio detected that bad actors obtained customer account credentials and used our platform to launch phishing attacks; our fraud, compliance and cyber security teams immediately shut down accounts identified and associated with the phishing campaign.

“We encourage all end users to take a multi-pronged approach to combat phishing attacks, including two factor authentication, IP access management, and using domain-based messaging.”

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data