Targeted Phishing Attempt with Personal and Company Emails – Concerned About Data Breach
Posted by SignificanceFair3298@reddit | sysadmin | View on Reddit | 4 comments
Hi all
Has anyone encountered something like this?
Around 100 users received a poorly constructed phishing email. The header shows the CEO’s name, but the envelope sender is a random generic email address. Our impersonation policy caught it, as it always does, so no harm done this time.
What’s troubling is that the attacker used both personal and company email addresses for each recipient in the "To" field. How could they have this information? Could it indicate a breach in our HR system?
What’s the goal here? Are they hoping someone responds so they can escalate to a money request?
I checked several users’ email addresses on “Have I Been Pwned,” and most were compromised in the massive 2019 PDL breach involving 1.2 billion records. Still, I can’t figure out how they’re matching personal and company email addresses like this.
Is this just better-organized data mining or the start of more advanced, AI-driven attacks?
Here’s what the email looked like:
From: "CEO Name" randomnumbers*@domain.co.uk
To: personalemail@gmail.com, companyemail@companydomain.com, previouscompanyemail@domain.com
Subject: [Company Name]
Body:
Hi [First Name],
Are you available now?
Kind regards
Would love to hear if others have faced this and what steps you took to investigate further.
reegz@reddit
They’re often vendor databases for sales that get leaked or stolen.
drunkenitninja@reddit
Or they offshored some of their workforce.
LodanMax@reddit
Sounds like they scraped LinkedIn. People shouldn’t add their work email visible there.
SignificanceFair3298@reddit (OP)
I think you right because linked in also keeps coming up in the seach