logo

Password Reset Notification Used for Identity Platform Credential Theft

ID: 1b4d1d9c-0fe7-4586-97bf-bb03e3b3f05c

STIX ID: report--1b4d1d9c-0fe7-4586-97bf-bb03e3b3f05c

Threat Score

70/100

Uploaded: 2026-04-13

Created by: Report Uploader

TLP:GREEN
...
...
Between 9 April 2026 and 12 April 2026, employees at a software company received emails claiming passwords would expire and linking to https://password-reset-verify.com/account, a site that visually mimicked the corporate identity platform and requested usernames, passwords, and MFA. Several accounts were later accessed from Eastern Europe and Southeast Asia and used to retrieve internal documents, indicating a focused credential-harvesting campaign intended to enable cloud account compromise. Observed indicators: domain password-reset-verify.com, path /account, theme "password expiration", and follow-on behavior of internal data access.