logo

Travel Policy Update Phishing Email Impersonating Corporate Operations

ID: dddb8240-0825-45b2-a33e-968bb56984b2

STIX ID: report--dddb8240-0825-45b2-a33e-968bb56984b2

Threat Score

55/100

Uploaded: 2026-04-13

Created by: Report Uploader

TLP:GREEN
...
...
Employees who frequently travel received phishing emails on 11 April 2026 impersonating a travel policy update; the messages used the sender operations@travel-policydesk.com and linked to https://corp-travel-policy.com/review, which prompted corporate credential sign-in and captured submitted credentials. Compromised accounts were subsequently leveraged to send additional internal phishing messages, indicating internal propagation and active credential theft. Observed indicators include the sender, URL, theme, victim profile, and compromised account behavior.