Thehackernews
Email Spoofing Exploit via Misconfigured Routing
First seen 7 Jan 2026, 17:41 UTC
•

•89% similarity
•22.3
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Attackers are exploiting misconfigured email routing to spoof internal emails, utilizing PhaaS platforms like Tycoon2FA to steal credentials. This tactic allows phishing actors to bypass spoof protections and send emails that appear to originate from within organizations, targeting their domains.
ThreatCluster AI
How this analysis works