GitHub and Jira Notification Systems Exploited for Phishing Attacks

GitHub and Jira Notification Systems Exploited for Phishing Attacks

First seen 14 Apr 2026, 22:58 UTC GbhackersScworld 79% similarity 67.5

Article Content

Browse articles
ThreatCluster

Cybercriminals have exploited GitHub and Atlassian Jira's notification systems to send phishing emails that appear legitimate. These emails bypass standard security checks such as SPF, DKIM, and DMARC because they originate from the platforms' own mail servers. Attackers have specifically targeted GitHub's automated commit notifications, crafting malicious commits that trigger phishing emails related to billing issues. Similarly, Jira's invitation and service desk workflows have been manipulated to inject phishing content into trusted templates, leading to the distribution of seemingly authentic messages. Organizations using these platforms are urged to enhance identity verification measures and adopt a zero-trust approach for SaaS notifications. The ongoing exploitation poses a significant risk to users and organizations relying on these collaboration tools.

Key Points: • Phishing emails are sent from GitHub and Jira, evading traditional security filters. • Attackers exploit automated notifications related to commits and service desk workflows. • Organizations are advised to implement stronger identity verification and zero-trust strategies.

ThreatCluster AI

Timeline

2026-04-13
Gbhackers article published detailing the phishing exploitation
2026-04-14
Scworld article published providing further insights on the attacks

Community

Browse all →