#Phishing attacks are prevalent and most of them are quite easy to spot. For example as a client of #Hetzner hosting service I frequently get emails claiming that my domain(s) are about to expire with links to random sites that try to steal the Hetzner login credentials. These attacks are dumb, and easy to tackle.
Today I received a bit more refined and sneakier one: The attacker is using a legitimate helpdesk platform as a staging area. The attackers have created an account on #Freshdesk, and then invite Hetzner users to the platform in name of Hetzner Support. This is quite devious as the email originates from Freshdesk, and thus looks quite legitimate. Presumably if you register an account, you will be then targeted with further attacks (which will be much easier once you’ve accepted the premise of them actually being the Hetzner Support).
I can see some people easily falling for this one. I’ve now reported the malicious account to Freshdesk.
The irony? I got yet another registration email after reporting the issue to them. But this time it appears to be from a legitimate source. I think.