The Amazing Thing Is that DHL Phishing Campaigns STILL Work

Stu Sjouwerman | Jan 18, 2023

DHL Most Spoofed Brand in PhishingResearchers at Armorblox warn that a phishing campaign is impersonating DHL with fake shipping invoices.

“The subject of this email aimed to instill an automatic level of trust through the inclusion of the well-known and trusted brand name, DHL, reading: ‘DHL Shipping Document/Invoice Receipt,’” the researchers write. “The inclusion of a legitimate brand name within the email subject encourages victims to open the email in a timely fashion, assuming the email is a legitimate communication from the brand that needs attention. At first glance, the email seems to be a legitimate communication from international shipping company, DHL, with the sender name and email address reading DHL but actually from the email address dhl@vaimti-yacht[.]com.”

However, the emails look close enough to legitimate DHL notifications, and they were able to bypass security filters.

“The body of the email continues to impersonate the well-known brand, through the inclusion of the company logo and brand colors and signature pertaining to the DLP customer service department,” Armorblox says. “The email looks like a notification from DHL, notifying recipients about a parcel sent by a customer that needed to be rerouted to the correct delivery address. The body of the email has one simple call to action for the recipient, to view the attached document and confirm the destination address of the parcel shipment.”

The emails instructed users to open the Excel attachment, which asked them to enter their Microsoft account credentials in order to view the phony invoice.

“The goal of the targeted attack was for victims to follow the prompted instructions within the email body and open the attachment,” the researchers write. “The attachment included within this email attack was named Shipping Document Invoice Receipt to further instill trust in the unsuspecting victims that the attachment was a legitimate file from DHL and the “copy of DHL receipt for tracking”, as referenced in the body of the email. The information and language used within the email led victims to click the attachment, unsuspecting that the attachment had malicious intent.”

New-school security awareness training can enable your employees to recognize social engineering attacks.

Armorblox has the story.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.