Warning: New Spear Phishing Campaign Targets Executives

KnowBe4 Team | Sep 5, 2025

Spear Phishing Bigger ProblemResearchers at Stripe warn of a wave of spear phishing attacks targeting C-suite employees and senior leadership across a wide range of industries. The emails pose as OneDrive document-sharing notifications with subject lines like “Salary amendment” or “FIN_SALARY.”

If a user clicks the link, they’ll be taken to a spoofed Microsoft Office/OneDrive login page designed to steal their credentials. The researchers note that “[b]oth the email body and phishing page are customized with the recipient’s name and company details to enhance credibility.”

Interestingly, the phishing emails use obfuscated button text to avoid detection by security filters. For example, the word “Open” is surrounded by random characters that are invisible to users in light mode.

“When the initial email is viewed in Light Mode, the buttons appear as ‘Open’ and ‘Share,’” the researchers explain. “In Dark Mode, concealed padding becomes visible, exposing randomised alphanumeric strings such as twPOpenHuxv and gQShareojxYI. This breaks up high-value trigger words like ‘Open’ and ‘Share,’ reducing the likelihood of detection by secure email gateways that apply string- or regex-based rules.”

Stripe offers the following recommendations to help organizations protect themselves against these attacks:

  • “Awareness for executives and assistants – Ensure that those most likely to be targeted understand this campaign. The actor is using realistic “salary amendment” subject lines and personalised company details to increase credibility.
  • “Scepticism around unexpected documents – Remind staff to be cautious when receiving links or documents relating to HR, payroll, or salary matters, particularly when sent externally.
  • “Reporting suspicious emails – Make it clear how to escalate suspicious messages quickly within your business. The faster these are reported to your security resource, the quicker they can take action to protect others.
  • “Support staff training – Executive assistants and close colleagues are also high-value targets. Ensure they receive the same level of awareness training and support as C-suite members.”

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 HRM+ platform to strengthen their security culture and reduce human risk.

Stripe has the story.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer



Subscribe to Our Blog


Gartner Magic Quadrant




Get the latest insights, trends and security news. Subscribe to CyberheistNews.