Picture this: You’re going through your daily routine, checking your emails, when suddenly, you spot a message from a company you trust. You don’t hesitate. You think, “Great! That’s safe to read.” But hold on one minute… this email might not be what it seems. This is how phishing attacks prey on you.
It could be part of a sophisticated phishing scam that’s more dangerous than ever before. Cyber criminals have now upped their game with a new tactic known as SubdoMailing, and it’s as malicious as it sounds.
What’s going on?
Just like traditional phishing attacks, cyber criminals are impersonating trusted brands to trick unsuspecting victims into clicking malicious links or handing over sensitive data. However, this new twist involves the clever exploitation of subdomains – those bits of text that appear before the main domain name in a web address, like “experience.trustedbrand.com”.
Here’s how they’re doing it:
- Scouring for subdomains: These criminals scour the internet for subdomains that reputable companies are no longer actively using.
- Domain takeover: Once they find a subdomain still pointing to an external domain that is no longer registered, they swoop in, purchase the now-available domain, and set up their scam website.
- Invisible redirection: You believe you’re clicking on a trusted link, like experience.trustedbrand.com, but in reality, you’re redirected to a malicious site, such as scamwebsite.com. Since the link looks legitimate, you might not suspect anything is wrong until it’s too late.
The sheer scale of these attacks is staggering. These criminals are sending out five million emails a day, targeting businesses just like yours. And the scariest part? Because the emails appear to be from a legitimate source, they often bypass regular security checks, landing straight in your inbox without raising any alarms.
Why SubdoMailing is so dangerous
There are several reasons why this phishing tactic is so dangerous, especially for small to medium-sized businesses (SMBs):
- Legitimacy: The email appears to come from a trusted brand, meaning most recipients don’t think twice before clicking the link or downloading attachments. This false sense of security makes the scam even more effective.
- Bypassing security: Because the subdomains still belong to reputable companies, these phishing emails can sneak past regular filters and security tools, landing directly in your inbox. Without heightened scrutiny, they’re often treated as legitimate messages.
- Widespread attacks: With millions of emails being sent daily, these attacks target businesses across industries. No sector is immune.
How to protect against SubdoMailing phishing attacks
In the face of this highly sophisticated phishing attack, it’s more important than ever to adopt a proactive approach to your email security. Here are some practical tips to help you stay safe:
- Be wary of suspicious emails: Always be on guard. Even if an email appears to come from a trusted source, look closely for anything that seems off. If something feels fishy, it probably is. For example, unexpected requests for sensitive information or unfamiliar links should raise immediate red flags.
- Verify the sender: Before clicking any links or opening attachments, take a few seconds to verify the sender’s details. Look for common signs of phishing, like spelling mistakes, odd formatting, or unfamiliar email addresses.
- Train your employees: Cybersecurity is only as strong as its weakest link, and that’s often your team. Educate your staff about the latest phishing tactics, including SubdoMailing, so they know what to watch out for. Regular training sessions and refresher courses can go a long way in reducing the risk of phishing attacks succeeding.
- Implement strong security software: Consider investing in advanced email security software that can detect and block phishing emails, even those using more advanced tactics like SubdoMailing. While it may seem like an extra expense, it’s worth it to prevent a costly data breach.
- Enable multi-factor authentication (MFA): Even if a phishing email gets through and an employee accidentally shares their login credentials, MFA can serve as an additional barrier that stops attackers from gaining access.
- Regular vulnerability assessments: Conduct regular vulnerability scans of your network and systems to ensure there are no weaknesses that cyber criminals could exploit.
Why you can’t afford to ignore this threat
Phishing scams like SubdoMailing are constantly evolving, and businesses that fail to take proper precautions are putting themselves at serious risk. It’s not just about financial loss, although that can be devastating. It’s also about the damage to your reputation, the loss of customer trust, and the potential legal ramifications of a data breach. Check out the ICO’s report on the impact of phishing.
The reality is, phishing is one of the most common and effective tactics used by cyber criminals, and it’s not going away anytime soon. As attacks become more sophisticated, your defences need to keep up. That means staying informed about the latest threats, educating your team, and investing in strong security solutions that can detect and block phishing attempts.
Nxt Steps
At Nxt Gen IT, we specialise in helping businesses protect themselves from phishing attacks and other cyber threats. Whether it’s conducting a security audit, setting up advanced email filters, or providing comprehensive employee training, we’re here to ensure your data stays safe.
If you’re concerned about the security of your emails, don’t wait until it’s too late. Get in touch with us today to discuss how we can help protect your business from these sophisticated attacks.
It’s time to stop phishing in its tracks – and we’re ready to help.
Interested in improving your cyber security by testing your team’s ability to spot phishing attacks? Find out how Nxt Gen IT can help.
Ben helps growing businesses turn technology into a driver of performance instead of a barrier. At Nxt Gen IT he works with SME leaders, recruiters, and fast-scaling teams to design solutions that improve reliability, strengthen security, and unlock growth.
With a background in email deliverability and cloud systems, Ben specialises in making sure businesses communicate effectively, keep data safe, and get the most from Microsoft 365. His experience spans solution design, managed IT services, and virtual CIO support, always with a focus on practical outcomes that reduce headaches for business owners.
Ben has supported organisations across the UK, from recruitment agencies struggling with inbox placement to SaaS firms scaling fast, and SMEs needing a trusted partner for their IT. He believes tech is never the end goal: growth is. His role is to make sure technology never gets in the way of it.
