Re: [mailop] Russian crypto phish campaign via sendgrid to stolen Robinhood account

2022-04-24 Thread Atro Tossavainen via mailop
On Sun, Apr 24, 2022 at 11:02:42PM -0400, John R Levine via mailop wrote: > I've gotten several copies of this phish sent to an address stolen > from a closed Robinhood brokerage account. It's sent from Sendgrid, > with a link to a web host at AWS that does a couple of web redirects > to a web ser

Re: [mailop] Russian crypto phish campaign via sendgrid to stolen Robinhood account

2022-04-24 Thread Alexander Huynh via mailop
On Apr 24, 2022, at 23:09, John R Levine via mailop wrote: Anyone else seeing this? I’ve received a similar spam email supposedly from Metamask almost a month ago, from an O365 tenant to my O365 tenant: https://pastebin.com/Tb3S8BuD There are slight differences in the email I received: * the