Education Phishing Teardowns
Every Attack of the Day teardown where the targeted organization was in education, newest first. Real attacks on schools and universities, dissected: the headers, the lure, and why it got past the first line of defense. Targeted organizations are never named.
All teardownsManufacturingHealthcareFilter in the ExplorerEducation email security
2026
- Fully Signed, Fully Passed: The Reply-To Was the Payload
- DKIM and DMARC Passed. The $97,500 Wire Was Fraud.
- The Squarespace Phish With No Brand Text to Match
- Full Authentication Pass, Zero Legitimacy: How a 26-Day-Old Domain Ran ACH Fraud
- A One-Line Curiosity Hook Sent a K-12 Teacher to a Same-Day Phishing Domain on Port 8443
- re: plans for party -- How a Compromised Argentine School Account Targeted K-12 in the U.S.
- McAfee Invoice Scam Weaponized a Google Calendar Invite 71 Minutes After Domain Registration
- The Childcare App That Passed Every Security Check (The Reply-To Header Didn't)
- The Timestamp That Gave It Away: Oracle Identity Cloud Phishing Targets K-12 with a Stale Timezone
- The Email That Passed Every Security Check (Because Adobe Sent It)
- When SPF, DKIM, and DMARC All Pass. And the Email Is Still Phishing
- The Phishing Link Lived on a Domain That Didn't Exist Nine Hours Earlier
- Legit Ticket, Lethal Link: A Real Telecharge Newsletter Hid a PII Harvester on Cloudflare Pages
2025
- The Photograph Link That Vanished Before Anyone Could Scan It
- Every Authentication Check Failed. An Allow-List Let It Through Anyway.
- DKIM Pass, SPF Pass, DMARC Pass: The Phish That Aced Every Authentication Check
- The Curiosity Lure Sent From a Compromised Moroccan Training Account
- A Geek Squad Calendar Invite With No Links, No Malware, and a Phone Number
- The PDF That Fired Before You Read It: AICPA Impersonation and an S3-Hosted Adobe Typosquat
- His Name in the From Field, Someone Else's Bank Account: Political Donation Impersonation via bluevision24.com
- Clio Platform Abuse: HMAC-Tokened Invoice Links and a Fabricated Internal Thread
- Authenticated Education Sender, Malicious Study-Abroad Link, and a Student File as Bait
- Lure Text You Recognize, Destination You Can't See: How a Yahoo Sender Weaponized a Corporate Brand
- Bitcoin Sextortion via Spoofed Legitimate Domain: SPF Softfail Lets Extortion Template Through
- When a Trusted University Account Delivers a Same-Day-Registered Phishing Link
- Free Gmail Sender, Nigerian IP, Freshly Registered Reply-To: Inside a Bapco Energies Vendor BEC
- Compromised University M365 Account Delivers Thread-Hijacked Email With Malicious QR Shortlink and Suspicious Image Payloads
- Disney+ Billing Lure Rides Legitimate Tax-Service Infrastructure to a phpList Subscribe Page
- The Email Inside the Email: How a Nested .eml and Microsoft Short Links Blind Inline Scanners
- Inside the Wrapper: How a Pre-Wrapped SafeLinks URL Became the Attack's First Layer of Cover
- Clean Scan, Full Auth, One Phone Number: A Compromised School Account Carrying a TOAD Payload
- Aged Domain, Cloud Rail, Fake Portal: How a Compromised 1998 Domain Delivered an EFT Credential Harvest via Amazon SES
- Credential Phish by Day, Remote-Access Trojan by Night
- DocuSign With No Subject: Two Hops to a Malicious Page
- A Student Account Weaponized Google's Own Script Engine
2024
- The OAuth Consent Phish Riding Microsoft's Real Login
- The DOCX That Was Actually a Fake M365 Admin Console
- The Blog Notification That Was a Vishing Scam
- A Real OneDrive Share Email, Built to Map an Inbox
- A Same-Day Domain, a McAfee Calendar Invite, Two Prices
- The Meta Verified Scam That Forgot to Fill In the Blanks
- A Zoom Calendar URL Where the Sender Should Be
- Look-Alike Letters Hid an Investment Scam From Filters
- The Calendar Invite Was the Whole Attack
- The Card Was Real, the Button Was Not