TL;DR A message from 'HubSpot Team' was sent via Amazon SES at IP 54.240.64.44 from an unrelated personal marketing domain (registered 2009, name withheld) and passed SPF, DKIM, and DMARC for that domain. The subject claimed 'Account Suspended' with a case number. The body used urgent suspension language, a generic 'Dear Customer' greeting, and duplicated content blocks. The Verify Your Account CTA routed through awstrack.me to r2.ddlnk[.]net, a redirect domain with prior phishing abuse reports that returned HTTP 404 at scan time. The footer showed a residential street address (not HubSpot's Cambridge headquarters) and preference links pointed to form.flodesk.com, exposing that the email was built on Flodesk infrastructure while impersonating HubSpot. The recipient tenant quarantined the message at SCL:5.
Severity: High Credential Harvesting Brand Impersonation Redirect Chain MITRE: {'id': 'T1566.002', 'name': 'Phishing: Spearphishing Link'} MITRE: {'id': 'T1583.006', 'name': 'Acquire Infrastructure: Web Services'} MITRE: {'id': 'T1036.005', 'name': 'Masquerading: Match Legitimate Name or Location'}

The email announced that the recipient's HubSpot email campaigns had been suspended as of May 29, 2026. Case number #048974-489368. A prominent orange "Verify Your Account" button. The sender line read "HubSpot Team." Three different platforms were involved in building this message, and none of them was HubSpot.

Three Platforms, Zero HubSpot

The From address belonged to an unrelated personal marketing domain, a long-established registration (2009) anonymized here because its owner is a third party whose authenticated sending identity was abused. The message was delivered through Amazon SES at IP 54[.]240[.]64[.]44. SPF, DKIM, and DMARC all passed for that sending domain. Authentication was technically valid but proved nothing about HubSpot.

The email template was built on Flodesk. Preference and unsubscribe links pointed to form.flodesk[.]com and usercontent.flodesk[.]com. The footer displayed a residential street address that does not match HubSpot's headquarters in Cambridge, MA. This was brand impersonation assembled from parts: Amazon SES for delivery, Flodesk for template infrastructure, and HubSpot's visual identity layered on top.

The Redirect That Was Already Gone

The "Verify Your Account" CTA linked to a URL on gkbt4brd.r.us-east-1.awstrack[.]me, an AWS SES click-tracking redirect. The tracking URL pointed to r2.ddlnk[.]net, a redirect domain fronted by Cloudflare with a valid SSL certificate.

At scan time, the ddlnk[.]net URL returned HTTP 404. The page was no longer live. But the domain has documented prior abuse reports, with sibling subdomains appearing in phishing campaigns. Attackers commonly activate credential harvesting pages during campaign delivery and take them offline within hours to avoid being crawled. A 404 at scan time does not mean the page was never serving a fake login page.

Quality Control Failures That Helped Detection

The body used a generic "Dear Customer" greeting with no account-specific identifiers, no organization name, and no email address associated with the claimed account. Content blocks were visibly duplicated in the HTML, a template-assembly error. The combination of urgency language, generic greeting, and duplicated blocks created a detection surface that compensated for the otherwise clean authentication signals.

The recipient tenant's protection system scored the message at SCL:5 and quarantined it before delivery, preventing user interaction with the CTA.

See Your Risk: Calculate how many threats your SEG is missing

Indicators of Compromise

TypeIndicatorContext
Sender DomainPersonal marketing domain (registered 2009), name withheldAuthenticated sender abused to impersonate HubSpot; likely third-party owner
Display Name"HubSpot Team"Spoofed brand identity over an unrelated sender domain
Sending IP54[.]240[.]64[.]44Amazon SES
CTA Redirectgkbt4brd.r.us-east-1.awstrack[.]meAWS click tracking
Landing Domainr2.ddlnk[.]netCloudflare-fronted, prior abuse reports, HTTP 404 at scan
Template PlatformFlodesk (form.flodesk[.]com)Preference/unsubscribe links
Footer AddressResidential street address (withheld)Not HubSpot (Cambridge, MA)
Case Number#048974-489368Fabricated

MITRE ATT&CK Mapping

TechniqueIDRelevance
Phishing: Spearphishing LinkT1566.002Verify Your Account CTA to credential harvesting redirect
Acquire Infrastructure: Web ServicesT1583.006Amazon SES, Flodesk, and ddlnk.net assembled for campaign
Masquerading: Match Legitimate Name or LocationT1036.005HubSpot branding over non-HubSpot infrastructure
Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.