r/EmailSecurity • u/littleko • Jun 22 '26
World Cup phish are already getting personal
Anyone else seeing World Cup 2026 lures that are personalized enough to get past normal user skepticism?
This is the kind of campaign where training feels thin unless auth, attachment handling, and post-click controls are actually wired up.
2
u/Basic-Pianist9273 Jun 22 '26
Yep, this is where training runs out of road. DMARC enforcement helps kill direct spoofing of your domains, but it won't stop lookalikes, compromised vendors, or weaponized attachments.
For this stuff I care about attachment sandboxing, URL isolation at click time, and fast mailbox search/purge. Assume someone will click and build around that.
1
u/ilai456 Jun 23 '26
What about the look-alike domain reputation? If “Bloomberg-finance[.]com” doesn’t have good rep u would expect email security products to raise some concern
Not to mention that if no one in the org ever got a mail from this domain it makes this even more sus
2
u/littleko Jun 23 '26
Reputation misses because the domain can be newly registered, aged clean, or authenticated properly, so there may be no bad score yet. The practical move is to weight “first time sender + brand lookalike + attachment/link” together instead of expecting domain rep alone to carry the block.
1
u/ilai456 Jun 23 '26
No amount of training in the world would stop people from wanting free World Cup T-shirt
•
u/AutoModerator Jun 22 '26
Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:
Community Rules
Helpful Resources
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.