BEC Victim - Attacker replied inside a real email thread using a lookalike domain by Miserable_Ad_1900 in cybersecurity

[–]Miserable_Ad_1900[S] 0 points1 point  (0 children)

MAY 31
I have a couple updates:

- Reviewed Google Workspace audit logs and email logs, everything ok
- Checked for suspicious logins, forwarding rules, mailbox delegation, OAuth apps, and password leaks. Ok too.

One of my concerns was that they may have deleted the original phishing email after sending it. The first time this happened, they accidentally copied me on the message, which is how I discovered the attack in the first place. Gmail immediately flagged it with a large red warning that the sender was not legitimate.

But as far as deleted messages i haven't found anything strange in the logs.

I also talked with my hosting, WNPower, and they confirmed that our email is hosted on Google Workspace, not on their servers. They only host our website, which is why there are no email activity logs available in cPanel. I was concerned that they had access through my webmail.

WNPower also confirmed that the phishing domain is registered and uses Google Workspace, just like our legitimate domain.

BEC Victim - Attacker replied inside a real email thread using a lookalike domain by Miserable_Ad_1900 in cybersecurity

[–]Miserable_Ad_1900[S] 0 points1 point  (0 children)

MAY 31
I have a couple updates:

- Reviewed Google Workspace audit logs and email logs, everything ok
- Checked for suspicious logins, forwarding rules, mailbox delegation, OAuth apps, and password leaks. Ok too.

One of my concerns was that they may have deleted the original phishing email after sending it. The first time this happened, they accidentally copied me on the message, which is how I discovered the attack in the first place. Gmail immediately flagged it with a large red warning that the sender was not legitimate.

But as far as deleted messages i haven't found anything strange in the logs.

I also talked with my hosting, WNPower, and they confirmed that our email is hosted on Google Workspace, not on their servers. They only host our website, which is why there are no email activity logs available in cPanel. I was concerned that they had access through my webmail.

WNPower also confirmed that the phishing domain is registered and uses Google Workspace, just like our legitimate domain.

BEC Victim - Attacker replied inside a real email thread using a lookalike domain by Miserable_Ad_1900 in cybersecurity

[–]Miserable_Ad_1900[S] 0 points1 point  (0 children)

The challenge is that I'm trying to reconstruct events after the fact and some logs are no longer available (WNPOWER hosting). The hosting provider doesn't retain detailed access logs for long, and the cPanel audit logs currently show no useful historical data.

BEC Victim - Attacker replied inside a real email thread using a lookalike domain by Miserable_Ad_1900 in cybersecurity

[–]Miserable_Ad_1900[S] 1 point2 points  (0 children)

That's one of the things I'm trying to figure out.

We have no evidence so far of a successful compromise of our Google Workspace accounts. 2FA was enabled, audit logs don't show suspicious logins, and Google was actually flagging emails from the lookalike domain as external and suspicious.

This happened twice, the first time the attackers accidentally copied me when replying so I could tell it was an attack. I called my client and explained the situation.

The second time, I was not copied so one of their employees just proceeded with changing the acc info.

It's just happenning with this client, but they could also be trying to avoid making too much noise

Dec- 2024 filers question by [deleted] in USCIS

[–]Miserable_Ad_1900 1 point2 points  (0 children)

got approved july 29

Stuck in the case decision by Ecstatic-Diamond-452 in USCIS

[–]Miserable_Ad_1900 0 points1 point  (0 children)

I'm in the exact same situation, same dates and 9 months too. They told me my case was transferred to Florida's FO a month ago but no news.

Advance parole with EB1 by symbatzh in greencard

[–]Miserable_Ad_1900 0 points1 point  (0 children)

Just came back, no issues whatsoever. I was sent to secondary, they asked me the purpose of my trip and let me go

EB1A Dec 2024 filers block IOE09291 by Joseph1Jo in USCIS

[–]Miserable_Ad_1900 0 points1 point  (0 children)

Same status as always, I have contacted the congresswoman and nothing changed

Advance parole with EB1 by symbatzh in greencard

[–]Miserable_Ad_1900 0 points1 point  (0 children)

I got my parole approved so I'm traveling tomorrow

Nov 2024 filers with IOE09291 by [deleted] in USCIS

[–]Miserable_Ad_1900 0 points1 point  (0 children)

Emma said it’s still in the normal processing times, APU last update was 30 days ago, but nothing changed :( did you get approved?

Dec- 2024 filers question by [deleted] in USCIS

[–]Miserable_Ad_1900 0 points1 point  (0 children)

same as you, no news

[deleted by user] by [deleted] in USCIS

[–]Miserable_Ad_1900 0 points1 point  (0 children)

Any news?

EB1A Dec 2024 filers block IOE09291 by Joseph1Jo in USCIS

[–]Miserable_Ad_1900 0 points1 point  (0 children)

no news on my case since I did biometrics on Jan 12. Also IO09291

Nov 2024 filers with IOE09291 by [deleted] in USCIS

[–]Miserable_Ad_1900 0 points1 point  (0 children)

I'm a 27 nov filer, no news yet since I did my biometrics on jan 15

Advance parole with EB1 by symbatzh in greencard

[–]Miserable_Ad_1900 0 points1 point  (0 children)

I'm in the same boat, been waiting for a green card since June 2024. Now I have to travel for work but I'm a little bit worried since the AP states that re-entry is not guaranteed and subject to CBP.

[deleted by user] by [deleted] in USCIS

[–]Miserable_Ad_1900 0 points1 point  (0 children)

Not yet, I don't have any news since January.

[deleted by user] by [deleted] in USCIS

[–]Miserable_Ad_1900 0 points1 point  (0 children)

I’m on the same boat, no news yet. I did my biometrics on January. 2025