Ali Chisom
I'm always excited to take on new projects and collaborate with innovative minds.
Lagos

🚨 Phishing Campaign Alert – Targeting Business Emails
Today, I received a well-crafted phishing email on my personal mailbox targeting contact@alichisom.com.
The email claimed:
“Incoming Messages For (contact@alichisom.com ) On Hold”
“You have incoming messages pending on alichisom.com mail server. Release emails to your mailbox.”
It included a “Release Mail” button — designed to create urgency and trigger immediate action.
After analyzing it, the button redirected to the following phishing domain:
The attacker abused a cloudworkstations.dev subdomain to host a fake login page. This is a common tactic because such domains often inherit trust from legitimate cloud infrastructure.
The landing page displayed:
This is classic credential harvesting behavior.
Attackers are increasingly using:
These campaigns bypass basic spam filters and rely heavily on social engineering, not malware.
✔ Always inspect the full URL before logging in
✔ Be suspicious of “urgent mailbox release” emails
✔ Check sender domain carefully (spoofing is common)
✔ Use MFA on all business emails
✔ Report and block phishing domains immediately
As cybersecurity professionals, we must continuously educate users and organizations about evolving phishing tactics.
This was a reminder that even security professionals are targets — and vigilance is non-negotiable.
Stay safe. Stay aware.
— Ali Chisom
System Administrator | Cybersecurity



Your email address will not be published. Required fields are marked *