IRONSCALES’ cover photo
IRONSCALES

IRONSCALES

Computer and Network Security

Atlanta, Georgia 20,934 followers

The leading enterprise cloud email security platform combining AI and human insights protecting 18,000 global customers.

About us

IRONSCALES is the leader in AI-powered email security protecting over 17,000 global organizations from advanced phishing threats. As the pioneer of adaptive AI, we detect and remediate attacks like business email compromise (BEC), account takeovers (ATO), and zero-days that other solutions miss. By combining the power of AI and continuous human insights, we safeguard inboxes, unburden IT teams, and turn employees into a vital part of cyber defense across enterprises and managed service providers. IRONSCALES is headquartered in Atlanta, Georgia. To learn more, visit  www.ironscales.com  or follow us on X  @IRONSCALES

Website
https://ironscales.com
Industry
Computer and Network Security
Company size
51-200 employees
Headquarters
Atlanta, Georgia
Type
Privately Held
Founded
2014
Specialties
Automated Phishing Response, Phishing Awareness, Phishing Assesment, Phishing Mitigation, Phishing Remediation, Threat Intelligence , Email Phishing, Ransomware Protection, Machine Learning, Email Security, Anti phishing, BEC, Phishing, AI, Business Email Compromise, Advanced Threat Protection, Incident Response, and Credential Theft

Locations

Employees at IRONSCALES

Updates

  • The DKIM signature on this phishing email passed, signed by the key of the company that received it. The only result that failed was DMARC, for a header From domain nobody in the delivery path owned, because nothing was forged: someone had working credentials for a small business's mailbox and submitted over SMTP AUTH, and that business is a victim, not a participant. Six ARC seals across three providers carried that genuine authentication to a European cyber-insurance provider's executive. Microsoft had already scored it SCL:9, but inside a partner tenant, and the partner's auto-forward moved the message without the verdict. Themis flagged it at confidence 84 and an independent scanner rated the terminal host malicious: model and scanner evidence, not a human adjudication. (Link to full teardown in comments)

  • An attacker impersonated UK Visas and Immigration with a security upgrade notice for the Sponsorship Management System, the real Home Office portal that any organisation holding a visa sponsor licence has to use. The email body carried no links at all. The entire payload was a one-page PDF with no JavaScript, no automatic action dictionary and no embedded file - just one clickable button pointing at an HTML page in a European object-storage bucket. Its GOV.UK-style footer held five more link annotations, and every one of them had an empty destination. Help, Security, Terms, UK Visas and Immigration, Home Office: decoration. Real government templates do not ship dead links. The Reply-To was set to an address on the real Home Office domain, which is bait rather than infrastructure - a reply goes to the actual Home Office, not the attacker. DKIM was never applied and DMARC failed against a published reject policy. The inline gateway scored the message clean and delivered it to three mailboxes. (Link to full teardown in comments)

  • Is https://lnkd.in/g5apCQWw legit? Yes. So are c.gle, forms.cloud.microsoft, message@adobe.com and mail.hellosign.com. We caught phishing sent through all five. Every message passed SPF, DKIM and DMARC, because the platform itself sent it on behalf of an account the attacker created or compromised. Swipe for what each attacker did and the one check that would have caught it. The full guide covers 10 domains people search for, plus the security-vendor link wrappers that get searched the same way. \(Link in comments\)

  • Julia Frament sharing a great perspective in The HR World, on what it takes for HR to operate at the executive level.

    Nice surprise to see this pop up in The HR World, a feature on what it takes for HR to operate at the executive level, with some sharp perspectives from HR leaders across the UK. My contribution was about proactive HR, building infrastructure before the business needs it rather than scrambling once something breaks. I also talked about transformation needing to raise both the floor and the ceiling, equipping the existing team while raising the hiring bar. At IRONSCALES that works because we now have a dedicated Head of AI Operations, Tyler Swinehart, driving the infrastructure, while I focus on certification and hiring. But honestly, the credit goes to the Scalers themselves, who have leaned all the way into their own development and made becoming AI first a shared mission rather than a mandate from the top. Good reminder that this kind of work only sticks when more than one person owns a piece of it. Always thankful for the opportunity to share my perspective!

  • Two captures of the same phishing URL, taken two days apart, returned two different pages. On the send date: a dark, Credit Agricole-branded "Verification de securite" page that demanded a CAPTCHA code before anything else would load. Two days later: a plain French notice saying the service was not accessible from the visitor's geographic location, with a panel labelling the country it had detected and the IP it had refused. It printed its own filtering decision back at the request. Every link verdict in the incident record reads Clean. That is what a URL verdict measures - the response one request received, at one moment, from one network position. Not a property of the destination. The landing domain is not a bank domain, and Credit Agricole is a bystander whose brand and palette were copied without its involvement. The mail itself was sent through the abused bulk-mail account of a US technical college, another uninvolved bystander, which is why SPF, DKIM and DMARC all passed - true, and beside the point. Themis scored the incident at 88 with a Credential Theft label, supported by two community-reputation insights drawn from resolutions of similar incidents, and all three mailboxes were mitigated within seconds. Stop treating a clean URL verdict as evidence of a safe destination. (Link to full teardown in comments)

  • What got past your SEG filters this week? A bank lure told three engineers their device would be blocked tomorrow. The page behind its button showed a CAPTCHA on the day it was sent. Two days later, the same URL served a French geo-block notice that printed the visitor's own country and IP back at them. Every link verdict in the record read Clean. This week's Interception breaks it down, plus four more that cleared the filters.

  • AI writes a flawless phishing email now. Perfect grammar, perfect logo. Jess Burn points out the tells that survive anyway: authority, novelty, urgency. Her fix: make pausing normal, make "let me call you back" polite, and when someone stops an attack, tell the whole company. (Link to the full session in the comments)

  • A document-share lure reached four senior mailboxes at a multinational consumer goods group. SPF passed, and the header that explains why also named the attacker. The Korean shared mail platform that relayed the message adds an X-Authinfo line recording which account authenticated the outbound SMTP session. That account was a mailbox at one company, the From address belonged to a second and unrelated one, and the session came from a Microsoft Azure IP. The lure impersonated the recipient's own employer instead of a software brand, and the link ran a silent identity probe - identity scopes only, no mailbox access. All four were quarantined, and a human analyst confirmed the sender malicious. (Link to full teardown in comments)

  • Homework from Jess Burn that takes one afternoon: add API keys and personal access tokens to your outbound DLP rules. Everybody is wiring tools into ChatGPT and Claude for the first time, and one captured token can do a lot of damage. (Link to the full session in the comments)

  • Three mailboxes at one multinational industrial group received the same attack inside three hours and thirty-seven minutes, each with its own per-recipient code in the format XXXX-XXXXXX-XXXX. In one message that code appeared five times, ending as the fragment key whose value was the recipient's own mailbox in base64. The body held the gateway's caution banner and ten line breaks: no text, no images, no links. The whole attack was an untitled PDF, scored Clean and correctly so, whose single button hit a real email-marketing platform's unsubscribe API and used the redirect parameter that endpoint exposes, recycled whole from a genuine 2023 marketing send. SPF, DKIM and DMARC all passed, honestly. Human review pulled all three back the same day. (Link to full teardown in comments)

Similar pages

Browse jobs