‘This campaign works because it looks normal’: Experts reveal how hackers use fake DHL messages to lure victims



  • Phishing campaign spoofs DHL emails to steal login credentials
  • Victims are tricked with fake consignment note confirmation and staged validation steps
  • The captured data, including passwords and device details, is sent directly to the attackers’ mailboxes.

Forcepoint has published a report about an ongoing phishing campaign designed to steal people’s DHL login credentials.

It begins by sending an email to the victim, requesting confirmation of a consignment note. While the email itself looks authentic and is designed in the same way as legitimate DHL emails, this one is easy to detect as fake: the domain used to send the message is cupelva.[.]com – completely unrelated to DHL.

Leave a Comment

Your email address will not be published. Required fields are marked *