Skip to Content
Shared - Banner with Media - Background

INC-2025-001: Ausnutzung von Sophos Email zum Senden von Spam-Nachrichten

Overview

On April 14, 2025, at 15:54 UTC, a report surfaced that users were receiving spam orignating from the sophos.com domain. Within the hour our Sophos Internal Detection and Response team was made aware and began investigating the report.

Our investigation found that trial accounts were being used to exploit a logic flaw in how Sophos Email validates whether senders are authorized to relay through our cloud email service.

Our team took immediate action, including blocking the accounts and IPs involved in the abuse, during an investigation into how the attackers were able to bypass that validation policy.

The investigation determined that the logic used to constrain a customer account to only send mail from domains they control wasn’t strict enough. Permanent solutions were implemented to prevent this abuse in the future. Additionally, restrictions were imposed on trial accounts to prevent future attempts to find flaws by unverified accounts.

Impact

The attackers were able to send approximately 1.9 million non-malicious spam messages through Sophos gateways. The abuse primarily used the outbound email addresses info [AT] sophos [DOT] com and news [AT] sophos [DOT] com, but did include 30 messages impersonating the domains of 12 Sophos Email customers. All impacted customers have been notified by Sophos Support.

Timeline


TimeEvent
April 2, 2025First trial account created by Threat Actors (TA) to figure out how to bypass outbound filtering policy intended to prevent domain impersonation.
April 13, 2025 18:00 UTCTA begins sending large quantities of email outbound through Sophos Email gateways.
April 14, 2025 15:54 UTCInitial post to Reddit by /u/jegraves puzzling over spam originating from info [AT] sophos [DOT] com.
April 14, 2025 16:52 UTCSophos Internal Detection and Response team (IDR) is made aware of the Reddit post and triages incident.
April 14, 2025 17:05 UTCSophos IDR begins investigation involving key stakeholders.
April 14, 2025 19:07 UTCSophos blocks the domain linked from the spam campaign.
April 15, 2025 06:00 UTCChanges are pushed to production to prevent spoofing of sophos.com.
April 15, 2025 16:33 UTCAll IPs and email addresses related to the abuse are blocked in Sophos Email.
April 17, 2025 11:51 UTCDeactivated all trial accounts linked to spam campaigns.
April 19, 2025 04:59 UTCChanged policy to prevent future trial accounts from sending outbound emails not managed by a partner or reseller.