.avif?width=640&quality=80&format=auto&cache=true&immutable=true&cache-control=max-age%3D31536000)
INC-2025-001: Ausnutzung von Sophos Email zum Senden von Spam-Nachrichten
Overview
On April 14, 2025, at 15:54 UTC, a report surfaced that users were receiving spam orignating from the sophos.com domain. Within the hour our Sophos Internal Detection and Response team was made aware and began investigating the report.
Our investigation found that trial accounts were being used to exploit a logic flaw in how Sophos Email validates whether senders are authorized to relay through our cloud email service.
Our team took immediate action, including blocking the accounts and IPs involved in the abuse, during an investigation into how the attackers were able to bypass that validation policy.
The investigation determined that the logic used to constrain a customer account to only send mail from domains they control wasn’t strict enough. Permanent solutions were implemented to prevent this abuse in the future. Additionally, restrictions were imposed on trial accounts to prevent future attempts to find flaws by unverified accounts.
Impact
The attackers were able to send approximately 1.9 million non-malicious spam messages through Sophos gateways. The abuse primarily used the outbound email addresses info [AT] sophos [DOT] com and news [AT] sophos [DOT] com, but did include 30 messages impersonating the domains of 12 Sophos Email customers. All impacted customers have been notified by Sophos Support.
Timeline
Time Event April 2, 2025 First trial account created by Threat Actors (TA) to figure out how to bypass outbound filtering policy intended to prevent domain impersonation. April 13, 2025 18:00 UTC TA begins sending large quantities of email outbound through Sophos Email gateways. April 14, 2025 15:54 UTC Initial post to Reddit by /u/jegraves puzzling over spam originating from info [AT] sophos [DOT] com. April 14, 2025 16:52 UTC Sophos Internal Detection and Response team (IDR) is made aware of the Reddit post and triages incident. April 14, 2025 17:05 UTC Sophos IDR begins investigation involving key stakeholders. April 14, 2025 19:07 UTC Sophos blocks the domain linked from the spam campaign. April 15, 2025 06:00 UTC Changes are pushed to production to prevent spoofing of sophos.com. April 15, 2025 16:33 UTC All IPs and email addresses related to the abuse are blocked in Sophos Email. April 17, 2025 11:51 UTC Deactivated all trial accounts linked to spam campaigns. April 19, 2025 04:59 UTC Changed policy to prevent future trial accounts from sending outbound emails not managed by a partner or reseller.
| Time | Event |
|---|---|
| April 2, 2025 | First trial account created by Threat Actors (TA) to figure out how to bypass outbound filtering policy intended to prevent domain impersonation. |
| April 13, 2025 18:00 UTC | TA begins sending large quantities of email outbound through Sophos Email gateways. |
| April 14, 2025 15:54 UTC | Initial post to Reddit by /u/jegraves puzzling over spam originating from info [AT] sophos [DOT] com. |
| April 14, 2025 16:52 UTC | Sophos Internal Detection and Response team (IDR) is made aware of the Reddit post and triages incident. |
| April 14, 2025 17:05 UTC | Sophos IDR begins investigation involving key stakeholders. |
| April 14, 2025 19:07 UTC | Sophos blocks the domain linked from the spam campaign. |
| April 15, 2025 06:00 UTC | Changes are pushed to production to prevent spoofing of sophos.com. |
| April 15, 2025 16:33 UTC | All IPs and email addresses related to the abuse are blocked in Sophos Email. |
| April 17, 2025 11:51 UTC | Deactivated all trial accounts linked to spam campaigns. |
| April 19, 2025 04:59 UTC | Changed policy to prevent future trial accounts from sending outbound emails not managed by a partner or reseller. |