PULSE NAME
Fake WordPress Domain Renewal Phishing Email Stealing Credit Card And 3-D Secure OTP
WHITE MarinaDiamandis 2026-01-08 Modified: 2026-01-08
1
IOCs
LOW VOLUME
I investigated a phishing email impersonating WordPress.com that claims a domain renewal is due soon and urges immediate action to prevent service disruption. The campaign leads victims to a fake WordPress payment portal hosted on attacker infrastructure and performs theft of credit card details and 3-D Secure OTPs, which are exfiltrated to the attacker via Telegram.
Indicators of Compromise (1)
All URL
TYPEINDICATORDESCRIPTIONCREATED
URL https://soyfix.com/log/log/ 2026-01-08