A large-scale fraudulent operation has been traced back to an unidentified cybercriminal who leveraged a flaw in the email routing setup of the email security provider Proofpoint. This vulnerability allowed the actor to dispatch millions of deceptive emails pretending to come from well-known companies such as Best Buy, IBM, Nike, and Walt Disney.
“These emails appeared to come from legitimate Proofpoint servers, complete with valid SPF and DKIM signatures, effectively circumventing significant security barriers—aimed at tricking recipients and pilfering funds and credit card information,” explained Nati Tal, a researcher from Guardio Labs, in an in-depth report provided to The Hacker News.
The cybersecurity firm has dubbed this scheme EchoSpoofing. It is believed that the campaign began in January 2024, with the perpetrator exploiting the security loophole to send an average of three million emails daily, peaking at 14 million in early June when Proofpoint began implementing countermeasures.
Tal highlighted that the most striking feature of this scheme is its sophisticated spoofing method, which makes it nearly impossible for recipients to distinguish these emails from legitimate correspondence from the targeted companies.
“This EchoSpoofing approach is remarkably effective. It’s unusual that it’s being employed in such a broad phishing attack rather than in a more targeted spear-phishing effort—where an attacker could impersonate a real employee to deceive other staff members, potentially gaining access to sensitive internal data or compromising the entire organization through high-quality social engineering.”
The technique involves sending emails from an SMTP server on a virtual private server (VPS) while adhering to security standards like SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail), which are designed to thwart domain impersonation. The emails are routed through various compromised Microsoft 365 tenants and then relayed through Proofpoint’s email infrastructure to reach users of services like Yahoo!, Gmail, and GMX.
This issue stems from what Guardio termed a “super-permissive misconfiguration flaw” in Proofpoint’s servers (under the domain “pphosted.com”), which allowed spammers to exploit the email routing setup to send fraudulent emails.
“The core problem lies in a configurable feature on Proofpoint’s servers that permits relay of outbound messages from Microsoft 365 tenants without restricting which tenants are allowed,” Proofpoint explained in a disclosure report to The Hacker News.
In essence, attackers can exploit this flaw by setting up rogue Microsoft 365 tenants and sending spoofed messages through Proofpoint’s relay servers, making them appear as if they are from legitimate domains.
This is achieved by configuring the Exchange Server’s outgoing email connector to route through the vulnerable “pphosted.com” endpoint associated with the customer. Additionally, a pirated version of the legitimate email software PowerMTA was used to dispatch the messages.
“The spammer employed a rotating array of leased VPSs from various providers, using different IP addresses to send bursts of thousands of messages at a time from their SMTP servers to Microsoft 365, which then relayed them through Proofpoint’s infrastructure,” Proofpoint detailed.
“Microsoft 365 accepted these spoofed emails and forwarded them through the customers’ email systems. Because the emails were relayed through the customer’s infrastructure, DKIM signing was applied, making the spam messages more likely to be delivered.”
EchoSpoofing appears to have been strategically chosen to maximize illicit revenue while minimizing detection risks. A direct attack on the companies could have significantly increased the risk of detection, jeopardizing the entire operation.
Currently, the identity of the responsible party remains unknown. Proofpoint has stated that this activity does not align with any known threat actor or group.
“In March, Proofpoint discovered spam campaigns relayed through a few Proofpoint customers’ email systems, originating from Microsoft 365 tenants,” the company stated. “All indications suggest this was the work of a single spam actor, with no connection to any known entity.”
“Since discovering the spam campaign, we have worked to provide corrective measures, including an enhanced administrative interface for customers to control which M365 tenants are permitted to relay messages, with all other tenants blocked by default.”
Proofpoint assured that no customer data was compromised, nor was there any data loss resulting from these campaigns. The company also reached out to some of its clients to adjust their settings and mitigate the effectiveness of the spam relays.
“As we began blocking the spammer’s activities, they quickly shifted to target other customers,” the company noted. “We have established an ongoing process to identify affected customers daily and prioritize fixing their configurations.”
To combat such threats, Proofpoint is advising VPS providers to restrict users’ ability to send large volumes of emails from SMTP servers hosted on their platforms. Additionally, email service providers are encouraged to limit the capabilities of free trial and newly created unverified tenants to send bulk outbound messages and prevent domain spoofing.
“For CISOs, the key takeaway is to carefully manage their organization’s cloud services, particularly those involving third-party providers integral to their networking and communication,” Tal advised. “Maintaining vigilance and control over your email services is crucial, even if you fully trust your email provider.”
“For other companies offering backbone services, like Proofpoint, it is essential to anticipate a wide range of potential threats. This responsibility extends beyond protecting their own customers to safeguarding the broader public.”
“As the saying goes, ‘With great power comes great responsibility.’ This principle is particularly relevant for companies managing critical internet infrastructure.”



