{"id":4768,"date":"2026-01-07T19:53:40","date_gmt":"2026-01-07T19:53:40","guid":{"rendered":"https:\/\/nikola-breznjak.com\/blog\/?p=4768"},"modified":"2026-02-25T15:23:15","modified_gmt":"2026-02-25T15:23:15","slug":"sendgrid-phishing-scam-attempts","status":"publish","type":"post","link":"https:\/\/nikola-breznjak.com\/blog\/miscellaneou\/sendgrid-phishing-scam-attempts\/","title":{"rendered":"SendGrid Phishing Scam Attempts"},"content":{"rendered":"<h2>TL;DR<\/h2>\n<p>Over the past few days I started getting a bunch of weird error emails in my inbox from, what seemed to be, <strong>SendGrid<\/strong>. The subjects all looked technical; things like \u201cAPI Endpoint Failure\u201d or \u201cmessages are not processing via \/v1\/send\u201d. Enough to make any developer raise an eyebrow \ud83e\udd28<\/p>\n<p>What&#8217;s going on is simple: some mail servers seem to have been compromised over the holidays and a bunch of <em>not-so-nice people<\/em> are sending <strong>phishing emails posing as SendGrid<\/strong>.<\/p>\n<p>Now, if you&#8217;re not using SendGrid, you&#8217;d probably ignore them right away.<\/p>\n<p>However, the goal is to get you to click a link that leads to a page that <strong>looks exactly like the real SendGrid login<\/strong> \u2014 and if you&#8217;re not careful, enter your real credentials (which they&#8217;ll happily store for future use \ud83d\ude05).<\/p>\n<p>What makes this unusual is that Google hasn&#8217;t flagged these as spam yet, so be wary.<\/p>\n<h2>What You Should Do<\/h2>\n<ul>\n<li><strong>Don&#8217;t click any links<\/strong> in the message.<\/li>\n<li><strong>Mark the message as spam or phishing<\/strong> in your email client.<\/li>\n<li>If you <em>do<\/em> use the service, open your dashboard manually and check logs rather than clicking through the email.<\/li>\n<\/ul>\n<h2>Examples<\/h2>\n<p>Here are just some examples, so you can get an idea of what to look for. One common sign is that the email claims to be from SendGrid, but the <strong>domain in the \u201csigned-by\u201d field<\/strong> is something you&#8217;ve never heard of.<\/p>\n<p><a href=\"https:\/\/nikola-breznjak.com\/blog\/wp-content\/uploads\/2026\/01\/5.png\" rel=\"lightbox[4768]\"><img decoding=\"async\" src=\"https:\/\/nikola-breznjak.com\/blog\/wp-content\/uploads\/2026\/01\/5-300x163.png\" alt=\"\" \/><\/a><br \/>\n<a href=\"https:\/\/nikola-breznjak.com\/blog\/wp-content\/uploads\/2026\/01\/2.png\" rel=\"lightbox[4768]\"><img decoding=\"async\" src=\"https:\/\/nikola-breznjak.com\/blog\/wp-content\/uploads\/2026\/01\/2-300x266.png\" alt=\"\" \/><\/a><br \/>\n<a href=\"https:\/\/nikola-breznjak.com\/blog\/wp-content\/uploads\/2026\/01\/3.png\" rel=\"lightbox[4768]\"><img decoding=\"async\" src=\"https:\/\/nikola-breznjak.com\/blog\/wp-content\/uploads\/2026\/01\/3-300x184.png\" alt=\"\" \/><\/a><br \/>\n<a href=\"https:\/\/nikola-breznjak.com\/blog\/wp-content\/uploads\/2026\/01\/4.png\" rel=\"lightbox[4768]\"><img decoding=\"async\" src=\"https:\/\/nikola-breznjak.com\/blog\/wp-content\/uploads\/2026\/01\/4-284x300.png\" alt=\"\" \/><\/a><br \/>\n<a href=\"https:\/\/nikola-breznjak.com\/blog\/wp-content\/uploads\/2026\/01\/5.png\" rel=\"lightbox[4768]\"><img decoding=\"async\" src=\"https:\/\/nikola-breznjak.com\/blog\/wp-content\/uploads\/2026\/01\/5-300x163.png\" alt=\"\" \/><\/a><\/p>\n<h2>Conclusion<\/h2>\n<p>Remember, <strong>always, always, always<\/strong> check the actual <strong>From<\/strong> in an email if it looks remotely shady.<\/p>\n<p>Stay safe!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>TL;DR Over the past few days I started getting a bunch of weird error emails in my inbox from, what seemed to be, SendGrid. The subjects all looked&hellip;<\/p>\n","protected":false},"author":1,"featured_media":4776,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[32],"tags":[],"class_list":["post-4768","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-miscellaneou"],"_links":{"self":[{"href":"https:\/\/nikola-breznjak.com\/blog\/wp-json\/wp\/v2\/posts\/4768","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nikola-breznjak.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nikola-breznjak.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nikola-breznjak.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nikola-breznjak.com\/blog\/wp-json\/wp\/v2\/comments?post=4768"}],"version-history":[{"count":0,"href":"https:\/\/nikola-breznjak.com\/blog\/wp-json\/wp\/v2\/posts\/4768\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nikola-breznjak.com\/blog\/wp-json\/wp\/v2\/media\/4776"}],"wp:attachment":[{"href":"https:\/\/nikola-breznjak.com\/blog\/wp-json\/wp\/v2\/media?parent=4768"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nikola-breznjak.com\/blog\/wp-json\/wp\/v2\/categories?post=4768"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nikola-breznjak.com\/blog\/wp-json\/wp\/v2\/tags?post=4768"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}