Nordstrom's email system abused to send crypto scams to customers
嗯,用户让我帮忙总结一篇文章,控制在100字以内,而且不需要用“文章内容总结”这样的开头。首先,我得仔细阅读文章内容,抓住主要信息。 文章讲的是Nordstrom的客户收到了欺诈邮件,这些邮件看起来像是来自Nordstrom的官方邮箱,但实际上是一个加密货币骗局。邮件以圣帕特里克节促销为名,承诺在两小时内将存入指定钱包地址的加密货币金额翻倍。很多客户报告收到了这样的邮件,甚至有些从未在网上泄露过地址的客户也收到了。 骗子利用紧迫感让客户匆忙行动,忽略了错误的公司名称拼写等线索。Nordstrom官方后来发出了警告邮件,说明之前的邮件未经授权,并强调他们不会要求客户使用加密货币进行交易。 进一步的信息显示,这次安全漏洞是通过Okta SSO和Salesforce的妥协实现的,诈骗邮件通过Salesforce Marketing Cloud发送。已经有人向骗子的钱包地址转账,涉及金额超过5600美元。 总结的时候要包括:Nordstrom客户收到欺诈邮件、伪装成促销活动、加密货币骗局、安全漏洞来源、Nordstrom的回应以及建议客户不要转账。 现在把这些信息浓缩到100字以内。确保涵盖主要事件、影响和应对措施。 </think> Nordstrom客户收到伪装成促销活动的欺诈邮件, 骗子利用紧迫感诱导用户向指定钱包地址转账加密货币, 并承诺双倍返还。尽管邮件来自官方地址, 但存在拼写错误等漏洞。Nordstrom已发出警告, 称该信息未经授权, 并强调不会要求客户使用加密货币交易。 2026-3-18 14:0:35 Author: www.bleepingcomputer.com(查看原文) 阅读量:3 收藏

Nordstrom's email system abused to send crypto scams to customers

Customers of upscale department store chain Nordstrom received fraudulent messages from a legitimate company email address that promoted cryptocurrency scams disguised as a St. Patrick’s Day promotion.

The emails promise recipients to double the cryptocurrency amount deposited to a specific wallet address over the next two hours.

"Send cryptocurrency to any of your unique deposit addresses below, and we'll send you right back 200% of the amount you sent," reads the fraudulent message.

Multiple customers reported on social media [1, 2] that they received such emails. Some said that the message arrived to an address that had never been exposed or leaked online.

By giving recipients only two hours to take action, the threat actor creates a sense of urgency that makes it more likely for Nordstrom customers to rush into the "deal" and fail to notice the signs of a scam, such as the incorrect spelling of the company in the heading, which reads “Normstorm.”

The scam email sent to Nordstorm customers
The scam email sent to Nordstorm customers
Source: X

However, any signs of deception could easily be ignored because the emails came from [email protected], an official address the company uses for sending marketing, sales, and promotional communication, indicating a security breach.

Nordstrom did not respond to BleepingComputer’s request for comments on the matter, but customers reported that the company sent out a warning email urging members to disregard the previous message, which was “unauthorized.”

“Nordstrom will never ask customers to transact or otherwise transfer funds using cryptocurrency,” warned the firm in its message to customers. “We are taking immediate action to investigate and address the issue,” the department store said.

The follow-up communication by the firm
The follow-up communication by the firm
Source: X

Nordstrom is a large fashion retailer in the U.S., selling clothing, shoes, beauty products, and accessories through physical department stores and online shops.

Founded in 1901, the company has millions of customers, employs 55,000 people, and has an annual revenue of over $15 billion.

It’s unclear if the unauthorized message reached the entire registered customer base of Nordstrom, but some recipients have already sent payments to the fraudster's wallet address.

The wallets used in the crypto scam shows that the threat actor received a little over $5,600 in cryptocurrency since the emails were sent.

A source familiar with the incident told BleepingComputer that the security breach occurred via an Okta SSO > Salesforce compromise, and the scam emails were then sent to customers through Salesforce Marketing Cloud.

Although BleepingComputer couldn't confirm, this incident is similar to recent attacks on Betterment and GrubHub that also pushed crypto scams.

Nordstrom customers are advised to ignore the promotion message and not send any money or disclose sensitive data.

Suspicious content should be treated with caution, even when it comes from a trusted sender address, and any promotions should be verified by visiting the firm’s official website, communication channels, and social media profiles.\

Update 3/18/26: Article updated to correct Salesforce Experience Cloud to Salesforce Marketing Cloud.

tines

Red Report 2026: Why Ransomware Encryption Dropped 38%

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.


文章来源: https://www.bleepingcomputer.com/news/security/nordstroms-email-system-abused-to-send-crypto-scams-to-customers/
如有侵权请联系:admin#unsafe.sh