A major sportswear brand's legitimate email domain was compromised and used to launch a large-scale phishing campaign, as observed by KnowBe4 analysts. Attackers exploited the trust associated with the brand to send polymorphic phishing emails that bypassed traditional email defenses, employing advanced social engineering tactics and frequently changing payloads to evade detection. The campaign demonstrated how attackers can move laterally within an organization, extend their reach to additional victims, and continue impersonation efforts even after the initial compromise, highlighting the persistent threat to high-profile brands.
Recent research presented by Okta further underscores the ongoing risk posed by phishing attacks, revealing that even organizations with advanced security measures remain vulnerable. The study found that traditional defenses such as email gateways, endpoint protection, and user training are often insufficient to stop sophisticated phishing campaigns, with American enterprises and Office 365 users being particularly frequent targets. These findings illustrate the persistent and evolving nature of phishing threats, especially when attackers leverage compromised trusted domains to increase their success rates.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Okta analyzed 26 months of FastPass authentication logs and found that sophisticated phishing attacks continued to evade common enterprise controls such as email gateways, endpoint protection, and user training. The study also found American organizations and Office 365 were frequent targets, while phishing-resistant authentication adoption remained limited.
KnowBe4 Defend detected the phishing campaign leveraging the compromised sportswear brand domain and documented how attackers rapidly exploited a compromised business email account for broad abuse. The report highlighted the use of obfuscated payloads, varied subject lines, and trust in a legitimate domain to increase delivery and effectiveness.
Between October 29 and 30, 2025, attackers used the compromised domain of a major global sportswear brand to send polymorphic phishing emails that bypassed SPF, DKIM, DMARC, and secure email gateways. The campaign targeted organizations in 80 countries, used region-specific lures and credential-harvesting sites, and impersonated entities such as UK Visa and Immigration and Microsoft.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.