Daud Jawad, Security Engineer at Fortra, is featured in Unite.AI for FIRE team research into a CalPhishing campaign that turns internal email forwards into credential-stealing lures. The campaign uses trusted workplace interactions and malicious booking links to target Microsoft 365 credentials. The findings show why organizations should validate external destinations, even when links are forwarded by trusted colleagues.
“This is the central innovation in the campaign. Traditional phishing often depends on impersonating someone the target trusts. Here, the attacker persuades a real, trusted person to deliver the lure without realizing it.”