← Matters
KB-4170mediumIntake

Executive impersonation + wire-fraud lure domain

Lookalike domain impersonating the client's CFO, used in a wire-fraud lure to two vendors. Awaiting counsel assignment. Packet ready for engagement.

Client
Delphi Holdings
client
Counsel
Unassigned
awaiting engagement
Type
Impersonation / Fraud
Opened
2026-06-16
2 exposures
Push to practice
The red element
Who and what is behind it
actor
delph1-holdings.com
Lookalike domain, MX configured
US registrar
source
sender infrastructure
Shared bulletproof host
unknown
Status ledger
We track. Counsel acts.
registrarAbuse / UDRP prepQueued2026-06-16
Evidence
Captured and hashed at discovery
Domain WHOISwhois
2026-06-16 11:05sha256 ecbd…ceea
Lure email headersheader
2026-06-16 11:02sha256 c0c6…5aef
Timeline
Auditable, shared with counsel
Matter created from Defender scan. 4 exposures, severity medium.
system · 2026-06-16 11:00
Awaiting counsel. Packet ready for engagement.
system · 2026-06-16 11:30