KB-4170mediumIntake
Executive impersonation + wire-fraud lure domain
Lookalike domain impersonating the client's CFO, used in a wire-fraud lure to two vendors. Awaiting counsel assignment. Packet ready for engagement.
Client
Delphi Holdings
client
Counsel
Unassigned
awaiting engagement
Type
Impersonation / Fraud
Opened
2026-06-16
2 exposures
The red element
Who and what is behind it
actorUS registrar
delph1-holdings.com
Lookalike domain, MX configured
sourceunknown
sender infrastructure
Shared bulletproof host
Status ledger
We track. Counsel acts.
registrarAbuse / UDRP prepQueued2026-06-16
Evidence
Captured and hashed at discovery
Domain WHOISwhois
2026-06-16 11:05sha256 ecbd…ceea
Lure email headersheader
2026-06-16 11:02sha256 c0c6…5aef
Timeline
Auditable, shared with counsel
Matter created from Defender scan. 4 exposures, severity medium.
system · 2026-06-16 11:00
Awaiting counsel. Packet ready for engagement.
system · 2026-06-16 11:30