A coordinated phishing campaign is actively targeting HubSpot users using a mix of business email compromise and infrastructure abuse. The attack relies on trusted platforms, compromised domains, and subtle email tricks to bypass security controls and convince users to log in. Instead of deploying traditional malware, attackers harvest valid HubSpot credentials through realistic fake login pages. Marketing teams and business users are the primary targets, making this a high risk issue for organizations that depend on HubSpot for daily operations.
Relevant Source (IBM X-Force Exchange): Active HubSpot Phishing Campaign
IBM’s advisory documents an active HubSpot-focused phishing campaign that hides the malicious link in the sender display name and redirects to credential-harvesting infrastructure.
Quick Facts
- HubSpot users are being targeted by a live phishing campaign.
- Emails claim unusual unsubscribe activity to create urgency.
- MailChimp is used to distribute phishing emails at scale.
- Malicious links are hidden in the sender display name.
- Fake HubSpot login pages steal real credentials.
- Hosting infrastructure is tied to repeat phishing activity.
How The HubSpot Phish Works
This campaign is a targeted credential phishing operation aimed at HubSpot accounts used by marketing and business teams. Attackers send convincing emails that appear to come from legitimate business accounts and trusted marketing platforms. The emails push recipients to log in quickly by warning of abnormal unsubscribe spikes. Once credentials are entered on a fake HubSpot login page, attackers gain direct access to real accounts.
- Uses business email compromise rather than malware
- Exploits trust in MailChimp and legitimate domains
- Steals credentials through cloned HubSpot login pages
Unlike noisy attacks that rely on attachments or obvious malicious links, this operation stays quiet. The goal is account takeover, not immediate system damage, which makes detection harder and long term impact more severe.
Relevant Source (Palo Alto Networks Unit 42): Abused HubSpot Free Form Builder
Unit 42 documents attackers using HubSpot-hosted pages and realistic lures to harvest credentials for account takeover without relying on traditional malware.
Why Stolen HubSpot Logins Hurt
HubSpot accounts often have deep access to customer data, marketing automation, and internal communications. A compromised account can be used to steal contact lists, send further phishing emails, or manipulate marketing campaigns. Because the attack uses trusted infrastructure and subtle techniques, many security tools fail to flag it. The result is a higher chance of successful compromise with real business consequences.
- Marketing contact databases can be exfiltrated
- Attackers can launch follow up phishing from trusted accounts
- Brand reputation can be damaged by malicious campaigns
- Security teams may not see alerts or warnings
- Credential reuse can expose other internal systems
The absence of malware does not mean the absence of risk. Credential theft often leads to wider breaches that unfold over weeks rather than hours.
Relevant Source (New Zealand NCSC): Impacting NZ Organisations
Compromised user accounts are used to send follow-on phishing from trusted contacts while harvesting credentials or session tokens, raising the odds of quiet account takeover.
Immediate HubSpot Phishing Steps
Organizations should treat this as a warning that standard email filtering is no longer enough. Security controls must account for manipulation of sender fields and trusted platforms. User awareness also plays a major role, especially for teams that regularly interact with marketing alerts and analytics emails.
- Enforce multi factor authentication on HubSpot accounts
- Train users to inspect sender display names and headers
- Monitor for unusual login locations and activity
- Limit account permissions to what is strictly necessary
- Review outbound email activity for signs of abuse
Fast action reduces the window attackers have to exploit stolen credentials. Waiting for automated alerts is no longer sufficient.
Relevant Source (CISA): Weak Security Controls And Practices Exploited
CISA recommends MFA, tighter access controls, and monitoring for anomalous authentication activity to reduce the impact of credential phishing and account takeover.
Phishing Becomes A Pro Operation
This campaign reflects a broader shift in phishing tactics toward infrastructure abuse and psychological precision. Attackers are no longer relying on sloppy emails or obvious red flags. They are blending into normal business workflows and using trusted tools to do it. That makes human judgment and layered security more important than ever.
The infrastructure details uncovered by researchers reinforce this trend. The use of Plesk managed servers with exposed mail services allows rapid deployment and rotation of phishing assets. Hosting tied to repeated campaigns shows organization, planning, and persistence. These are not opportunistic attacks but part of an ongoing professional operation.
Relevant Source (CISA): Mitigate Risks From Bulletproof Hosting Providers
CISA describes how bulletproof hosting enables repeatable phishing and other cybercrime by helping attackers rapidly stand up and rotate infrastructure while resisting takedowns.
Phishing Defenses That Work
Phishing defenses must evolve beyond scanning email bodies and blocking known bad links. Organizations need visibility into how emails are constructed and how users interact with them. Credential protection should be treated as critical infrastructure, not a convenience feature.
Security teams that adapt to these realities reduce risk. Those that rely on outdated assumptions remain exposed.
Relevant Source (UK NCSC): Defending Your Organisation
Guidance on layered anti-phishing controls that go beyond link scanning, including user reporting, filtering, and account protections to reduce credential theft.
FAQ
Is this attack delivering malware?
No. The attack focuses on stealing login credentials rather than installing malware on devices.
Why do the emails bypass security filters?
Malicious URLs are embedded in the sender display name, which many email security tools do not scan.
Who is most at risk?
Marketing professionals and business teams that regularly use HubSpot and MailChimp.
What happens after credentials are stolen?
Attackers can access HubSpot accounts, steal data, and send phishing emails from trusted accounts.
Does multi factor authentication help?
Yes. MFA significantly reduces the impact of stolen credentials and is strongly recommended.
How JENI Helps Reduce Credential Risk
Phishing attacks that steal credentials often leave systems unstable, misconfigured, and silently compromised. Even when no malware is installed, attackers frequently modify system settings, network services, and cached credentials to maintain access. That lingering damage is where many security failures begin.
Where JENI Fits In
- Repairs corrupted system components that attackers often touch during credential abuse
- Resets network, DNS, firewall, and cache layers used to persist access
- Runs fully local with no cloud access, telemetry, or credential harvesting
JENI focuses on restoring system integrity after real world security incidents, not chasing signatures or scanning inboxes. When credentials are stolen, affected machines often show subtle instability, network misbehavior, or permission issues that standard antivirus tools ignore. JENI addresses those underlying conditions using trusted system level repair methods. The result is a cleaner, more predictable environment that reduces the chance of secondary compromise and long term exposure.

