AT&T-Themed Phishing Campaign Abuses Open Redirect Vulnerability (noSuchEntryRedirect) to Harvest SSN, Credit Card, and CVV Data — Threadlinqs Intelligence
As of 2026-07-22, AT&T-Themed Phishing Campaign Abuses Open Redirect Vulnerability (noSuchEntryRedirect) to Harvest SSN, Credit Card, and CVV Data is a medium-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-1607 · Severity: MEDIUM · Status: ACTIVE · Category: PHISHING
A phishing campaign impersonating AT&T sends fake payment-failure emails threatening 48-hour service disconnection. The lure link abuses a legitimate third-party website's open redirect flaw (via a
MailGuard reported an active phishing campaign spoofing "AT&T My Account" as the sender, using an urgency-driven payment-failure notice that threatens service interruption within 48 hours to pressure recipients into clicking an "UPDATE PAYMENT METHOD HERE" button. Rather than linking directly to attacker infrastructure, the email link points to a legitimate, unrelated website's redirect-handling endpoint. That endpoint exposes a "noSuchEntryRedirect" parameter intended to route users somewhere sane after a 404 (page-not-found) condition; the attackers instead engineer the 404 path to be redirected to their own phishing page. Because the initial URL a security scanner or reputation engine sees resolves to a trusted, legitimate domain, this open-redirect abuse defeats domain-reputation and simple URL-scanning defenses that only inspect the link at time of delivery rather than at time of click. The resulting fraudulent page mimics an AT&T billing/payment page and collects full name, billing address, city/state/ZIP, phone number, Social Security Number (or EIN for business accounts), credit card number, expiration date, and CVV. After form submission, the victim is redirected to the genuine AT&T website, a technique intended to suppress victim suspicion and delay campaign discovery/reporting. No CVE, specific malware family, or named threat actor was disclosed in the source reporting; the technique (third-party open-redirect abuse for phishing-link evasion) mirrors a broader 2026 trend documented independently by SANS ISC, Microsoft, and other researchers involving OAuth-redirection and other open-redirect abuse in brand-impersonation phishing.
This campaign also fits a persistent, recurring pattern of AT&T-branded payment/billing phishing observed throughout 2026: a materially similar "Your AT&T bill payment could not be processed" / "Bill Payment Center: Service Disconnection Notification" lure was documented by PCrisk as early as May 2026 (updated again in July 2026), using a phishing page hosted on the no-code site builder domain direct-tv-att-management.framer[.]website and harvesting an identical data set (name, billing address, card number, CVV, expiry, phone). A related but distinct AT&T "rewards points expiring" SMS/smishing campaign observed by Malwarebytes in January 2026 exfiltrated harvested card data via a JSON POST to att.hgfxp[.]cc/api/open/cvvInterface. These are not confirmed to be the same physical infrastructure as the MailGuard-reported noSuchEntryRedirect instance, but they share the same actor TTP profile — free/low-cost no-code web-builder hosting, brand-consistent AT&T page templates, urgency/deadline lures, and direct exfiltration of full card-present-fraud data sets — consistent with recurring, likely PhaaS-adjacent commodity activity rather than a single isolated incident.
Target sectors: telecoms, consumer, financial-services, retail
Target regions: North America, united states of america
Detections & IOCs
As of 2026-07-22, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, MEDIUM, threat intelligence, cybersecurity, T1598, T1595, T1589, T1583, T1583, T1584, T1608, T1586, T1566, T1204