Fake American Express "non-compliance" card-lock phishing campaign targets Australians
Fake American Express "non-compliance" card-lock phishing (TL-2026-2758) is a medium-severity phishing campaign, first published 2026-09-29. It has no confirmed attribution, affects American Express American Express card members (brand impersonated; no, maps to 10 MITRE ATT&CK techniques (T1078, T1111, T1204.001), and is covered by 9 detection rules and 6 indicators of compromise.
Key facts for TL-2026-2758
- Threat ID
- TL-2026-2758
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-09-29
- Last reviewed
- 2026-09-29
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- finance, corporate card holders, consumer
- Target regions
- australia
- Detection rules
- 9
- Indicators of compromise
- 6
Emails impersonating American Express claim the recipient's Amex card is locked (subject cites "non-compliance issues") and send victims through a four-step fake portal that harvests the User ID, password and 3-digit card verification code (CID) before redirecting to the legitimate Amex site. Reported by MailGuard against Australian recipients, including organisations with corporate card programs.
How Fake American Express "non-compliance" card-lock phishing works
MailGuard reported a phishing campaign impersonating American Express and aimed at Australian recipients, with particular relevance to organisations that run corporate card programs. The email arrives with the display name "American Express | Non-Compliance Issues", the display and sending address donotreplyus@online.net, and the subject "Your Amex Card has been locked due to non-compliance issues". The body states the card was "temporarily locked due to unusual spending activity" and that "all card transactions and merchant payments are currently suspended", and offers a blue "Confirm your Identity" button. The pretext is deliberately mundane rather than alarming, which lowers suspicion.
The button opens a staged fake portal. Step 1 is a "Confirm access" screen that says "Tap below to verify this browser session and continue" with an "I'm ready" button, which gates the rest of the flow. Step 2 is a fake American Express sign-in page asking for User ID and Password, with a "Remember Me" checkbox. Step 3 asks for the "3-Digit CID", the security code on the card, with an illustration showing where to find it. Step 4 shows a fake error page and then redirects the victim to the legitimate American Express site, which MailGuard says is designed to leave the victim with a sense of normalcy and reduce the likelihood of the incident being reported. MailGuard reports the data harvested as the Amex login credentials, the card verification data (CID) and browser/session metadata.
The MailGuard write-up lists no URLs, phishing domains, hosting infrastructure or hashes, and makes no attribution to a named actor. Harvested credentials plus CID give an attacker what they need for account takeover and card-not-present fraud, but the source does not say how the data is monetised.
MailGuard has documented two earlier American Express kits that are listed here as related context only; the sources do not say the three campaigns share an operator. (1) 1 May 2026, "Account Limited": display name "American Express | Account Limited", pretext that the account is "temporarily restricted due to missing or incomplete information", a simple HTML email with a single link, then a four-step flow of login page (User ID/password), CID page, and a fake loading screen telling the victim not to close or refresh the page. No URLs or hosting were disclosed. (2) 14 July 2026, "Sign-In Alert": display name "American Express | Sign-In Alert", sender pattern americanonline_[recipient handle]@info.net, a "Secure Log In" button routed through a Twitter URL shortener, and a five-to-six step flow that collects User ID/password, CID, mother's maiden name, a 6-digit SMS code (showing "Invalid code" errors to encourage repeated entry) and an email one-time password. MailGuard notes that flow defeats MFA by harvesting both OTPs, enabling account takeover, fraudulent transactions, password resets and inbox compromise. The same three-part core (login, CID, benign ending) recurs across all three kits. Severity is an analyst estimate.
MITRE ATT&CK techniques used in TL-2026-2758
Initial Access
T1078 Valid Accounts; T1566.002 Spearphishing Link
Credential Access
T1111 Multi-Factor Authentication Interception
Execution
Resource Development
T1583.001 Domains; T1608.005 Link Target
Reconnaissance
T1589.001 Credentials; T1598.003 Spearphishing Link
Impact
Stealth
Affected products and versions in Fake American Express "non-compliance" card-lock phishing
- American Express — American Express card members (brand impersonated; no product vulnerability)
Remediation for Fake American Express "non-compliance" card-lock phishing
Immediate actions
- Delete the email without clicking any link or button
- Block or quarantine mail matching sender donotreplyus@online.net and the subject 'Your Amex Card has been locked due to non-compliance issues'
- If credentials or the CID were entered, contact American Express immediately, change the Amex password and any reuse of it, and request a card replacement
- Report the message to American Express at spoof@americanexpress.com
Workarounds
- Never enter a card security code (CID) after following an emailed link; navigate to americanexpress.com directly instead
- Access the account via a bookmarked URL or the official app rather than an email link
Longer-term hardening
- Train staff, especially corporate card holders and finance teams, to reach card issuers only through the app or the number on the card
- Use email security that inspects links and page content at click time, since the portal is multi-step and the source lists no static URL to block
- Enable card transaction alerts and review corporate card statements for unexpected activity
- Hunt mail logs for the sibling display names 'American Express | Account Limited' and 'American Express | Sign-In Alert' and the americanonline_*@info.net sender pattern
Timeline of Fake American Express "non-compliance" card-lock phishing
- MailGuard reports an American Express "Account Limited" phishing email ("temporarily restricted due to missing or incomplete information") with a four-step login/CID/fake-loading-screen flow; no URLs or hosting disclosed. Related context only.
- MailGuard reports an American Express "Sign-In Alert" kit (senders americanonline_[handle]@info.net, Twitter URL shortener, 5-6 step flow collecting credentials, CID, mother's maiden name, SMS and email OTPs); common operator not established.
- Portal step 4: victim sees a fake error page and is redirected to the legitimate American Express site, leaving a sense of normalcy and reducing the chance of a report.
- Portal step 3: page requests the 3-Digit CID card security code, with an illustration of where it sits on the card.
- Portal steps 1-2: "Confirm access" browser-session prompt ("I'm ready") followed by a fake Amex sign-in page collecting User ID and Password, with browser/session metadata also collected.
- Email with subject "Your Amex Card has been locked due to non-compliance issues" claims temporary lock due to unusual spending activity, says transactions and merchant payments are suspended, and offers a "Confirm your Identity" button.
- MailGuard publishes analysis of the American Express "non-compliance" card-lock phishing email aimed at Australian recipients, sent as donotreplyus@online.net.
Sources cited for Fake American Express "non-compliance" card-lock phishing
- Fake American Express "non-compliance" phishing scam targets Australians
- American Express "Sign-In Alert" phishing email leads to fake multi-step credential harvesting pages
- American Express "Account Limited" phishing scam
- Credit Card Security | Fraud Prevention & Security | AMEX AU
- Phishing Scam Awareness & Protection | American Express US
- American Express Account Has Been Locked Email Scam - Removal and recovery steps
More in phishing
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations
- Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+ Organizations
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification
- Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt Injection)
Detection coverage for TL-2026-2758
As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2758 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.