Fake American Express "non-compliance" card-lock phishing campaign targets Australians

Fake American Express "non-compliance" card-lock phishing (TL-2026-2758) is a medium-severity phishing campaign, first published 2026-09-29. It has no confirmed attribution, affects American Express American Express card members (brand impersonated; no, maps to 10 MITRE ATT&CK techniques (T1078, T1111, T1204.001), and is covered by 9 detection rules and 6 indicators of compromise.

Key facts for TL-2026-2758

Threat ID
TL-2026-2758
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
2026-09-29
Last reviewed
2026-09-29
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
finance, corporate card holders, consumer
Target regions
australia
Detection rules
9
Indicators of compromise
6

Emails impersonating American Express claim the recipient's Amex card is locked (subject cites "non-compliance issues") and send victims through a four-step fake portal that harvests the User ID, password and 3-digit card verification code (CID) before redirecting to the legitimate Amex site. Reported by MailGuard against Australian recipients, including organisations with corporate card programs.

How Fake American Express "non-compliance" card-lock phishing works

MailGuard reported a phishing campaign impersonating American Express and aimed at Australian recipients, with particular relevance to organisations that run corporate card programs. The email arrives with the display name "American Express | Non-Compliance Issues", the display and sending address donotreplyus@online.net, and the subject "Your Amex Card has been locked due to non-compliance issues". The body states the card was "temporarily locked due to unusual spending activity" and that "all card transactions and merchant payments are currently suspended", and offers a blue "Confirm your Identity" button. The pretext is deliberately mundane rather than alarming, which lowers suspicion.

The button opens a staged fake portal. Step 1 is a "Confirm access" screen that says "Tap below to verify this browser session and continue" with an "I'm ready" button, which gates the rest of the flow. Step 2 is a fake American Express sign-in page asking for User ID and Password, with a "Remember Me" checkbox. Step 3 asks for the "3-Digit CID", the security code on the card, with an illustration showing where to find it. Step 4 shows a fake error page and then redirects the victim to the legitimate American Express site, which MailGuard says is designed to leave the victim with a sense of normalcy and reduce the likelihood of the incident being reported. MailGuard reports the data harvested as the Amex login credentials, the card verification data (CID) and browser/session metadata.

The MailGuard write-up lists no URLs, phishing domains, hosting infrastructure or hashes, and makes no attribution to a named actor. Harvested credentials plus CID give an attacker what they need for account takeover and card-not-present fraud, but the source does not say how the data is monetised.

MailGuard has documented two earlier American Express kits that are listed here as related context only; the sources do not say the three campaigns share an operator. (1) 1 May 2026, "Account Limited": display name "American Express | Account Limited", pretext that the account is "temporarily restricted due to missing or incomplete information", a simple HTML email with a single link, then a four-step flow of login page (User ID/password), CID page, and a fake loading screen telling the victim not to close or refresh the page. No URLs or hosting were disclosed. (2) 14 July 2026, "Sign-In Alert": display name "American Express | Sign-In Alert", sender pattern americanonline_[recipient handle]@info.net, a "Secure Log In" button routed through a Twitter URL shortener, and a five-to-six step flow that collects User ID/password, CID, mother's maiden name, a 6-digit SMS code (showing "Invalid code" errors to encourage repeated entry) and an email one-time password. MailGuard notes that flow defeats MFA by harvesting both OTPs, enabling account takeover, fraudulent transactions, password resets and inbox compromise. The same three-part core (login, CID, benign ending) recurs across all three kits. Severity is an analyst estimate.

MITRE ATT&CK techniques used in TL-2026-2758

Initial Access

T1078 Valid Accounts; T1566.002 Spearphishing Link

Credential Access

T1111 Multi-Factor Authentication Interception

Execution

T1204.001 Malicious Link

Resource Development

T1583.001 Domains; T1608.005 Link Target

Reconnaissance

T1589.001 Credentials; T1598.003 Spearphishing Link

Impact

T1657 Financial Theft

Stealth

T1684.001 Impersonation

Affected products and versions in Fake American Express "non-compliance" card-lock phishing

  • American Express — American Express card members (brand impersonated; no product vulnerability)

Remediation for Fake American Express "non-compliance" card-lock phishing

Immediate actions

  • Delete the email without clicking any link or button
  • Block or quarantine mail matching sender donotreplyus@online.net and the subject 'Your Amex Card has been locked due to non-compliance issues'
  • If credentials or the CID were entered, contact American Express immediately, change the Amex password and any reuse of it, and request a card replacement
  • Report the message to American Express at spoof@americanexpress.com

Workarounds

  • Never enter a card security code (CID) after following an emailed link; navigate to americanexpress.com directly instead
  • Access the account via a bookmarked URL or the official app rather than an email link

Longer-term hardening

  • Train staff, especially corporate card holders and finance teams, to reach card issuers only through the app or the number on the card
  • Use email security that inspects links and page content at click time, since the portal is multi-step and the source lists no static URL to block
  • Enable card transaction alerts and review corporate card statements for unexpected activity
  • Hunt mail logs for the sibling display names 'American Express | Account Limited' and 'American Express | Sign-In Alert' and the americanonline_*@info.net sender pattern

Timeline of Fake American Express "non-compliance" card-lock phishing

  • MailGuard reports an American Express "Account Limited" phishing email ("temporarily restricted due to missing or incomplete information") with a four-step login/CID/fake-loading-screen flow; no URLs or hosting disclosed. Related context only.
  • MailGuard reports an American Express "Sign-In Alert" kit (senders americanonline_[handle]@info.net, Twitter URL shortener, 5-6 step flow collecting credentials, CID, mother's maiden name, SMS and email OTPs); common operator not established.
  • Portal step 4: victim sees a fake error page and is redirected to the legitimate American Express site, leaving a sense of normalcy and reducing the chance of a report.
  • Portal step 3: page requests the 3-Digit CID card security code, with an illustration of where it sits on the card.
  • Portal steps 1-2: "Confirm access" browser-session prompt ("I'm ready") followed by a fake Amex sign-in page collecting User ID and Password, with browser/session metadata also collected.
  • Email with subject "Your Amex Card has been locked due to non-compliance issues" claims temporary lock due to unusual spending activity, says transactions and merchant payments are suspended, and offers a "Confirm your Identity" button.
  • MailGuard publishes analysis of the American Express "non-compliance" card-lock phishing email aimed at Australian recipients, sent as donotreplyus@online.net.

Sources cited for Fake American Express "non-compliance" card-lock phishing

More in phishing

Detection coverage for TL-2026-2758

As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2758 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats