08/19/2026
🚨 SCAM ALERT FOR NONPROFITS & BUSINESSES 🚨
Below is the exact text of a targeted phishing email circulating to organizations, along with how it bypassed standard security filters:
EMAIL HEADER & TEXT:
From: [email protected]
Subject: Selection for Support / Grant Notice
⚠️ DO NOT OPEN THIS ATTACHMENT OR REPLY. ⚠️
How This Email Bypassed Gmail Filters:
Valid Domain Authentication (SPF/DKIM): The sending domain matched its DNS technical security checks, allowing it to bypass basic spoofing detection.
Image-Based Text Evasion: Key trigger words (grant, proposal, funding) were hidden inside an image within a PDF rather than plain email text, preventing automated scanners from flagging suspicious language.
Clean Attachment Footprint: The 2.9 MB PDF contained no obvious malicious ex*****on scripts or macro code on initial automated scanning.
Typosquatted Lookalike Domain: The body and signature direct responses to texar.org (missing the "s" from the real nonprofit TEXSAR), routing communications to a privately registered domain.
What to do if you receive it:
1. Do not click or open any attachments.
2. Report the email as Phishing in your email system (Gmail/Outlook).
3. Warn your finance, operations, and administrative teams immediately.
Please share this post to help protect other nonprofits and small businesses from falling victim to this campaign!
How This Email Bypassed Gmail Filters:
Valid Domain Authentication (SPF/DKIM): The sending domain matched its DNS technical security checks, allowing it to bypass basic spoofing detection.
Image-Based Text Evasion: Key trigger words (grant, proposal, funding) were hidden inside an image within a PDF rather than plain email text, preventing automated scanners from flagging suspicious language.
Clean Attachment Footprint: The 2.9 MB PDF contained no obvious malicious ex*****on scripts or macro code on initial automated scanning.
Typosquatted Lookalike Domain: The body and signature direct responses to texar.org (missing the "s" from the real nonprofit TEXSAR), routing communications to a privately registered domain.
What to do if you receive it:
1. Do not click or open any attachments.
2. Report the email as Phishing in your email system (Gmail/Outlook).
3. Warn your finance, operations, and administrative teams immediately.
Please share this post to help protect other nonprofits and small businesses from falling victim to this campaign!