A Subscription Confirmation You Never Requested Is Reaching Your Staff
McAfee-spoofed subscription confirmation emails target staff to harvest credentials or prompt fraudulent cancellation calls via vishing.
A wave of unsolicited subscription confirmation emails is landing in NZ inboxes, posing a quiet but meaningful risk to your organisation. These messages are designed to normalise contact from an unknown sender, establishing a foothold for follow-on phishing, credential harvesting, or malicious link delivery. Even without an obvious payload in the initial message, the act of engaging — clicking unsubscribe, managing preferences, or simply replying — can confirm an active address to threat actors and trigger escalating contact.
A spike in matching messages has been detected across multiple local organisations within a narrow window, indicating a coordinated distribution effort rather than isolated noise. The campaign spread across several unrelated environments in a single day, suggesting automated bulk sending infrastructure targeting NZ-based recipients broadly rather than any single sector or organisation type.
What makes this campaign particularly deceptive is the authentication posture it presents. DKIM, DMARC, and composite authentication checks all return passing verdicts, meaning many email security controls will treat these messages as legitimate. The sender address, however, tells a different story — it routes through a free-tier HubSpot sending domain and encodes a mismatched French domain within the address itself, a pattern inconsistent with any genuine subscription service your staff would recognise or have enrolled in.
The physical address embedded in the email footer references a Stockholm street address, lending a veneer of regulatory compliance typical of legitimate marketing emails under GDPR requirements. The greeting uses a garbled placeholder string rather than a real name, suggesting the personalisation tokens in the sending template failed or were deliberately left malformed — a hallmark of hastily assembled bulk campaigns. The unsubscribe link resolves to a HubSpot free-tier preference centre subdomain, which, if clicked, confirms deliverability and recipient engagement to whoever controls the sending account.

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Scrutinise sender addresses carefully — this email originates from a suspicious third-party domain (hubspotfree.eu1.hs-send.com) rather than a legitimate business address, which is a clear red flag
- Delete any email with this subject line ("Thank you for confirming your sign-up") immediately if you have no recollection of signing up to a service, as attackers rely on curiosity to prompt clicks
- Avoid clicking any links or downloading attachments within the email, as these may lead to credential-harvesting sites or install malware on your device
- Report the phishing email to CERT NZ (cert.govt.nz) using their online reporting tool, helping protect other New Zealand businesses from the same campaign
- Educate your staff by sharing this example in a team briefing or via your internal communications, ensuring employees know to verify unexpected sign-up confirmations directly with the relevant service through official channels rather than via email links
See what a genuine Spotify message looks like, the real sender domain, the real link destination, and where to report a fake.


