Back to The Local Vocal
The Local VocalMedium
Phishing🎭 Spotify
Email
Medium risk PhishingEncountered ViaEMAIL 15 July 2026
RegionOtagoNew Zealand

A Subscription Confirmation You Never Requested Is Reaching Your Staff

McAfee-spoofed subscription confirmation emails target staff to harvest credentials or prompt fraudulent cancellation calls via vishing.

A wave of unsolicited subscription confirmation emails is landing in NZ inboxes, posing a quiet but meaningful risk to your organisation. These messages are designed to normalise contact from an unknown sender, establishing a foothold for follow-on phishing, credential harvesting, or malicious link delivery. Even without an obvious payload in the initial message, the act of engaging — clicking unsubscribe, managing preferences, or simply replying — can confirm an active address to threat actors and trigger escalating contact.

A spike in matching messages has been detected across multiple local organisations within a narrow window, indicating a coordinated distribution effort rather than isolated noise. The campaign spread across several unrelated environments in a single day, suggesting automated bulk sending infrastructure targeting NZ-based recipients broadly rather than any single sector or organisation type.

What makes this campaign particularly deceptive is the authentication posture it presents. DKIM, DMARC, and composite authentication checks all return passing verdicts, meaning many email security controls will treat these messages as legitimate. The sender address, however, tells a different story — it routes through a free-tier HubSpot sending domain and encodes a mismatched French domain within the address itself, a pattern inconsistent with any genuine subscription service your staff would recognise or have enrolled in.

The physical address embedded in the email footer references a Stockholm street address, lending a veneer of regulatory compliance typical of legitimate marketing emails under GDPR requirements. The greeting uses a garbled placeholder string rather than a real name, suggesting the personalisation tokens in the sending template failed or were deliberately left malformed — a hallmark of hastily assembled bulk campaigns. The unsubscribe link resolves to a HubSpot free-tier preference centre subdomain, which, if clicked, confirms deliverability and recipient engagement to whoever controls the sending account.

Email authorisation
SPF
none
DKIM
fail
DMARC
none
COMPAUTH
fail
Domain authentication
Sender / From domain
shoppingbestof.shop
Domain age
104 days old
Email Sample
Email Sample screenshot
Domain Reputation
Abuse score
15/ 100Low
ISP (Internet Service Provider)
Regional Host
Function:Function Unknown
Reputation:Reputation Unknown
Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Scrutinise sender addresses carefully — this email originates from a suspicious third-party domain (hubspotfree.eu1.hs-send.com) rather than a legitimate business address, which is a clear red flag
  • Delete any email with this subject line ("Thank you for confirming your sign-up") immediately if you have no recollection of signing up to a service, as attackers rely on curiosity to prompt clicks
  • Avoid clicking any links or downloading attachments within the email, as these may lead to credential-harvesting sites or install malware on your device
  • Report the phishing email to CERT NZ (cert.govt.nz) using their online reporting tool, helping protect other New Zealand businesses from the same campaign
  • Educate your staff by sharing this example in a team briefing or via your internal communications, ensuring employees know to verify unexpected sign-up confirmations directly with the relevant service through official channels rather than via email links
Spotify logo
Is it real?
Got an email from Spotify?

See what a genuine Spotify message looks like, the real sender domain, the real link destination, and where to report a fake.

Check the real thing