We’ve received reports of a sophisticated phishing campaign targeting Atlassian customers.
These malicious emails use forged email headers to appear legitimate and seek to obtain user credentials by linking victims to phishing sites that closely resemble Atlassian domains.
These can be hard to spot, so we ask that customers exercise caution when engaging with links and/or requests for user credentials in emails that appear to be from noreply@am.atlassian[.]com received before 2023-06-19.
Below is an example of a phishing email and a list of phishing domains reported by Atlassian customers, though threat actors may be using additional assets.
-
app-atlassian[.]com
-
verify-atlassian[.]com
-
cableos-atlassian[.]com
-
apac-atlassian[.]com
-
confirm-atlassian[.]com
-
support-atlassian[.]com
Please change your passwords immediately if you believe you may have entered your Atlassian credentials into a phishing site.
Atlassian’s security team has contacted the phishing domain registrars to request deactivation and taken additional steps to improve the security posture of our domains to prevent these types of attacks from occurring in the future.
Your security is our priority, and we appreciate your partnership in remaining diligent. Please contact Atlassian Support with any questions and report any similar phishing attempts.