Spam campaign used Jira Cloud to slip past email filters
Trend Micro researchers have uncovered a spam campaign that weaponised Atlassian Jira Cloud's trusted domain reputation to deliver large volumes of unsolicited email past traditional filters. Using legitimate Jira Cloud notifications, the attackers sent tailored spam in English, French, German, Italian, Portuguese and Russian to both government and corporate recipients worldwide. Many messages directed users to investment scams, online casinos and other dubious landing pages, pointing to financial gain as the motive. The campaign ran from late December 2025 through January 2026 and exploited the trust recipients place in notifications from widely used SaaS platforms.
What this means for your organisation
This is not about blocking a sender; a service the organisation actually uses becomes the channel. Filters based on domain reputation cannot catch it, and staff have been taught that Jira notifications can be trusted. This time the content was fraud, but the same approach works just as well for targeted phishing against your own people. Any SaaS tool able to send outbound email on behalf of users is potentially the same channel.
Berigo recommends
- Review who can create issues and trigger notifications in Jira and similar tools, and close open external access where it is not needed.
- Use email security that evaluates content and links, not only the reputation of the sending domain.
- Include in training that a notification from a familiar tool is no guarantee about its content.
- Set up an internal reporting channel for suspicious email and make sure reports are actually followed up.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch