MailGuard 09 July 2025 09:32:59 AEST 5 MIN READ

MyDisney Phishing Scam Claims Your Account Has Been Suspended

Just in time for the school holidays, MailGuard is intercepting a new phishing scam that impersonates Disney’s subscription service to steal user credentials and credit card information. The email claims a payment has failed and urges the recipient to update the details for their MyDisney account. The campaign is highly targeted, convincingly branded, and built to bypass basic security filters. 

A Convincing Facade: "Subscription Suspended"

The email appears to come from Disney Support using the sender address `an(at)findingmeili(dot)com`, with display names spoofed to reinforce authenticity.

The subject line reads: “Your MyDisney account has been SUSPENDED \[DD-843817-D5379] 

Here's what the email looks like 👇

Disney - 0725 - email

The message claims that Disney has been unable to renew the user’s subscription because their bank declined the payment. It urges the recipient to click an “UPDATE” button to restore access to their account. All links in the email, except for the blue update button, point to legitimate Disney services. This tactic is used to increase the perceived authenticity of the email.

Step-by-Step Credential Theft

Clicking the update button leads to a series of spoofed Disney-branded login pages, hosted on a non-Disney domain, `builder(dot)ai’. These phishing pages are designed to harvest personal credentials and payment details in multiple stages.

1. Login prompt: Victims are asked to re-enter their email and password.

Disney - 0725 - signin

2. Payment update: The next screen prompts for credit card details, including card number, expiry date, and CVV.

Disney - 0725 - creditcard

3. Final “update required” warning: A third screen uses a fabricated regulatory message to justify the data request and reinforce urgency.

Disney - 0725 - updaterequired

Finally, the victim is redirected to the real MyDisney login page to avoid raising suspicion, a common trick used in credential harvesting attacks.

Indicators of Deception

This phishing campaign uses sophisticated social engineering and visual mimicry to bypass both technical defences and human judgment.

Here’s what to watch for:

  • Generic or oddly structured sender addresses (e.g., `(at)findingmeili(dot)com`)
  • Hyperlinked buttons that redirect to unfamiliar or unofficial domains
  • High-stakes warnings involving account suspension or failed payments
  • Requests for sensitive information under the guise of “security updates”
  • Redirects to real brand websites after credential capture

Despite appearing legitimate, this scam operates from a series of disposable AmazonSES sender addresses and is hosted on non-affiliated domains. It’s engineered to bypass default Microsoft 365 filters and catch users off guard. 

Stay Safe - Know the Signs

MailGuard advises all recipients of these emails to delete them immediately without clicking on any links. Responding or providing personal details can lead to identity theft, data breaches, and financial losses.

Avoid emails that:

  • Aren’t addressed to you personally.
  • Are unexpected and urge immediate action.
  • Contain poor grammar or miss crucial identifying details.
  • Direct you to a suspicious URL that isn’t associated with the genuine company.

Many businesses turn to MailGuard after a near miss or incident. Don't wait until it's too late. Reach out to our team for a confidential discussion by emailing expert@mailguard.com.au or calling 1300 30 44 30.

One Email Is All That It Takes   

All that it takes to devastate your business is a cleverly worded email message that can steal sensitive user credentials or disrupt your business operations. If scammers can trick one person in your company into clicking on a malicious link or attachment, they can gain access to your data or inflict damage on your business.     

For a few dollars per staff member per month, you can protect your business with MailGuard's specialist, 'zero zero-day' email security. Special Ops for when speed matters!  Our real-time 'zero zero-day', email threat detection amplifies our client’s intelligence, knowledge, security and defence. Talk to a solution consultant at MailGuard today about securing your company's inboxes.  

Stay up-to-date with MailGuard's latest blog posts by subscribing to free updates. Subscribe to weekly updates by clicking on the button below.  

Keep Informed with Weekly Updates