Just in time for the school holidays, MailGuard is intercepting a new phishing scam that impersonates Disney’s subscription service to steal user credentials and credit card information. The email claims a payment has failed and urges the recipient to update the details for their MyDisney account. The campaign is highly targeted, convincingly branded, and built to bypass basic security filters.
The email appears to come from Disney Support using the sender address `an(at)findingmeili(dot)com`, with display names spoofed to reinforce authenticity.
The subject line reads: “Your MyDisney account has been SUSPENDED \[DD-843817-D5379]
Here's what the email looks like 👇
The message claims that Disney has been unable to renew the user’s subscription because their bank declined the payment. It urges the recipient to click an “UPDATE” button to restore access to their account. All links in the email, except for the blue update button, point to legitimate Disney services. This tactic is used to increase the perceived authenticity of the email.
Clicking the update button leads to a series of spoofed Disney-branded login pages, hosted on a non-Disney domain, `builder(dot)ai’. These phishing pages are designed to harvest personal credentials and payment details in multiple stages.
1. Login prompt: Victims are asked to re-enter their email and password.Finally, the victim is redirected to the real MyDisney login page to avoid raising suspicion, a common trick used in credential harvesting attacks.
This phishing campaign uses sophisticated social engineering and visual mimicry to bypass both technical defences and human judgment.
Here’s what to watch for:
Despite appearing legitimate, this scam operates from a series of disposable AmazonSES sender addresses and is hosted on non-affiliated domains. It’s engineered to bypass default Microsoft 365 filters and catch users off guard.
Stay Safe - Know the Signs
MailGuard advises all recipients of these emails to delete them immediately without clicking on any links. Responding or providing personal details can lead to identity theft, data breaches, and financial losses.
Avoid emails that:
Many businesses turn to MailGuard after a near miss or incident. Don't wait until it's too late. Reach out to our team for a confidential discussion by emailing expert@mailguard.com.au or calling 1300 30 44 30.
All that it takes to devastate your business is a cleverly worded email message that can steal sensitive user credentials or disrupt your business operations. If scammers can trick one person in your company into clicking on a malicious link or attachment, they can gain access to your data or inflict damage on your business.
For a few dollars per staff member per month, you can protect your business with MailGuard's specialist, 'zero zero-day' email security. Special Ops for when speed matters! Our real-time 'zero zero-day', email threat detection amplifies our client’s intelligence, knowledge, security and defence. Talk to a solution consultant at MailGuard today about securing your company's inboxes.
Stay up-to-date with MailGuard's latest blog posts by subscribing to free updates. Subscribe to weekly updates by clicking on the button below.