Skip to content

How a recruiter phishing campaign hijacked Salesforce Marketing Cloud to impersonate Delta, American Airlines, and Digitas

| 8 min read
phishing cybersecurity email-deliverability job-search dmarc salesforce-marketing-cloud awsapps threat-intelligence
A four-stage diagram showing how a phishing email reaches the inbox: an attacker spins up an AWS WorkMail mailbox, sends from a look-alike awsapps.com address, relays through Salesforce Marketing Cloud where it passes SPF, DKIM, and DMARC, and lands in the inbox displaying a trusted brand name.

I almost replied to a recruiter who doesn’t exist.

The email was good. A talent lead named Amy Banks had “come across my profile,” complimented my performance marketing background, and asked for 15 minutes to talk about some new projects. No pressure, no hard sell. I was writing back when I did the thing I now do before I answer any recruiter: I ignored the name and looked at the address that actually sent it.

It wasn’t Creative Circle, the staffing agency she claimed to work for. It was [email protected]. That awsapps.com suffix is Amazon WorkMail’s default test domain, the one Amazon’s own documentation says should not be used in production. No real staffing firm recruits from it.

So I searched my inbox for the pattern. I did not find one scam. I found a campaign.

One kit, five brands, ten weeks

At least six near-identical emails arrived between May 11 and July 17, 2026, each impersonating a different well-known brand’s careers or talent team. Before anything else: those brands are victims here. Someone is wearing their names to get to people like me.

ReceivedBrand impersonatedSending address”Recruiter”Call to action
May 11Delta Air Lines[email protected]”Stephanie Asbury""Schedule Introductory Call”
Jul 6Aquent[email protected]”Jacki Ryan”booking link
Jul 7American Airlines[email protected]”Danielle Richards”booking link
Jul 10American Airlines[email protected]”Jane Park”booking link
Jul 13Digitas[email protected]Talent Acquisition teambooking link
Jul 17Creative Circle[email protected]”Amy Banks""VIEW OPPORTUNITY”

Every one used the same three ingredients: a throwaway Amazon WorkMail sender, a relay through Salesforce Marketing Cloud, and a fabricated recruiter persona closing with a “let’s schedule a call” link. Those recruiter names are aliases invented by the attacker, not real people at those companies.

I work in marketing and I spend a lot of my time on email deliverability, so the thing that caught my attention wasn’t the fake domain. It was how these messages were reaching the inbox at all.

The weapon is reputation laundering, not the fake domain

Here is the technique. The attacker sends from a cheap, disposable Amazon WorkMail address, then relays the message through Salesforce Marketing Cloud, the same enterprise platform legitimate brands use to send their newsletters and campaigns. You can read it right in the headers of the Delta sample: “mailed-by bounce.s13.exacttarget.com” and “signed-by s13.y.mc.salesforce.com.” ExactTarget is Salesforce Marketing Cloud’s sending infrastructure, and the domain exct.net is registered to Salesforce itself.

Why go to that trouble? Because Salesforce Marketing Cloud has an excellent sending reputation. Its addresses are trusted, its mail is properly authenticated, and inbox providers let it through. By routing a phishing email through that platform, the attacker borrows all of that trust. The Delta email did not land in my spam folder. It landed in my primary inbox.

This is reputation laundering. The same way dirty money is passed through a legitimate business to come out clean, a dishonest email is passed through a legitimate email platform to come out trusted.

The authentication paradox

Now the part that should worry every security team.

These emails almost certainly pass SPF, DKIM, and DMARC. Those are the three email authentication standards, Sender Policy Framework, DomainKeys Identified Mail, and Domain-based Message Authentication, Reporting and Conformance, that exist specifically to stop impersonation.

So how does a phishing email pass the anti-impersonation checks? Because of what those checks actually validate. They confirm that the message really was sent by the domain in the technical “from” field, and that the domain authorized it. In these emails, that domain is the attacker’s own awsapps.com address, relayed by Salesforce. The attacker legitimately controls both. Authentication passes cleanly.

What none of those standards check is the display name, the human-readable “Delta Air Lines - Careers” that your mail client shows in big letters. There is no standard that authenticates a brand name. So the attacker authenticates a domain they own, then writes any brand they like in the display field.

Sit with that for a second. The controls we all trust to stop impersonation are validating the attacker’s real domain and, in doing so, helping a well-formed forgery reach the inbox. Authentication is not failing here. It is working perfectly, for the wrong party.

The fingerprints that give it away

Because it is one kit run at volume, it leaves marks.

The clearest one: the email from aa-talentsolutions.awsapps.com, signed by “Jane Park” and branded American Airlines, arrived with the subject line “Digitas Careers: A World of Digital Innovation Awaits.” That is a find-and-replace slip from a shared template. One operator, many brands, one messy template pool.

Another: the Creative Circle email wrapped its links through cl.s10.exct.net. According to Salesforce practitioners, that default, unbranded ExactTarget tracking domain only shows up when a proper Sender Authentication Package has not been configured, which is consistent with a bare or trial Marketing Cloud account rather than an established brand sender.

Why it is aimed at job seekers

The brands were not chosen at random. Digitas is a marketing agency. Aquent and Creative Circle are marketing staffing firms that genuinely cold-source candidates. Delta and American Airlines are household names with large marketing organizations. If you are a marketer looking for work, “an Aquent recruiter reached out about a marketing role” is exactly what you expect to see. Plausibility is engineered.

There is an uncomfortable corollary. The act of job hunting widens your attack surface. Five of my six emails arrived within a single week, right as my applications and “open to work” signals were circulating across boards and resume databases. The more visible your search, the more of these you will receive. Good application hygiene and good security hygiene turn out to be the same discipline: verify the sender and the destination before you engage.

Conversation first, because it defeats your training

Notice what the first email never asks for. No password. No Social Security number. No bank details. Just a friendly note and a calendar link.

That is deliberate. Every anti-phishing training you have ever sat through teaches you to refuse credential and payment requests. A warm “do you have 15 minutes to chat” sails straight past that reflex, because nothing sensitive is being requested yet. The data grab comes later: on the booking page (the one I did not click was flagged a dangerous site by Google Safe Browsing), on the call itself, or in a fake “onboarding” step once you have started to trust them.

Why the real brands cannot simply stop this

Delta, American Airlines, Digitas, Aquent, and Creative Circle can lock down their own domains all they want. It does not matter, because the attacker never used their domains. Impersonation by display name plus a look-alike domain lives outside what DMARC was built to protect. And because the attack rides on two separate, reputable clouds, Amazon for the mailbox and Salesforce for the send, taking it down requires cooperation from two vendors, not a single block rule. That is exactly why the technique is durable.

How to catch it in five seconds

  1. Read the sending address, not the display name. If it ends in awsapps.com, delete it. Legitimate enterprises do not recruit from Amazon WorkMail test domains.
  2. A real personal recruiter is not relayed through a bulk marketing platform. If the headers mention Salesforce Marketing Cloud, ExactTarget, or exct.net, and the tone is intimate and one to one, that is a contradiction.
  3. If the display name is a known brand but the domain is neither the company’s real corporate domain nor a known applicant tracking system (Greenhouse, Lever, Ashby, Workday, iCIMS), treat it as hostile.
  4. Watch for a generic full-name greeting (“Hello Firstname Lastname”), no specific role or requisition number, and a “book a time” button.
  5. On mobile, expand the sender details before you trust anything. Phones hide the address and the relay line, which is exactly where these emails win.

What to do if you get one

Report it as phishing to your email provider, which both removes it and trains the filters. If you want to do real damage to the operation, report it to the shared infrastructure: Salesforce Marketing Cloud abuse and Amazon Web Services abuse. Disabling the sending tenant takes down every brand in the campaign at once, not just the one email in front of you. Verify the correct abuse contacts on the vendors’ own websites before you send anything, and never forward your personal details to an address a search result hands you.

I build and defend email programs for a living, and I still had my reply half-written before I caught this one. That is how good it has gotten. The name on the envelope means nothing. Check the address first, every time.


Delta Air Lines, American Airlines, Digitas, Aquent, and Creative Circle are named here as victims of brand impersonation. Nothing in this article suggests those companies or their employees were involved in the campaign, and the recruiter names quoted are aliases used by the attacker. Technical claims are drawn from Amazon’s and Salesforce’s own published documentation; verify current details with those sources before relying on them.

About the Author

Andrés Plashal

Author of the Assistive Agent Optimization (AAO) framework. Twenty years building search and measurement systems for B2B and SEC-regulated firms. Google Partner since 2017.

Credentials: UIUC Gies College of Business (Behavioral Science), Columbia College Chicago (Interactive Arts & Media). Member: American Marketing Association, GAABS, Paid Search Association. Published researcher (SCTE/NCTA).