Skip to main content

Company intelligence

Infoblox cybersecurity incidents and threat signals

infoblox.com

Infoblox logo

Infoblox is a cloud networking and security company specialising in DNS, DHCP and IP address management, collectively known as DDI.

Company country

United States

Facts last verified July 23, 2026

1

Published signals

currently linked to this company

1

Last 28 days

recent published signals

1

Last 90 days

recent published signals

1

High or critical

confidence classifications

July 24, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Infoblox. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Infoblox

Infoblox logoPhishing
High

Infoblox Uncovers Global AiTM Phishing Campaign Targeting EU and UN Agencies

Infoblox Threat Intel has identified a sophisticated adversary-in-the-middle (AiTM) phishing campaign that began in May 2026 and was publicly reported on July 22, 2026. This campaign targets global organizations, including agencies associated with the European Union and the United Nations, as well as universities and commercial enterprises. The attackers utilize procurement-themed emails sent from previously compromised organizational accounts to bypass multi-factor authentication (MFA) and hijack authenticated sessions. These emails are designed to appear credible, mimicking routine business workflows such as bid invitations, shared project files, or requests for information, often incorporating false deadlines and confidentiality language to create urgency. When a recipient clicks an embedded link, the AiTM infrastructure intercepts credentials and session tokens in real-time, allowing attackers to gain access to the organization's account and network. The campaign leverages various Phishing-as-a-Service kits, including EvilProxy, FlowerStorm, and Kali365, and hosts fake download pages on compromised, often dormant, websites to enhance their apparent legitimacy. Infoblox emphasizes that this type of phishing scenario is not typically covered in standard security training, highlighting the need for organizations to combine user awareness with early visibility into phishing infrastructure through DNS-based threat intelligence.

Infoblox

FAQ

Questions about Infoblox cybersecurity reporting

What does the Infoblox page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Infoblox.

Does every mention of Infoblox appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.