Grubhub Email Crypto Scam Promises 10× Bitcoin Return

Related

U.S. Treasury Lifts Sanctions on Crypto Wallets

What happened U.S. Treasury sanctions were lifted after the Department...

OpenVSX Developers Targeted with Crypto-Stealing Worms

What happened OpenVSX developers were targeted with crypto-stealing worms designed...

5 CISOs to Watch in the Crypto Industry

The crypto industry faces non stop attacks and rapid...

Police Shut Down CryptoMixer: What CISOs Need To Know

What happened Europol and several national police units seized the...

Share

What happened

A Grubhub email crypto scam saw fraudulent emails posing as company communications promising recipients a “Holiday Crypto Promotion” that would return ten times any Bitcoin sent to a listed wallet address. The messages appeared to come from a legitimate Grubhub subdomain and even included recipient names, but the offer was fake and designed to trick people into sending cryptocurrency to scammers.  

Who is affected

Grubhub users and merchant partners who received these deceptive emails were targeted. Some victims received messages from seemingly trusted addresses, increasing the likelihood of engagement.  

Why CISOs should care

This incident highlights how attackers exploit trusted brands and legitimate infrastructure to craft convincing phishing campaigns. Even well‑known companies can have their communication channels abused to distribute fraudulent content, posing financial and reputational risk. CISOs must anticipate brand impersonation and be ready to defend against increasingly sophisticated social engineering tactics.  

3 practical actions:

  1. Enhance email authentication: Ensure SPF, DKIM, and DMARC policies are properly enforced to reduce phishing from spoofed or compromised domains.
  2. Monitor brand channels: Actively monitor corporate subdomains and vendor integrations for unauthorized use or unusual activity.
  3. Educate users: Regularly train employees and external partners on spotting phishing lures, especially scams promising financial rewards, and encourage reporting suspicious messages before action is taken.