The Email From Yourself: When Routing Mistakes Make Phishing Look Internal
January 2026 reporting showed attackers skipping lookalike domains entirely and sending phishing that appeared to come from the victim's own organization. The enabling factors were weak mail routing and permissive spoof handling.