Threat Research
Samsung Sender, Costco Lure: Cross-Brand Phishing Chain Stealing Credentials, Cards, and SSNs
Samsung-looking sender, Costco order-hold lure. Credentials, SSNs, and cards stolen via sslip.io embedded-IP DNS abuse, then redirect to real Costco.
By ZeroBEC Team · June 3, 2026 · 11 min read
On June 2, 2026, ZeroBEC identified a phishing campaign that used a trusted-looking Samsung sender identity to deliver a Costco-themed order-hold lure. The visible sender presented as Billing Administration from [email protected], but the body impersonated Costco Wholesale and pushed the recipient to confirm a supposedly delayed warehouse order.
The campaign did not stop at Costco credential theft. The flow attempted to collect Costco login credentials, membership details, date of birth, phone number, billing address, Social Security Number, and full payment card data including CVV.
After the collection flow, the victim was redirected to the legitimate Costco website. That final redirect is important: it creates a sense of closure and can delay user suspicion long after the attacker has already collected the data.
The key idea. The attack chained trust across multiple places: a Samsung-looking sender identity, Costco-branded content, a high-reputation shared DNS service, and a final redirect to the real Costco website.
The Email: Samsung Sender, Costco Story
The email arrived with the subject line "Your recent order cannot ship without confirmation."
The sender display name was Billing Administration and the visible from address was [email protected]. At a glance, this looks like a transactional billing or order message. The content immediately pivots to Costco Wholesale.
The message claims that a warehouse order is on hold, references a specific date, and lists a small order value of $75.81. That combination makes the lure feel routine and believable. The user is not being asked to wire money or approve an invoice. They are being asked to fix a small account issue so an order can continue.
Header and Content Clues Worth Hunting
The important point is not whether a specific perimeter product labeled the message one way or another. The important point is the relationship between the sender identity, the content, and the destination. Here, those relationships were inconsistent: a Samsung-looking sender delivered Costco-branded content, and the call-to-action pointed to a domain unrelated to either brand.
Observable artifacts in this campaign:
- Subject:
Your recent order cannot ship without confirmation— order-hold theme designed to drive action. - Display name:
Billing Administration— generic transactional billing persona. - Visible sender claim:
noreply@samsung[.]com— trusted-looking brand anchor; use for hunting context only, not domain blocking. - Body brand: Costco Wholesale — cross-brand mismatch between sender and message content.
- CTA text:
Confirm My Order— action-oriented retail lure. - Mailer artifact:
Mozilla Thunderbird 115.0— an automated billing message originating from a localized desktop user-agent is an immediate indicator of a spoofed or compromised standalone mailbox being used for a blast campaign, not a real automated enterprise workflow. - Primary link:
hxxp://sg210[.]com/api//<campaign id>/— external domain unrelated to Samsung or Costco. Example campaign id:9my3qcqh6h.
The Link Chain: From sg210[.]com to the Phishing Portal
The body contained two links: the red Confirm My Order button and the Membership Help footer link. Both pointed to the same sg210[.]com URL path.
That first domain acted as the campaign's entry point. The user was then sent into a Costco-themed credential-collection flow hosted on an sslip[.]io hostname containing an embedded IP address.
hxxp://sg210[.]com/api/<campaign id>/ -> myaccount.login.membership.216.194.167.42.sslip[.]io/login?token=[redacted]
Why this matters. Reputation-only controls can struggle when the final phishing hostname sits under a legitimate, highly used parent domain. The malicious signal is in the full hostname, embedded IP, path, page content, and requested data, not only the parent domain.
The Interesting Part: Abuse of sslip[.]io Embedded-IP DNS
The phishing portal used the hostname:
myaccount.login.membership.216.194.167.42.sslip[.]io
This is interesting because sslip[.]io is a legitimate, dual-use wildcard DNS service. The service is programmatically designed to resolve hostnames containing an embedded IP address back to that specific IP.
The sslip[.]io documentation explicitly features a "Branding / White Label / Custom Domains" capability, which allows developers to delegate their own custom subdomains to sslip.io's infrastructure to handle dynamic IP routing. In this campaign, the attacker did not even bother white-labeling their own domain. Instead, they abused the raw, high-reputation sslip[.]io parent domain directly, with a valid SSL certificate.
Because the service ignores any subdomains placed in front of the embedded IP block, the attacker was able to effortlessly "brand" the URL string themselves. By prepending misleading, brand-centric labels like myaccount, login, and membership ahead of their target infrastructure IP (216[.]194[.]167[.]42), they created a URL structure that looks like a legitimate account portal to an untrained eye or a lightweight scanner.
This highlights why legacy, reputation-only filters struggle. In reputation datasets, the parent domain sslip[.]io often appears as a trusted, high-ranking Information Technology domain because of its massive legitimate use. The attacker gets the double-whammy: they bypass perimeter filters by hiding under a high-reputation parent domain, while retaining total freedom to manipulate the visible subdomains to impersonate corporate brands.
Pattern elements observed in the abuse:
- Brand and account labels:
myaccount.login.membership— creates a portal-like URL shape. - Embedded IP:
216[.]194[.]167[.]42— routing clue for attacker-controlled infrastructure. - Parent service:
sslip[.]io— legitimate shared DNS service; do not block parent globally without context. - Credential path:
/login— Costco credential collection stage. - Identity path:
/account/billing-address— membership, DOB, phone, address, and SSN collection stage. - Payment path:
/account/payment-method— cardholder data and CVV collection stage.
Reference note. sslip[.]io publicly documents that it returns embedded IP addresses from hostnames and supports branding / white-label / custom-domain style use. This is legitimate functionality being abused in this phishing chain.
Stage 1: Fake Costco Login
The first phishing page mimics Costco sign-in and asks for an email address and password.
The page includes familiar login elements such as Forgot Password, Keep me signed in, and Create Account. These small details make the page feel like a normal account portal rather than a standalone credential form.
sslip[.]io embedded-IP hostname. Token redacted.Stage 2: Identity and SSN Theft
After login, the victim is moved to a page titled "Confirm your personal details." This page claims it needs to verify membership and billing information currently on file.
The form requests membership number, date of birth, Social Security Number, phone number, street address, and ZIP / postal code. The Social Security Number request is the clearest escalation: at this stage the campaign becomes identity theft, not just credential theft.
The copy attempts to reduce friction by claiming that the information is encrypted and used only for membership verification.
Data requested and the risk it creates:
- Membership number — links the victim to a Costco account identity.
- Date of birth — core identity verification data.
- Social Security Number — high-risk identity theft data.
- Phone number — account recovery and fraud-enrichment data.
- Street address and ZIP — billing identity and payment fraud support.
Stage 3: Payment Card Harvesting
The next page asks the victim to confirm the payment method associated with their Costco membership.
The form requests cardholder name, card number, expiration date, and CSC / CVV. The page also uses fake assurance language such as "256-bit SSL Encryption", "Costco Verified", and "PCI DSS Compliant."
Those claims are persuasion elements, not proof of legitimacy. When combined with the identity page, the attacker has enough information for account takeover, card fraud, and broader identity fraud.
Final Stage: Redirect to the Real Costco Website
After harvesting data, the flow redirects to the real Costco website. In the observed session, the final destination was costco[.]com/my-account, which returned a Page Not Found screen.
This redirect is part of the deception. Even if the final page is a 404, the victim sees the legitimate Costco domain after completing the flow. That can delay suspicion and reduce immediate reporting.
Attack Flow
Samsung-looking sender identity -> Costco order-hold email lure -> sg210[.]com/api/9my3qcqh6h/ -> myaccount.login.membership.216.194.167.42.sslip[.]io/login -> Costco credential collection -> /account/billing-address (identity + SSN collection) -> /account/payment-method (card + CVV collection) -> real Costco website redirect
The campaign works because it does not rely on a single deception. It layers multiple credibility cues: a major-brand sender identity, a Costco order issue, a high-reputation shared DNS parent, and a final redirect to the real Costco site.
Indicators of Compromise (Defanged)
IOC scope. The network IOC section below intentionally excludes known legitimate mail-relay infrastructure, cloud-mail infrastructure, security-gateway infrastructure, and the final legitimate Costco redirect. Those may appear in message traces, but they should not be treated as malicious IOCs for this campaign.Network indicators:
- Domain:
sg210[.]com— initial campaign link domain in the email body. - URL:
hxxp://sg210[.]com/api//<campaign id>/— used by bothConfirm My OrderandMembership Helplinks. - Hostname:
myaccount.login.membership.216.194.167.42.sslip[.]io— fake Costco portal hostname under a legitimate shared DNS parent. - Embedded IP:
216[.]194[.]167[.]42— IP embedded in thesslip[.]iohostname. - Path:
/login— credential collection stage. - Path:
/account/billing-address— identity and SSN collection stage. - Path:
/account/payment-method— payment-card collection stage.
Mail-header hunting artifacts:
- Subject:
Your recent order cannot ship without confirmation— useful for mailbox hunting and clustering. - Display name:
Billing Administration— useful only with other signals. - Visible sender claim:
noreply@samsung[.]com— do not block the real Samsung domain; use as cross-brand mismatch context. - Message-ID:
<178041473805.169868.5277737579003227437@samsung[.]com>— campaign-specific artifact. - X-Mailer:
Mozilla Thunderbird 115.0— use as supporting evidence, not a standalone rule. - CTA text:
Confirm My Order— pair with non-Costco destination domains. - Footer link text:
Membership Help— pair withsg210[.]comor suspicious redirect chain.
Lure and content indicators:
- Brand text: Costco Wholesale
- Header text:
ORDER HOLD - Status text:
Your warehouse order is on hold - CTA:
Confirm My Order - Order date in lure: June 02, 2026
- Order value in lure: $75.81
- Service status:
Scheduled - Hidden trust text in email body:
Authenticated sender, identity verified by domain administrator - Preheader:
A Costco warehouse order is awaiting your confirmation before it can be released.
Detection Opportunities
The strongest detection opportunities are relational. A single string or domain reputation score is not enough. The campaign becomes obvious when the system understands the relationship between sender, brand, link, page content, and requested data.
- Flag cross-brand messages where a Samsung-looking sender delivers Costco-branded content.
- Flag Costco-themed messages where the CTA domain is not Costco-controlled.
- Hunt for
sg210[.]comand the full/api/9my3qcqh6h/path. - Hunt for
sslip[.]iohostnames containing brand or account labels plus an embedded public IP address. - Flag retail verification flows that request Social Security Number, CVV, and account credentials in sequence.
- Treat high-reputation shared services contextually: parent-domain reputation should not override malicious child-hostname behavior.
Why This Bypasses Simple Reputation Thinking
The most interesting infrastructure decision in this campaign is the use of sslip[.]io. Defenders often score parent domains heavily. That approach is useful, but attackers know how to hide under legitimate, high-volume services.
A top-10K or Information Technology classification can make a parent domain appear safe in broad reputation systems. This campaign shows why reputation is only one input. The child hostname, embedded IP, page flow, form fields, and brand mismatch carry the real signal.
A high-reputation parent domain does not make a phishing subdomain safe.
Where ZeroBEC Fits
Perimeter email security, authentication checks, URL rewriting, and reputation feeds are still important. They reduce noise and stop many commodity attacks. Campaigns like this show why organizations need an additional layer that understands intent and context.
This attack is not just a bad URL. It is a relationship problem: Samsung sender identity, Costco content, non-Costco link, high-reputation shared DNS parent, credential collection, SSN collection, payment-card collection, and a final redirect to the real brand.
ZeroBEC is designed for exactly this kind of gap. Built as a full AI system rather than a rules engine, it analyzes each message like an investigator. The starting point is the recipient's normal communication patterns: whom they typically hear from, which brands and senders they actually interact with, how their mailbox behaves day-to-day. The current message is then evaluated against that personal baseline alongside brand mismatch, sender and content alignment, link intent, page behavior, requested data, and the full social-engineering flow. A Samsung-sender / Costco-content message arriving for a recipient who has never received transactional mail from either brand is a sharp anomaly against their own history, even when every external reputation signal looks clean.
Advanced AI-native email security should sit on top of existing perimeter defenses. The perimeter is necessary; context-aware AI analysis is what helps catch the nuanced, cross-brand, multi-stage attacks that exploit trusted-looking infrastructure and human workflow assumptions.As attackers increasingly chain legitimate services, trusted brands, and realistic workflows, security teams need detections that reason across the entire attack narrative. ZeroBEC helps surface those hidden relationships before a user becomes the detection mechanism. Ready to see behavioral detection in action against cross-brand phishing? Start free or contact us.