Phishing is getting past mail gateways by borrowing trust from domains that already look established. The standard response misses that a brand-new lure can arrive on infrastructure with years of clean history, so reputation scoring can favor the attacker instead of blocking them.
The campaign described uses aged domains with long certificate and DNS history, and one Sneaky2FA operation was run from 117 origin servers across two hosting providers. The targets include government, energy, and healthcare organizations in the UK and US, which shows this is a durable infrastructure play, not a one-off lure.
The risk persists wherever email security leans hard on domain age and certificate history. Once that trust is inherited, the phishing site can keep reaching inboxes even when the content is malicious.