Reference LIB-2026-08

Compromised sending credential and phishing abuse

Libra Innovation FlexCo, Innsbruck, Austria

English below. Deutsche Fassung am Ende der Seite.

Purpose of this page

We are sending abuse reports to registrars, hosting providers, blocklist operators and national reporting bodies. Those reports name this page so the recipient can confirm they are genuine before acting on them.

This page carries no personal data and offers no downloads. Evidence is supplied on request, directly to the receiving organisation.

What happened

An API key belonging to our company was published by us, in plain text, in a public source code repository on 25 September 2025. A cleanup commit the same day removed it from the current version of the file but not from the repository history, where it remained publicly retrievable for 313 days.

On 4 August 2026 the key was validated by an automated credential checking tool. From 10 August 2026 it was used to send phishing messages through our verified sending domains. We revoked it on 22 August 2026 at 05:00 UTC.

There was no intrusion into any system of ours. No account was taken over, no vulnerability was exploited, and no DNS or registrar record was altered. The messages passed authentication because they were signed with our own valid DKIM keys, which is why no sender authentication mechanism could have prevented them.

Scale

Mass sending period16 Aug 2026 20:40 UTC to 21 Aug 2026 23:04 UTC
Earlier test messages10 Aug 2026, four messages
Messages sent36,835
Accepted by recipient providers17,617
Rejected18,599
Recorded clicks230, lower bound
Reported as spam by recipients85
RecipientsPrivate individuals and company mailboxes in Switzerland and France

The click figure is a lower bound: click measurement was active on only two of the seven affected domains. The real number is higher.

Brands impersonated

None of these organisations is in any way responsible for the messages, and none of them was involved.

For mailbox providers: how to find the messages

We do not send recipient lists. What lets you locate the messages in your own systems is the selector below. It is more precise than any list we could supply, and it avoids transferring personal data of your customers to a third party.

DKIM signing domains
kinn.at · nl.kinn.at · in.kinn.at · kidu.at · in.kidu.at · aicollective.at · in.aicollective.at
Envelope return path
send.<domain>, MX feedback-smtp.eu-west-1.amazonses.com
Time window
2026-08-16T20:40Z to 2026-08-21T23:04Z
Header From pattern
noreply@<any of the domains above>
Display names
Contain Cyrillic homoglyphs and a middle dot as a word separator, for example SЕRАFЕ·AG with Cyrillic А and Е, or Sеrаfе·SA with Cyrillic а and е. Roughly 155 distinct display names were used.
Subject patterns
Colis · Suivi · Point Relais · Livraison · Redevance de radio-TV · Déclaration de la situation · Envoi
Destination hosts in the message body
newsletter.galagers.space · newsletter.ch-suivicolis-dpd.com · rf.ijnggpi.com · seven Amazon S3 objects

Legitimate mail from the same domains uses named senders such as thomas@in.kinn.at or crew@in.kinn.at and carries no Cyrillic characters in the display name.

Note on verifying the phishing pages

The landing pages use cloaking. A request that does not match the target profile is redirected to an unrelated legitimate US magazine site. A reviewer who opens the reported address from outside Switzerland or France will therefore see a harmless page and may conclude the report is unfounded. Please take this into account, or request our captured evidence.

Status

Key revoked22 Aug 2026, 05:00 UTC
All other credentials rotated22 Aug 2026
Supervisory authorityAustrian Data Protection Authority. Notification under Article 33 GDPR being filed on 22 August 2026, within the statutory 72 hour deadline.
Service providerResend contacted 22 August 2026. A formal preservation request for the account logs is being sent the same day.
Sending abuseEnded 21 Aug 2026, none since

Contact

Thomas Seiger, Libra Innovation FlexCo, Innsbruck, Austria
security@libralab.at

We deliberately do not use an address on any of the affected domains. Those domains were the source of the abuse, and their sending reputation is still recovering, so a reply to them could be delayed or filtered.

We can supply, to any receiving organisation on request: complete delivery records with timestamps and message identifiers, original messages in full, the captured redirect chain, and SHA-256 checksums for all of it.

Deutsche Fassung

Diese Seite dient einem Zweck: Wer von uns eine Missbrauchsmeldung erhält, soll prüfen können, dass sie echt ist. Sie enthält keine personenbezogenen Daten und keine Dateien zum Herunterladen.

Was geschehen ist. Ein Zugangsschlüssel unseres Unternehmens wurde von uns selbst am 25. September 2025 im Klartext in ein öffentliches Quellcode-Verzeichnis veröffentlicht. Eine Bereinigung am selben Tag entfernte ihn aus der aktuellen Fassung der Datei, nicht aus der Versionsgeschichte, wo er 313 Tage lang öffentlich abrufbar blieb. Am 4. August 2026 prüfte ihn ein automatisches Werkzeug, ab dem 10. August wurde er für Phishing über unsere Versanddomains benutzt. Am 22. August 2026 um 05:00 UTC haben wir ihn widerrufen.

Es gab keinen Einbruch. Kein Konto wurde übernommen, keine Schwachstelle ausgenutzt, kein DNS-Eintrag und kein Registrar verändert. Die Nachrichten bestanden die Absenderprüfung, weil sie mit unseren eigenen gültigen DKIM-Schlüsseln signiert waren. Kein Authentifizierungsverfahren hätte das verhindern können.

Umfang. 36.835 Nachrichten zwischen dem 16. August 2026 um 20:40 UTC und dem 21. August 2026 um 23:04 UTC, davon 17.617 zugestellt, 18.599 abgewiesen, 230 nachweisliche Klicks und 85 Spam-Beschwerden. Die Klickzahl ist eine Untergrenze, weil die Messung nur auf zwei der sieben Domains aktiv war. Empfänger waren Privatpersonen und Firmenpostfächer in der Schweiz und in Frankreich.

Missbrauchte Marken: SERAFE AG, Schweizerische Post, DPD Schweiz, Mondial Relay und Crédit Mutuel. Keines dieser Unternehmen trägt dafür Verantwortung, keines war beteiligt.

An Mailanbieter: Wir übermitteln keine Empfängerlisten. Der Selektor im englischen Teil dieser Seite ist genauer als jede Liste und vermeidet, dass personenbezogene Daten Ihrer Kundschaft an einen Dritten gehen.

Hinweis zur Überprüfung: Die Phishing-Seiten tarnen sich. Wer die gemeldete Adresse von ausserhalb der Schweiz oder Frankreichs aufruft, wird auf eine unbeteiligte amerikanische Magazinseite umgeleitet und sieht kein Phishing. Bitte berücksichtigen Sie das oder fordern Sie unsere gesicherten Belege an.

Kontakt: Thomas Seiger, Libra Innovation FlexCo, Innsbruck, security@libralab.at. Bewusst keine Adresse auf einer der betroffenen Domains, deren Absenderruf sich noch erholt.