The subject line reads: "URGENT: Verification required for your company's press listing." The sender: newsroom-desk@ a domain one letter off from a real outlet. Inside, a familiar design, a real masthead photo scraped from LinkedIn, and a link to "confirm your media profile." Targets who click land on a credential-harvesting page. Targets who reply get the second act: an invoice for a "directory listing upgrade" they never ordered.
Fake newsroom email is the PR world's phishing layer — a hybrid of brand spoofing and business email compromise aimed at the people who answer media mail fastest: comms teams and founders chasing coverage.
Why PR is the ideal phishing vertical
Security teams train finance departments to verify wire requests. Nobody trains comms teams to verify journalists. The pressure works in the attacker's favor: media requests carry deadlines, flattery, and the fear of missing coverage — the same levers used against accounts-payable clerks, applied to people whose job description rewards fast replies. The FBI's business email compromise advisories document billions in annual attempted losses from sender-impersonation schemes; media-branded variants borrow the same mechanics with a press badge. scam coverage.
The documented attack patterns
1. Credential capture
"Verify your source profile," "renew your media subscription," "unlock your press release dashboard." The links terminate at cloned login pages. PR platforms and media databases are the impersonated properties because one captured PR-agency login exposes dozens of client accounts, journalist contacts, and scheduled embargoes — a lateral-movement jackpot.
2. Invoice spoofing
An email from a "newsroom billing desk" requests payment for a listing upgrade, syndication renewal, or embargo fee. The fake invoice exploits a real ambiguity: many outlets do sell legitimate ancillary services (advertorials, directories, event tickets), so a plausible invoice often finds an accounts-payable process with no mechanism to check. Payments routed to attacker-controlled accounts are typically unrecoverable after settlement.
3. The attachment
"Press release draft for fact-check," "embargoed documents," "interview consent form." Malware payloads arrive as documents because documents are the currency of trust between newsrooms and sources. Security-industry post-mortems of media-sector intrusions repeatedly trace initial access to exactly this channel.
How the spoof is built
The build is cheap and inspectable. Lookalike domains — swapped letters, added hyphens, alternate TLDs — cost under $15. Logo theft is a right-click. The sender display name does the heavy lifting: mail clients show "Newsroom Desk" prominently and the actual domain only in the details. Scraped staff photos and masthead layout complete the costume. Nothing in the stack requires skill; everything requires only that the recipient checks nothing.
The institutional response
Major outlets now publish impersonation warnings and state outright what they will never ask for: payment for coverage, credential re-verification by email link, or attachments outside known editorial systems. DMARC email authentication, which lets receiving mail servers verify that mail genuinely comes from a domain's infrastructure, has become standard at major publishers — and remains inconsistently deployed across the long tail of local and trade media where most spoofing happens.
Related stories: Your Press Kit Is a Product — and Someone Is Reselling It · The 'Guaranteed Forbes Placement' Machine: How Clone Mastheads Sell What They Don't Own.
One intercepted thread, dissected
The anatomy of a live attempt shows how much evidence sits in plain view. A comms team received "billing@ a newsroom domain" for a $940 "directory renewal." Dissection: the sending domain was registered 61 days earlier, privacy-shielded, on a registrar known for high-abuse tolerance; the display name rendered "Newsroom Billing Desk" while the raw domain differed from the real outlet's by one doubled letter; the invoice PDF's metadata listed a creation date two days before the email and an author field matching no publication; the payment rail was a payment-app handle, not a bank account — because bank accounts leave KYC trails payment apps largely avoid. Every one of those facts was checkable in under ten minutes with WHOIS, a PDF inspector, and the outlet's published contact. The thread, preserved with full headers, later supported the registrar's abuse takedown of the lookalike domain. The broader lesson for comms teams: spoofing is cheap but never free — it always leaves registration, metadata, and payment-rail evidence. Teams that check one of the three stop the fraud; teams that preserve all three help end the operator.
A one-interception post-mortem
Teams that intercept an attempt should run a short post-mortem, because the finding is always process, never luck. Standard findings in reviewed cases: the target replied inside minutes because no verification gate existed; the verification that eventually caught it was accidental — a colleague CC'd on a whim; and the evidence preservation happened late, after a reply or two had already been sent. The fix list is correspondingly short. One verification gate: no external media contact reaches an executive inbox without a masthead or callback check logged. One delay rule: no attachments, payments, or credentials inside the same business day as first contact. One preservation habit: full headers and the untouched thread saved before any response. Teams that adopt all three report the same pattern in later attempts — the spoof collapses at the gate, and the preserved evidence supports registrar takedowns that take the lookalike domain down for the next target too. Interception is not the end of the incident; it is the beginning of the record that shortens the attacker's runway everywhere else.
How to protect yourself
- Read the domain, not the name. The display name is decoration; the sending domain is the fact. One-letter differences are the whole trick.
- Never pay any invoice that touches editorial. If it claims to be billing, verify through the outlet's published contact channels — a phone number you look up, not one in the email.
- No credential links from inbound mail. Navigate to any media platform by typing its address yourself.
- Attach nothing on first contact. Embargo materials move after identity is verified and under agreed terms.
- Train the comms desk like the finance desk. Media requests need the same callback discipline as wire transfers.
- Report the spoof. To the impersonated outlet (they pursue brand abuse), to the registrar (lookalike domains violate registration abuse policies), and to the FTC and FBI IC3 where money moved.
The fake newsroom email works because it requests exactly what its target already wants to give: attention, materials, access. That is what makes it dangerous — and what makes the countermeasure simple. Institutions are verifiable. Verify.
For more context, read The Fake Journalist Playbook: Interview Bait, Paywalled 'Features,' and Stolen Bylines.
For more context, read pr reseller.
For more context, read Your Press Kit Is a Product — and Someone Is Reselling It.
