Suplantación de correos electrónicos y retrodispersión de correos: Aviso de seguridad
Security notice — fake cloud storage emails using our address
On 1 August 2026, a third party launched an email spoofing campaign using [email protected] as a forged sender address. These emails were not sent by ObviousIdea.
The messages pretended to be urgent cloud-storage or backup renewal notices. They claimed that a 250GB storage plan was full or had expired and threatened to permanently delete the recipient’s photos, videos, and backups unless payment was made immediately. This campaign was unrelated to ObviousIdea’s products and services.
How to recognise the fraudulent emails
The forged sender address was [email protected], but the visible sender name varied. Names recovered from the campaign included Backup Center, Storage Audit, Storage Security, Cloud Admin, Backup Center Team, Cloud Services, Account Management, Storage Alerts Team, Storage Notices and Cloud Care.
Observed subject lines
The following exact subject variants were recovered from delivery reports, security notifications, automatic replies and attached copies of the original fraudulent messages:
- Without action today, your files will be permanently deleted from storage
- Your files will be deleted if you don’t renew your storage today.
- Your files are at risk. Renew your storage now to protect everything.
- Your storage is 250GB full and your renewal status shows FAILED
- Your Cloud Plus 250GB plan has expired. Your storage is completely full.
- Your account needs immediate attention due to renewal failure.
- Action required: Your storage is full and renewal has failed completely
- Your storage renewal failed. Take action today to keep your files safe.
Some receiving systems added prefixes such as [SPAM], [DKIM FAILED], [EXTERNAL], Re:, Automatic reply or Undeliverable. Those prefixes may have been added by the recipient’s email system and are not necessarily part of the original subject.
What the fraudulent message looked like
Recovered copies used a professional-looking blue cloud-storage notice headed “Action Required: Your Cloud Storage.” The message claimed:
- a “Cloud Plus 250GB” plan had expired;
- storage usage was “250GB / 250GB (100%)”;
- the renewal status was “FAILED”;
- “ALL FILES” were at risk;
- photos, videos and backups would be permanently deleted that day;
- renewal would take less than 60 seconds;
- payment was encrypted and secure.
The email included a “Renew My Storage Now” button. Its links led to external Google Cloud Storage addresses, not to an ObviousIdea website. Do not click those links.
What happened technically
Email spoofing allows criminals to place a forged address in the visible From field. It does not, by itself, mean that the genuine mailbox or website was accessed.
The recovered messages came from external infrastructure and failed email-authentication checks. Samples failed DMARC, were not signed with an authorised ObviousIdea DKIM signature, and were not authenticated as legitimate ObviousIdea mail.
The large number of delivery failures, quarantine notices and automatic replies received by ObviousIdea is known as backscatter: remote systems responded to the forged sender address after processing the fraudulent campaign.
Based on the messages and authentication data reviewed, we found no evidence that ObviousIdea’s email service, website or customer accounts were compromised. This conclusion is limited to the evidence reviewed and is not a claim that every possible security scenario has been ruled out.
What you should do
- Delete or report any message matching these descriptions as phishing.
- Do not click the renewal, payment or unsubscribe links.
- Do not enter a password, card number or personal information.
- Do not reply to the suspicious message.
- If you already entered a password, change it directly on the genuine service’s website and anywhere else you reused it.
- If you entered payment information, contact your bank or card provider immediately.
- Contact ObviousIdea only through the contact details published on obviousidea.com.
We strengthened our DMARC anti-spoofing policy so receiving providers can quarantine fraudulent messages that fail authentication. We will update this notice if new verified information becomes available.
