Heads up: Active phishing campaign targeting the OWASP Global Board

1 view
Skip to first unread message

Steve Springett

unread,
Mar 27, 2026, 4:10:06 PM (3 days ago) Mar 27
to OWASP Project Leaders, OWASP Chapter Leaders, OWASP Global Board
Leaders,

We've identified a spear phishing campaign targeting OWASP Global Board members. Some of these emails are spoofed to look like they're coming from me. They are not.

If you receive anything suspicious that appears to be from a Board member, do not engage with it. Verify through a separate channel and report it to Foundation staff.

Image samples attached.

Steve Springett
Leader, OWASP CycloneDX and Dependency-Track
Leader and Co-author, OWASP SCVS
Chair, OWASP CycloneDX and Ecma TC54
Chair, OWASP Global Board of Directors
signal-2026-03-28-005521-1.jpg
signal-2026-03-27-145709.jpg
Reply all
Reply to author
Forward
0 new messages