DataDog being abused in phishing campaign

Hi,

Posting since I haven’t seen DataDog being abused before. I hope it helps.

Related:

Headers:

MIME-Version: 1.0
Date: Wed, 15 Apr 2026 19:41:10 +0200
From: Datadog Alerting <alert(at)dtdg[.]co>
Subject: Triggered: #Reciept is ready to view #006290
Thread-Topic: Triggered: #Reciept is ready to view #006290
Message-ID: REDACTED@geopod-ismtpd-6

Thanks! Datadog isn’t mentioned in that report, so was this a sample you caught yourself?

How does one abuse Datadog functionality to produce these messages? I’m unfamiliar with the platform.

Hi,

The sample was reported by an employee.

DataDog has Monitors that trigger when an arbitrary event happens, like a certain regex matches a log line or a computer is overloaded. This event generates an email that is sent to a predefined email address, and the contents can be customized. Nothing fancy.

1 Like