Manufacturing Phishing Teardowns
Every Attack of the Day teardown where the targeted organization was in manufacturing, newest first. Real attacks on manufacturers, dissected: the headers, the lure, and why it got past the first line of defense. Targeted organizations are never named.
All teardownsEducationHealthcareFilter in the ExplorerManufacturing email security
2026
- A Phishing Kit Padded Its Payload With Someone Else's Mail
- The Whole Page Is the Button: A PDF Click Trap
- Two-Stage Bank Scam Splits the Link to Starve Scanners
- The PDF That Scanned Clean Because Nobody Could Read It
- The PayPal Scam That Emailed You Your Own Password
- Three Brands, One Lure: A Chase 'Secure Message via Virtru' That Actually Came From LinkedIn
- The Compliance Notice That Borrowed the Government's Words and the Carrier's Own DOT Number
- The File Format Your Gateway Forgot: EPS Macros Hidden in a Logo ZIP
- The Payroll Memo Whose Link You Could Not Scan: QR Code Quishing Buried in a Word Attachment
- Seized and Still Dangerous: IP-Literal Download Link, Netlify Credential Page, and a VIP Target
- A Construction Bid Invitation Hid a Compromised Website Behind a Legitimate-Looking PDF Label
- A Fake Scotiabank Voicemail Was Actually an HTML File Asking You to Call an Attacker
- The Law Firm Document That Linked to a Cleaning Company
- The Invoice Portal Link That Didn't Need a Password
- The Invoice Email With No Text to Scan: Image-Only Payload From a Compromised Account With a Broken ARC Chain
- The Password Reset That Came From an Auth0 Dev Tenant
- The Warranty Form With a Windows Executable Hidden Inside a GIF
- The Spreadsheet With No Macros and One Hidden Link: External Relationships in Office XML
- Perfect Authentication, Zero Payload: The Yahoo Free-Mail BEC That Microsoft Flagged but Didn't Block
- The Government Email That Authenticated Itself After Transit
- Insurance Claim PDF Hides JavaScript Behind AcroForm Fields and SendGrid Redirects
- Sign Here, Get Phished: Inside an Adobe Sign Lure With a Multi-Hop Redirect to Credential Theft
- One Missing Letter, One Stolen Payment: A Reply-To Typosquat That Beat the Spam Score
- The URL That Put adobe.com in the Wrong Place
- The Button Text Was the Weapon: Unicode RTL Obfuscation Inside a DocuSign Lure
- When the Safety Wrapper Becomes the Disguise: Brazilian NF-e Phishing via Safe Links Rewrite
- The FedEx Email Was Real, the PDF Was an Image, and the Sandbox Saw Nothing
- SafeLinks Wrapped the Phishing URL With the Recipient's Name on It
- Hyundai Card HTML Attachment Harvests Credentials Without a Single Malicious URL
- The Auth0 Developer Tenant That Passed Every Security Check (Because It Was Real)
- Encrypted PDF Invoice Drops Through SPF, DKIM, and DMARC on a 6-Day-Old Domain
- A Fake Microsoft Quarantine Notice Rode a Hijacked Business Thread Through Amazon SES
- When the Password Reset Comes From a Fortune 500 Logistics Giant
- Microsoft's Own Domain, Your Attacker's Form: How forms.cloud.microsoft Became a Credential Harvest Host
- Seven Days Old, Port 8443: The Throwaway Domain That Safe Links Couldn't Stop
- A False Positive Worth Studying: Why Behavioural Detection Fired on a Legitimate Email
- A Pixel-Perfect Sephora Delivery Notice Shows Why Email Authentication Alone Can't Protect You
2025
- The Wire Transfer Confirmation That Had No Body, No Links, and Full Authentication
- The DKIM Key That Was Too Small to Verify: When Cryptographic Weakness Becomes a Detection Gap
- The Marketing Email That Forgot to Fill In Its Own Template
- Three Brands, Zero Connection: A Saudi Football Club, a Healthcare Vendor, and a Business Advisory Firm Walk Into Your Inbox
- Authenticated Dutch Email from WBG Pooling Carries Undecodable Barcode in Signature Image
- Taulia Supplier Portal Impersonation with Footer Address Mismatch via Amazon SES
- Hidden in Plain Sight: Executables Buried Inside a JPEG and a 1KB ZIP
- A Phishing Lure Hiding Inside a Real Microsoft Verification Email
- Three Domains, One Scam: The RFQ That Routed Replies to a Freshly Built Lookalike
- The Proposal Button Nobody Could Inspect
- The JPEG That Kept Going After the Image Ended
- The Verizon Rewards Email with a Kitchen Drawer Stuck in the Middle
- The Email Was Real. The Workspace Was the Weapon. An Asana Invite Claimed to Be From Meta.
- The 454 KB HTML Attachment That Pretended to Be an Outlook Inbox
- The Fake PayPal Charge That Needed You to Read Your Own Login Code Out Loud
- Three Brand Names, One Payment Email, and a PDF That Lied About What It Was
- Four PE Executables Hidden Inside an OLE Container Disguised as a CAD Drawing, Sent From Inside the Organization
- The Google Calendar Invite That Charged $316.66 to a Brand That Didn't Send It
- The Shipping Notice That Hid a Windows Executable Inside a PNG
- Oracle Email Delivery Sends the Phish: Authenticated Invoice Lure via NetSuite Infrastructure
- Zero-Link 'Reply YES' Scam Uses Hotmail to Bypass Every Payload Scanner
- Purchase Order PDF With Embedded Image Bypasses Static Analysis From Authenticated Sender
- Malicious PDF Proposal Hides Behind Authenticated Vendor Infrastructure and Four Words
- The Invoice Was an Image. The Body Was Two Words. The Authentication Was Perfect.
- Full Authentication, a Three-Week-Old Domain, and a Link Flagged Malicious
- Hiding Inside the Security Stack: How a Redirect Chain Used Trusted URL-Rewriters to Deliver a Throwaway Domain
- The W-9 Request That Proved Itself: How a Click-Tracker PDF Targeted One Accounts-Payable Recipient
- DocuSign Lure, Compromised WordPress Endpoint: When the CTA Goes Nowhere DocuSign Would Ever Send You
- Three Domains, One Fake Invoice: The Pact Group Payment Confirmation Lure
- Construction Plan Room Impersonation: Amazon SES Authentication Passes While the CTA Routes to nasr.org.uk
- HPI Brand Impersonation Uses Authenticated-but-Unrelated Amazon SES Sender and Three-Hop Redirect Chain
- Free Hotmail, Fake Adobe: How a Relocation Lure Hid a Throwaway Credential-Harvest Domain
- MSC Brand Impersonation Abuses a Legitimate Open Redirector and Base64-Encodes the Victim's Address for Targeted Tracking
- Trusted Vendor, Attacker's Form: How a Compromised Lab Account Delivered a Zoho Credential Harvest
- Image-Only Invoice Fraud: How Attackers Hide Mule Bank Accounts from Every Text Scanner
- No Links, No Malware, Just a Phone Number: Geek Squad TOAD Invoice Targets an Engineering Manager
- Finance Director's Name, Stranger's Domain: VIP Display-Name BEC Targets Accounts Receivable Data
- Compromised Vendor M365 Account Issues Fraudulent Banking-Change Instructions Across Four Mailboxes
- Price Revision as the Hook: How a Mirror Site Without TLS Impersonates an Industrial Supplier
- PE Executable Concealed in a JPEG, Nested Inside an RFC822 Email: The COSCO Bill-of-Lading Lure
- Luxury Brand Bait: How Mandrill, Safe Links, and a Fake Display URL Combined to Hide a Credential Harvest
- When Amazon SES Carries the Malware: HR Impersonation and a Confirmed-Malicious PDF
- Dairy Brand, IRS PDF, Stolen Credentials: How ESP Abuse Launders Phishing Trust
- No Link, No Compromised Account, No Problem: How a Personal Outlook Address Delivered a Boleto Fraud
- Your Own IT Department, Forged: BOM Encoding and a Medium Open-Redirect Hide a Vercel Credential-Harvest Portal
- Dressed as Microsoft Forms, Pointing Somewhere Else: How a Single Wrapped CTA Hid Behind a Page Full of Legitimate Links
- One Day Old, Fully Authenticated: How a Fresh Attacker Domain Passed Every Check and Delivered a Fraudulent Boleto
- Real Brand Trackers as Cover: A Boot Barn and DocuSign Impersonation That Routed One Malicious Link Through a Field of Legitimate Ones
- The Netflix Billing Alert That Every Scanner Blessed (One Header Told the Truth)
- When the Link Has Nothing to Do with the Brand: Nexi Impersonation via Throwaway Domain
- This Phish Wanted Your LINE QR Code, Not Your Password
- They Hijacked a Real Thread to Hide a Google Redirect
- The $0.01 Email That Was an Account-Fraud Dry Run
- The FedEx Invoice Your Scanner Couldn't Read on Purpose
- A Real Zoom Alert With Fraud Text Grafted Into It
- A Free Trial Bought Them a Perfect Sending Identity
- The Authenticated Email That Only Wanted a Contact List
- Nothing to Block: Real DocHub, Fake QuickBooks Branding
- A Month-Old Domain With Perfectly Clean Authentication
- A 64-Bit Password, Handed Over in the Same Email
- The Phishing Link That Was Only an Image
- Perfect Authentication, Invented Conversation
- Fake HubSpot Partner Invoice, Recycled Phishing Kit
- Spoofed LinkedIn Alert Rides an ARC Seal Past DMARC
- SPF-Passed Email Carried an $80K Fake Vendor Invoice
- Own-Domain Spoof Fails SPF, DKIM, and DMARC, Still Delivers
- QuickBooks Display Name, LinkedIn Envelope
- The Share Button Looked Real. The Domain Didn't.
2024
- Europol Doesn't Email You a Screenshot
- The Credential Form Lived on a No-Code Automation Platform
- Failed Every Auth Check, Then Rode Google's Links to S3
- The Scam That Couldn't Spell the Name It Impersonated
- Invisible Letters Hid a Mailbox Verification Phish
- The Zero-Width Trick Inside a Fake Microsoft 365 Bill
- The Fake Webroot Renewal Hiding in a Calendar Invite
- The Gmail That Namedropped the CEO for a Phone Number
- DMARC Said Reject. The Real Account Sent It Anyway.
- The Verified FedEx Email That Wanted Your Documents
- A $27M Funding Pitch From a Trust That Doesn't Exist
- The PayPal Invoice Was Real. The Fraud Was Not.
- A Real Gmail, a Real Drive Link, a Fake Tax Form
- The Bank Authorization Lure Amazon SES Waved Through
- A Fake DocuSign Request Bolted to a Parking Thread
- SharePoint Renewal Lure Rides a Real Security Gateway
- The One PayPal Link That Dropped to Plain HTTP
- An Attachment Named Like the Microsoft 365 Admin Center
- The SAM.gov 'Final Notice' That Never Touched a .gov
- The RFQ With No Sender and a Hijacked Reply Path
- DocuSign Kit So Reused It Left a Hearing-Aid Signature
- A Hijacked ISP Mailbox, a QR Code, and a Clean DKIM Pass
- A Hijacked 20-Year-Old Mailbox Delivers a Document Lure
- When a University Mailbox Peddles a Loan Scam
- A Real Datadog Report, a Fake Bill, One Phone Number
- The Brand Name Was in the Path, Not the Domain
- The Password Was in the Email, Highlighted in Yellow
- A Fake Government Newsletter and a 45-Minute-Old Domain
- When the Subject Line Is Your Own Name
- When the Sender Name Is Not Even the Same Alphabet
- A Refund Notice From the Wrong Industry
- A Company Impersonating Itself, From Someone Else's Mailbox
- The Fake McAfee Renewal Typed Into a Calendar Field
- The Union Benefits Domain That Was Seven Weeks Old
- The Receipt That Looked Like You Sent It to Yourself
- The Invoice Authenticated Cleanly for the Wrong Company
- Clean Attachment, Clean Link, and a Guessed DMARC Pass
- Sixteen Minutes Old: An E-Signature Lure With No Text
- The Trade Lead Whose Own Website Did Not Resolve
- One Invoice Email, Four Different Identities
- Three Hops Deep, Behind a Gate No Scanner Can Solve
- The Wrong Tax Form Broke a Flawless Vendor Email