TL;DR A customer-service representative at a residential trades contractor told a sender in writing that her team could not open attached files, and asked two verification questions. Two minutes later the sender replied. It had already pre-empted that objection fourteen minutes earlier, unprompted, and across four turns in twenty-four minutes it offered three different reasons the file would not open while repeating one device instruction unchanged. Suspicion did not end the attack. It opened a negotiation the attacker was better prepared for, and the refusal had nowhere to go except back to the sender.
Severity: High Phishing Platform Abuse MITRE: T1566.002 MITRE: T1585.002 MITRE: T1204.001 MITRE: T1608.005

At 10:24 on the morning of Thursday, August 20, 2026, a customer-service representative at a regional residential HVAC, plumbing and electrical contractor did exactly what every awareness program asks of a front-line employee. She wrote back to a sender she did not trust and told it, in plain words, "We are unable to open any attached files." Then she asked two sensible verification questions: was this for a home the sender owned, and was the work HVAC, electrical, or plumbing?

Two minutes later, at 10:26, the sender replied.

Four Turns in Twenty-Four Minutes

The thread she was answering in had been seeded five days earlier, on Saturday the 15th, when someone submitted a request for an air-conditioning estimate through the company's own public website and the site notifier delivered it to her shared customer-service mailbox. That is the whole of the setup, and it is not the interesting part.

At 10:02 on the Thursday, a free Gmail account replied into that thread with a courteous estimate request, offered a video call, and presented a line reading "Project Documents:" above what looked in the mail client like a native cloud-storage attachment chip labelled with a PDF filename. At 10:05, the representative asked what work was needed. At 10:10 the sender answered, and volunteered something nobody had asked about: "i had the file sent to me just like that. It contains the address, all units, measurements documents and pictures you would need for an estimate. due to its large file size, you can open it using a window pc." At 10:24 came her refusal. At 10:26 came the answer to it: "its a new home, open on a window pc. that should work."

Four turns. Twenty-four minutes. A logged, timestamped, quotable negotiation conducted entirely inside a mailbox, with a correspondent on the other end who was still there when the defender pushed back.

The Objection Was Staged Before It Was Raised

Read the 10:10 message again against the 10:24 one. Fourteen minutes before the representative said her team could not open attached files, the sender had already explained why the file might not behave normally and had already supplied the workaround. Nobody had questioned it. The excuse arrived ahead of the objection it was built to absorb.

This is a different kind of preparation than a pretext. A pretext establishes why a message should be believed. This was an inoculation against a specific, predictable, correct instinct, deployed pre-emptively into a conversation that was going well.

Three Accounts, One Instruction

The shape of the retreat is the reveal. The first account shifted responsibility away from the sender: the file had arrived in that condition. The second offered a causal explanation with a technical flavour: the file was too large. The third, answering a flat written refusal, offered no explanation at all. It simply repeated the instruction and added, "that should work."

Under pressure the story did not improve. It was abandoned. The only element carried across every turn was the device steer, the lowercase "open on a window pc" that never changed while everything around it was rebuilt each time it was tested. Whether a person or an automated system composed those replies is not something this record can settle. What is observable is that they were fast, they answered the specific question asked, and they adapted. This is the spearphishing link pattern running with a live hand on it, using an email account established for the purpose.

The Attachment That Was Not There

There was no attachment. The incident record shows an empty attachment array. The chip was HTML: an anchor wrapping an 18 by 18 pixel image hotlinked from a legitimate cloud-storage provider's own PDF mediatype icon, set in the typeface and thin grey border a real attachment widget uses. Clicking the filename entered a click-tracking redirect run by a commodity email delivery platform, which expanded to a host on an attacker-registered apex domain behind a CDN. What lay past that host was never captured. This is a supporting detail rather than the story, but it explains why there was anything for the sender to make excuses about.

See Your Risk: Calculate how many threats your SEG is missing

Every Warning Fired and Nothing Changed

Authentication passed cleanly at every layer, because nothing was forged: a real Gmail account, real mail, genuine Google infrastructure, and the receiving platform's own verdict of "not spam." There was no header anomaly to find.

The more uncomfortable detail is the banner. The inbound gateway prepended its external-sender caution notice to every hop, so it appears four times in the message, once per quoted turn. It fired on all four turns and the conversation continued anyway, which is what a warning does when it comes with no route out of the conversation. Identity, authentication and conversation history had all been satisfied already, so the only layer with anything left to contribute was link analysis: the sole recorded detection insight flagged the destination behind that PDF-labelled chip. Four copies across two mailboxes were quarantined, and remediation landed two weeks later.

A Refusal Needs Somewhere to Go

The 2026 Verizon Data Breach Investigations Report puts the human element in 62% of breaches and phishing in 16% of initial access vectors, with pretexting accounting for 6%. Those figures are usually read as an argument for more training. This incident argues for something narrower. The training worked. The representative was suspicious, she declined in writing, and she asked the right questions. What she did not have was anywhere to send the message except back to the person who sent it.

Contrast it with the fabricated-thread pattern, where the quoted replies inside a lure are invented and the conversation collapses the moment you check whether it exists anywhere else. Here it did exist, in the organization's own sent mail, and a live correspondent was maintaining it. Separate it too from telephone-based social engineering, where the real-time negotiation leaves no artifact to examine afterwards. This one happened in writing, in the inbox, with timestamps. No phone call appears anywhere in the record.

So the control is organizational, not personal. Shared intake mailboxes that answer strangers for a living, the ones named for customer service, information or sales, need a one-click report path and a standing rule that a refusal is escalated and never negotiated. Awareness training that ends at "the user was suspicious" describes the middle of the story. Malicious link and payload analysis closed this one, after every identity signal had pointed the wrong way. Both CISA and NIST treat reporting as part of the control rather than an afterthought, and these twenty-four minutes show why: a correct objection is not a stopping condition unless it can be escalated out of the attacker's reach. The figures above are from the 2026 Verizon Data Breach Investigations Report.

Indicators of Compromise

TypeIndicatorContext
Emailmichaelhay7777@gmail[.]comAttacker-controlled Gmail account; the account that answered the written refusal two minutes after it was sent
Phone(713) 364-2852Attacker-supplied contact data; area code inconsistent with the recipient organization. Nothing in the record shows it was ever used
URLhxxps://ct[.]sendgrid[.]net/ls/click?upn=[truncated]Redirect behind the forged PDF-labelled chip. Shared platform; account ownership undetermined and not attributed
Domainct[.]sendgrid[.]netCommodity click-tracking host; shared platform, not attacker-owned
URLhxxps://pcprocessingadobeuptodater[.]zyvlora[.]vu/maadobequeExpansion target; a brand string is concatenated into the hostname label, but no brand asset or branding was used
Domainpcprocessingadobeuptodater[.]zyvlora[.]vuAttacker-owned subdomain
Domainzyvlora[.]vuAttacker-owned apex; no MX, no published DMARC or DKIM, CDN-fronted, valid TLS
URLhxxps://ssl[.]gstatic[.]com/docs/doclist/images/mediatype/icon_3_pdf_x64.pngLegitimate provider icon hotlinked to forge a native attachment chip; not attacker infrastructure
Domainmail-yw1-x112f[.]google[.]comGenuine outbound relay. Legitimate infrastructure

MITRE ATT&CK Mapping

TechniqueIDObserved as
Phishing: Spearphishing LinkT1566.002PDF-labelled chip wrapping a redirect to an attacker host
Establish Accounts: Email AccountsT1585.002Free webmail account sustaining a four-turn exchange
User Execution: Malicious LinkT1204.001Repeated device-specific instruction to open the link
Stage Capabilities: Link TargetT1608.005Attacker-registered apex and subdomain staged as destination

IRONSCALES and our Adaptive AI analyst, Themis, evaluate the conversation and the destination together rather than the envelope alone, and give every mailbox a one-click path to report rather than reply. See the platform.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
The Proposal Button Nobody Could InspectA phishing email disguised as a vendor proposal used an image-only CTA linking to Box.com.
The Audio Player That Was Never an ImageA message that reached a commercial building-services and construction firm carried one call to action: a media player with a waveform, a play control.
The Certificate Validation Path That Became a Credential HarvesterAttackers hosted a credential harvest page inside a .well-known/acme-challenge/ path, the directory reserved for Let's Encrypt certificate validation.
Every Link Was Real: DocuSign Reply-To Diversion With a Same-Day DomainA phishing email sent through legitimate DocuSign infrastructure passed SPF, DKIM, and DMARC with perfect scores.
Fake AI Conference, Real Authentication: How Attackers Weaponized Lu.ma to Bypass Every Email CheckAttackers registered a fake AI conference on lu.ma and sent phishing emails through the platform's own Amazon SES pipeline.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.