TL;DR A marine-electronics manufacturer received an advance-fee scam impersonating a global financial authority. The lure demanded full personal details within 48 hours to reopen a payment file, invoked the World Bank, UN, EU, and IMF, and routed replies to an off-domain Yandex mailbox. The sending domain passed SPF and DKIM, but the signature misspelled the very name it borrowed. That typo, plus the mismatched Reply-To, exposed the impersonation that authentication alone could not catch.
Severity: Medium Advance-Fee-Fraud Impersonation Business-Email-Compromise MITRE: T1566 MITRE: T1656

A Deadline, a Reference Number, and One Fatal Typo

The message arrived with the weight of the world behind it. It invoked the World Bank, the United Nations, the European Union, and the International Monetary Fund. It carried a long fabricated reference string, the kind of alphanumeric code that looks official precisely because it is impossible to verify. It was signed by Christine Lagarde, one of the most recognizable names in global finance. And it gave the recipient, a data sourcing manager at a marine-electronics manufacturer, exactly 48 hours to "submit your complete details for verification" and "reopen your payment file."

There was just one problem. The scam could not spell the name it was impersonating.

The real Christine Lagarde signs her name Christine Madeleine Odette Lagarde. This message closed with "Christine Madeleine O'Lagarde." An apostrophe and a mangled middle name turned a borrowed authority into a giveaway. A fraud that leans entirely on institutional prestige cannot afford to fumble the one detail that prestige depends on: the name itself.

How the Authority Play Works

This is an advance-fee scam, a long-running form of phishing sometimes called a 419 scam after the section of criminal code it is associated with. The mechanics are old, but the packaging is deliberate. Instead of a windfall inheritance from a distant relative, this variant wraps the pitch in the language of international financial governance. The promise of a released payment sits behind a wall of acronyms, and the recipient is invited to unlock it by handing over personal information.

The 48-hour deadline is the pressure valve. Urgency short-circuits the pause where a person might otherwise think to check whether the International Monetary Fund actually emails individual employees about payment files. The reference string does similar work, manufacturing the appearance of a case already in progress. Together they nudge the target toward the reply, which is where the real payload lives.

Because there is no malicious link and no attachment, the technical surface is nearly empty. Nothing to sandbox, nothing to detonate, nothing for a scanner to flag. The entire attack is social. According to the 2024 Verizon Data Breach Investigations Report, the human element factors into 68 percent of breaches, and this message is engineered to exploit exactly that.

The Authentication Paradox

Here is the uncomfortable part. The message was properly authenticated.

The sending domain, cadom-services[.]fr, passed both SPF and DKIM. It had been registered in 2015 through an OVH-hosted account with an opaque registrant, so it carried no obvious newness penalty and no reputation red flags. DMARC returned a bestguesspass with an action of none, and the message landed with a Spam Confidence Level of 5, comfortably inside the inbox rather than the junk folder.

Authentication answers a narrow question: did this message really come from the domain it claims? It does not answer the question that matters here, which is whether the claim inside the message is true. The Microsoft Digital Defense Report 2024 makes the same point at scale, noting that identity-based and social-engineering attacks succeed by abusing trusted paths rather than breaking them. A well-configured domain can carry a lie just as reliably as it carries the truth.

The tell that authentication cannot see is the Reply-To. Replies were not routed back to cadom-services[.]fr, the domain that passed every check. They were diverted to a.kunu@yandex[.]com, a consumer mailbox with no relationship to the sending infrastructure and no connection to any financial institution. The authenticated domain existed to get the message delivered. The Yandex address existed to collect the harvest. Learn more about defending against this pattern on the business email compromise protection page.

Mapping the Attack to MITRE ATT&CK

Two techniques from the MITRE ATT&CK framework describe this attack cleanly.

[T1566] Phishing covers the delivery. The message was sent as unsolicited email designed to elicit a response and extract sensitive information, the defining shape of a phishing lure.

[T1656] Impersonation covers the deception. The attacker assumed the identity of a named financial authority and layered on the borrowed credibility of four global institutions to pressure the target into acting against their own interest.

The FBI Internet Crime Complaint Center 2023 report continues to track advance-fee fraud as a persistent category, a reminder that these schemes endure because the underlying social lever, the promise of money in exchange for cooperation, never stops working on someone.

Indicators of Compromise

All indicators are defanged. Do not interact with them.

IndicatorTypeContext
cadom-services[.]frSending domainOVH-hosted, registered 2015, opaque registrant, passed SPF and DKIM
a.kunu@yandex[.]comReply-To addressOff-domain consumer mailbox that collected replies
178.33.251[.]152Sending IPOrigin of the authenticated message

Reading the Signals

No single field in this message screamed fraud. The domain checked out. The formatting was competent. The story was internally consistent enough to survive a skim. Catching it required reading the signals together rather than one at a time.

A first-contact sender invoking global institutions. A hard 48-hour deadline. A request for complete personal details. A Reply-To that pointed somewhere the sending domain did not. And a signature that misspelled the authority it claimed to be. Individually, each is a soft signal. Stacked, they form a pattern that behavioral analysis is built to recognize.

This is the gap that Adaptive AI is designed to close. Rather than trusting a domain because it authenticated, Themis weighs sender history, content intent, reply-path consistency, and anomalies like a misspelled principal, then scores the message on how it behaves in context. The 2024 Verizon Data Breach Investigations Report clocks the median time to click a phishing link at 21 seconds and to submit data at 28 seconds, and the CISA phishing guidance underscores that stopping the attack before that first interaction is the highest-leverage control. Context, not reputation, is what flags the lure in time.

The Takeaway

A scam that borrows authority is only as strong as its weakest imitation, and the name is never optional. This one passed every authentication check a mail system could throw at it, then undermined itself with an apostrophe.

The lesson is not to hunt for typos. It is that authentication and content truth are two different things, and defending against social engineering means evaluating the whole message, sender behavior, reply path, urgency, and internal consistency, rather than trusting a green checkmark on the sending domain. The attackers will keep getting the infrastructure right. The defense has to read everything else.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
DocuSign Lure, Diverted Replies: How Reply-Path Manipulation Turns a Legitimate Envelope Into a BEC TrapAn authenticated DocuSign notification arrived with its Reply-To silently diverted to an external attacker-controlled domain.
Accounts Payable Display-Name Spoof Delivers a Teams-Branded Payment Lure to a CFO via SendGridAttackers registered astevenltd.com, set the From display name to an Accounts Payable identity.
Lookalike Domain With Full Authentication Sends a Zero-Payload Trust-Building EmailAn attacker registered a lookalike domain one word apart from a known vendor's real domain, configured full DKIM and DMARC authentication.
BEC Wire Diversion via Compromised Authenticated Vendor: PDF Bank Instructions From a Domain That Passed DKIM and DMARCA payment-diversion BEC attack arrived from an authenticated cold-chain logistics vendor domain that passed DKIM, DMARC, and composite auth.
BEC Payroll Diversion via Display-Name Impersonation: No Links, No Attachments, High ConfidenceA threat actor sent a plain-text payroll-diversion request impersonating a senior executive at a technology company.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.