Table of Contents
Two mailboxes at a South African engineering and energy-services firm received the same pitch on the same morning: a friendly offer of financing, loan amounts ranging from R20,000 all the way up to R50,000,000, no collateral drama, just reply and get started. On its face it read like unsolicited marketing spam, the kind most people delete on reflex. What made this one worth a second look was the return address. The message had not come from some throwaway domain. It had come from a real university's law faculty, from a genuine academic mailbox, and it had sailed through email authentication without raising a single technical flag.
That is the trick worth understanding here. The attacker did not spoof anyone. They logged in.
Authenticated by the right domain for the wrong reason
When the message hit the recipients' gateway, the authentication verdict was a study in mixed signals that ultimately came out clean. SPF returned a softfail, because the envelope sender pointed at a consumer Gmail address that was not authorized to send from the connecting mail server. On its own, that softfail looks like a warning sign.
DKIM told a different story. The signature verified cleanly against the university's own law-faculty domain, because the message genuinely originated from that domain's mail server. And DMARC, which only needs one authenticated, aligned mechanism to pass, found exactly that in the passing DKIM signature aligned to the visible sender. DMARC passed under the domain's published policy. The composite authentication check resolved to pass with the strongest possible reason code.
Read the verdict as a whole and it is not a spoof at all. The mail really did leave the university's servers, signed by the university's own key. This is the defining property of an account takeover: the attacker is operating from inside a legitimate, fully owned mailbox, so there is nothing for authentication to reject. The 2024 Verizon Data Breach Investigations Report puts stolen credentials at the top of initial breach actions, involved in 38% of breaches, and notes the human element is a component of 68% of them. A hijacked academic account sits squarely at that intersection. The technique maps to MITRE ATT&CK T1586.002, Compromise Accounts: Email Accounts.
A loan offer that hops three countries
The content, once you pull the thread, is a classic advance-fee scheme wearing a fresh coat of paint. The body promoted a South African lending brand on its own dedicated web domain, a domain that had been registered roughly two years before the email was sent. The registration itself carried a quiet contradiction: the WHOIS record was privacy-redacted, yet the registrant country resolved to Nigeria despite the advertised business being a South African lender. The promoted brand domain published a DMARC record set to no enforcement, so it offered no protection and made no promises.
The real tell was where the conversation was supposed to go next. Replies were quietly diverted off the university domain entirely, routed to a consumer Gmail account through the Reply-To and Return-Path headers. The pitch also dangled a WhatsApp number and a fabricated National Credit Regulator registration number to manufacture an air of legitimacy. There was no link to click, no attachment to open, and no credential form to fill in. The entire attack was engineered to move the target off email and onto informal, unlogged channels where a scammer can work a victim through fee after fee.
That absurd loan range, from a few thousand rand to fifty million, is the fraud's own signature. Legitimate lenders do not advertise a spread that wide, because it is not an offer, it is a net. This is financial theft by social engineering, tracked in MITRE ATT&CK as T1657, Financial Theft. Business-email-style fraud remains the most expensive category of social engineering in the wild; the 2023 FBI IC3 Internet Crime Report attributes roughly $2.9 billion in losses to business email compromise, and the DBIR pegs the median business-email fraud transaction near $50,000.
Why authentication had nothing to work with
Step back and the problem becomes obvious. Every layer a traditional gateway leans on came up empty. Authentication passed, because the account was real. There was no payload to detonate, because the attack carried none. There was no malicious URL to scan or sandbox, because the call to action was a phone number and a Gmail address. DMARC did exactly what the standard, RFC 7489, asks of it, and that was never going to help, because DMARC validates domain ownership, not intent. A legacy secure email gateway checking envelopes and reputation would wave this through, and in most environments it would.
The signals that mattered were all in the substance of the message. This is where behavioral analysis earns its place. IRONSCALES Adaptive AI flagged the message at 62% confidence as an advance-fee scam aimed at a high-value recipient, reasoning entirely from content and context rather than from the clean authentication headers. The implausibly wide loan range, the unverifiable registration number, and the deliberate push to reply through an unrelated Gmail address and WhatsApp all read as fraud to a model that understands what normal correspondence looks like for this organization, even when every SPF, DKIM, and DMARC box is ticked.
What security teams should take from this
The lesson is not that authentication is broken. SPF, DKIM, and DMARC did their jobs precisely. The lesson is that they answer a narrow question, "did this mail really come from the domain it claims," and they answer nothing about whether the sender should be trusted today. A trusted academic partner, a long-standing vendor, or any account with a good reputation can be turned against you the moment its credentials are stolen.
Defense has to assume the sender can be genuine and hostile at the same time. That means watching for account takeover patterns on inbound mail, scoring content and sender behavior against a baseline of normal activity, and treating any nudge toward off-channel payment or personal-detail exchange as a hard signal regardless of how clean the headers look. The same discipline blunts the broader family of business email compromise attacks, where the fraud rides on trust rather than malware.
A loan offer from a law faculty should feel wrong. The technology that stopped this one agreed, and it did so without a single authentication failure to lean on.
See you next time
Attack of the Day is our daily teardown of the real phishing our SOC intercepts. The details are anonymized, the tradecraft is not. Come back tomorrow for the next one.
Indicators of Compromise
| Indicator | Type | Notes |
|---|---|---|
diphasweng[.]co[.]za | Domain | Promoted lending-brand domain; registered roughly two years earlier, WHOIS privacy-redacted with an anomalous Nigeria registrant country; DMARC set to no enforcement |
diphaswengsaptyltd[@]gmail[.]com | Email (Reply-To / Return-Path) | Off-domain reply channel used to divert the conversation to a consumer mailbox |
+27 65 745 1100 | Phone (WhatsApp) | Off-channel contact for continuing the scam outside email |
| Abused academic law-faculty mailbox | Sender | Compromised, fully authenticated legitimate account (innocent ATO victim, genericized); DKIM-signed and DMARC-aligned to its own domain |
| Fabricated NCR registration number | Lure artifact | Fake National Credit Regulator number used to fake legitimacy |
| Loan range R20,000 to R50,000,000 | Content signal | Implausibly wide range characteristic of advance-fee fraud |
MITRE ATT&CK Mapping
| Technique | ID | Use in this attack |
|---|---|---|
| Compromise Accounts: Email Accounts | T1586.002 | Attacker operated from a genuinely compromised university law-faculty mailbox, inheriting its clean authentication |
| Financial Theft | T1657 | Advance-fee loan pitch designed to extract fees and personal or banking details before any loan is disbursed |
Related attacks
| Attack | What happened |
|---|---|
| Spanish-Language Judicial Impersonation Exploits CDR Relay Trust to Deliver Advance-Fee Fraud | A Spanish-language judicial impersonation email delivered three identity document PDFs and a bank account number. |
| The Webinar Invite That Came With an Apple Wallet Pass and a Three-Hop Redirect Chain | A Google Calendar invite for a fake AI webinar passed full authentication and carried an .ics file, an Apple Wallet .pkpass. |
| The Bank Statement You Had to Unlock With Your Birthday: PII-Gated PDF Evasion From Authenticated Infrastructure | A fully authenticated email from banking infrastructure delivered a password-protected PDF that required the recipient's mobile number and date of birth... |
| The Spreadsheet That Arrived Twice: CR/LF Filename Obfuscation and a Base64 Shadow Payload | A clinical data report arrived as a .xlsx with CR/LF control characters in the filename and a companion .b64 base64 payload. |
| The Payload Was a Phone Number: How a Google Calendar Invite Weaponized Vishing | A Google Calendar invite with a fake $399.77 charge and a toll-free callback number. |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.