TL;DR Two mailboxes at a multi-site services organization received a payment summary notice in mid-July 2026 that passed SPF, DKIM and DMARC cleanly, with the ARC chain intact end to end. The authentication was genuine because the sending mailbox was genuine, a real employee account at a real utility company that had stopped being under its owner's control. The one hyperlink read like an attached document and pointed at an unrelated domain registered a hundred days earlier. That page answered with a human-verification gate, so automated scanners never saw what it served.
Severity: High Account-Takeover Credential-Harvesting Trusted-Infrastructure-Abuse MITRE: T1566.002 MITRE: T1204.001

A message titled EFT payment summary reached two mailboxes at a multi-site services organization in mid-July 2026. SPF passed. DKIM passed with the signature verified. DMARC passed with the header From aligned. The ARC chain sealed clean on the final hop, so the receiving provider could confirm the authentication had survived transit intact rather than merely looking plausible on arrival. The footer carried a genuine corporate legal disclaimer and whistleblower-policy notice, the kind of boilerplate that only ships from a real company's mail template.

None of that was forged. The message came from a real employee mailbox at a real, operating utility company, sent through that company's own Microsoft 365 tenant and relayed by Microsoft's outbound protection service to the recipients' Google-hosted mail. The authentication was genuine because the sender was genuine. The account had simply stopped being under its owner's control.

Authentication Confirmed a Real Sender, Not a Safe One

The header record is unambiguous. Received-SPF returned a pass for the sending domain. DKIM passed under that same domain with the signature verified, not just present. DMARC passed with an action of none and the From header aligned to the signing domain. On receipt the ARC seal validated as pass, confirming the chain of results had not been rewritten between hops.

One wrinkle is worth stating precisely, because misread it looks like a failure. An internal stamp inserted by the sending platform before the message left its own network reads dkim=none and dmarc=none. That is an outbound pre-departure stamp, superseded by the downstream results the receiving provider actually evaluated, which returned pass for both.

Account takeover does not bypass that layer. It inherits it. DMARC answers one narrow question, whether the domain owner authorized this message and whether the signed content survived transit, and whoever holds the mailbox answers it truthfully in the owner's name. The domain's accumulated sending reputation transfers along with the answer. So nothing here needed forging, and the NIST definition of phishing still fits, because it turns on the deception and the objective, both of which an attacker can supply while satisfying every identity control.

The Attached Document That Did Not Exist

The body was thin: a generic salutation addressed to no one in particular, a claim that a payment summary was attached, an instruction to allow 24 to 48 hours for processing, and one hyperlink.

That hyperlink is where the message stops holding together. Its display text read REVIEW ATTACHED DOCUMENT HERE, which describes a file, not a website, while the underlying destination was a URL on a third-party domain with no relationship to the sending company or the recipient organization. That mismatch was read directly out of the raw message body, not inferred from a rendered preview.

There was also no attachment. Attachment analysis on the case returned nothing to analyze, because nothing was ever attached. The lure described a document that had never existed in any form. The link path was spelled hmtl, a transposition of html, the sort of detail that survives in a kit because nobody proofreads a path that still resolves.

The platform's link scanner marked both instances of that URL, the plain form and the trailing-slash variant, malicious independently of any analyst narrative. The message was auto-resolved as phishing, with two mailboxes affected.

What the Destination Actually Showed

A fresh screenshot of the link destination shows one static white card. It reads that one more step is needed before proceeding, prompts the visitor to verify they are human, and carries the branding of a widely used content delivery network. There is no username field. There is no password field. There is no login form of any kind. What sits behind that gate, whether a credential page, another redirect or something else, is not established by anything in this record.

The gate is the finding. A human-verification interstitial answers automated visitors with a challenge instead of content, so a URL scanner, a sandbox or a crawler following that link retrieves the interstitial and stops. Reputation and content scoring then have almost nothing to grade, while a person who clicks through clears the challenge without a second thought and reads it as a mark of legitimacy. The same gate that reassures the target blinds the tooling.

The credential-theft characterization belongs to the platform's own content model, which scored the message credential theft at 90 percent confidence. That is an inference drawn from the whole message, worth separating from the observation, which is the bot-check card. Adaptive AI reached that score from signals the clean headers never touched: a first-time external sender with no prior correspondence with this organization, lure text promising a document that was not there, and a link whose display text and destination disagreed.

See Your Risk: Calculate how many threats your SEG is missing

A Hundred Days of Patience

A fresh WHOIS pull on the landing domain puts its creation in early April 2026, exactly 100 days before the message was sent. The registration lists a registrant country of Egypt and a registrant contact on a free consumer webmail service rather than any corporate address, with nameservers on a mainstream content delivery network. A registration update roughly 40 days before the send is consistent with configuration work ahead of a campaign, though the record does not confirm that.

A hundred days looks like a deliberate choice. Newly registered domain heuristics are calibrated for hours and days, so a domain that has sat quietly for over three months clears an age threshold while still being purpose-built. Combined with the gate, scanners cannot grade it and age rules will not stop it.

The Sending Company Was a Victim Too

The domain that sent this message belongs to a genuine, operating utility business. Its mail authenticated under its own name because it really was its own infrastructure, and it carried the company's authentic corporate disclaimer footer, which an outsider does not reconstruct. The most plausible reading of the record is a takeover of one employee mailbox, not a domain in attacker hands.

That distinction matters operationally. Account takeover turns a supplier or partner into a delivery channel no header control can revoke, because revoking it means distrusting a legitimate domain. Every downstream recipient inherits the compromise as trusted mail.

What This Should Change

The 2026 Verizon Data Breach Investigations Report puts the human element in 62% of breaches, phishing as the initial access vector in 16%, and credentials in 39% of breaches across the full kill chain. The 2025 FBI IC3 report records $3.05 billion in business email compromise losses in a single year. Compromised legitimate mailboxes keep both figures durable, because they defeat the sender-identity layer by satisfying it.

Two things follow. First, score content independently of identity. A message that passes every authentication check still needs its links resolved, its display text compared against its destinations, and its claims checked against what is actually present, which is the separation CISA's phishing guidance draws between sender validation and payload handling. A promised attachment that does not exist is a contradiction available at inspection time.

Second, treat an unresolvable destination as a signal rather than an absence of one. A verification gate a scanner cannot pass is not a clean result. Credential harvesting defenses have to weigh a page that refused to answer automation alongside domain age, sender history and the internal consistency of the message, because that refusal is deliberate and aimed squarely at the tooling.

Indicators of Compromise

TypeIndicatorContext
Domainengastando[.]usAttacker-owned landing domain, created early April 2026, exactly 100 days before the send. Registrant country Egypt, registrant contact a free consumer webmail address (withheld), nameservers on a mainstream content delivery network.
URLhxxps://engastando[.]us/hmtlMalicious link destination. Display text read REVIEW ATTACHED DOCUMENT HERE while the href pointed at this unrelated domain. Note the transposed path spelling.
URLhxxps://engastando[.]us/hmtl/Second instance of the same destination, trailing-slash variant. Independently scored malicious.
Landing behaviorHuman-verification interstitialFresh screenshot shows a static card prompting the visitor to verify they are human, with content delivery network branding. No login or credential field visible. Whatever sits behind the gate is not established by the record.
Emailemployee-mailbox@utility-domain[.]example (genericized)Bystander sender mailbox. A real employee account at a real utility company, almost certainly taken over. Domain and local part both genericized.
Domainutility-domain[.]example (genericized)Bystander sending domain. Passed SPF, DKIM and DMARC legitimately under its own tenant. No attacker linkage to the domain itself.
SubjectEFT payment summaryPayment-summary lure with a 24 to 48 hour processing window and no attachment present anywhere in the message.
Auth resultSPF pass, DKIM pass (verified), DMARC pass (action none), ARC passEvery downstream check cleared. Header spoofing was not part of this attack.
Detection signalAdaptive AI confidence 90, label credential theftInferred from message content plus first-time-sender history and the display-text mismatch, not from any authentication failure.

MITRE ATT&CK Mapping

TechniqueIDHow it appeared
Phishing: Spearphishing LinkT1566.002A single hyperlink to an unrelated attacker-registered domain, delivered from a fully authenticated real mailbox with display text impersonating an attachment.
User Execution: Malicious LinkT1204.001Execution depended on the recipient following the link and then clearing a human-verification gate, a step automated analysis could not complete.
Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
When a Government Ministry's Mailbox Sends a Benefit ScamA hijacked foreign government ministry mailbox passed SPF, DMARC, and compauth cleanly while pushing an unrelated country's benefit-program scam.
A Perfect DMARC Pass from a Stolen K-12 MailboxA K-12 district administrator's mailbox sent a document-share lure to an ed-tech vendor.
When a University's Own Domain Blasts a Job ScamA vocational school's own Microsoft 365 tenant sent a Federal Work-Study job scam to hundreds of inboxes.
The Auth0 Developer Tenant That Passed Every Security Check (Because It Was Real)An attacker weaponized Auth0's free developer tenant to build a phishing chain that passed DKIM, DMARC, and every link scanner.
The Lab Result Notification That Every Security Check Approved (Because the Platform Was Real)A credential harvest targeting healthcare portal logins arrived through bridgeinteract.io, a legitimate HIPAA-adjacent patient engagement platform.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.