Table of Contents
The email that reached a resident-services staff member at a residential property management company in mid-August 2026 held a conversation that had actually happened. Underneath the notice at the top sat two dated messages from an internal support thread at a resident-services software vendor, sent the previous day between staff in onboarding operations and customer success, addressed to the vendor's own shared mailboxes. Real signature blocks with real titles, a working meeting-booking link, working links to the vendor's product hub and live social accounts. None of it was reconstructed: it had been lifted whole out of the mailbox the attacker was sitting inside.
Bolted on top of that correspondence was a voicemail playback notice, and it was the only new thing in the message. Its two buttons pointed somewhere the rest of the email did not go. Every cue a recipient reaches for when judging a message, who the sender is, whether they have written before, whether the surrounding content reads as authentically internal, whether links resolve where they claim, held up, because all of it was real.
The Sender Was Exactly Who It Claimed to Be
The authentication record explains why nothing looked wrong. SPF returned a pass. The DKIM signature verified under the vendor's own domain. DMARC passed against that domain's published policy of quarantine at full coverage, not permissive monitoring. Both ARC seals validated across the hops the message travelled, and composite authentication passed. The mail left the vendor's own Microsoft 365 tenant, on a domain registered since 2018, from a mailbox belonging to a real employee doing a real job. The only thing that had changed was who was typing.
One header detail is worth pausing over. The From and To headers named the same mailbox, the shape of a blind-copied blast pushed out of a mailbox somebody else is operating rather than a message composed for one person.
DMARC resolves one narrow question, whether the domain owner authorized this message and whether the signed content survived transit, and whoever holds the keys to a mailbox answers it honestly in the owner's name, accumulated reputation included. Nothing here failed, which is why the NIST definition of phishing still fits: it turns on the deception and the objective, not a broken check.
Reuse Beats Fabrication
This is what separates the case from ordinary thread bait. There was no fabricated reply prefix and no invented history. Thread bait asks a recipient to accept a plausible past; this message handed her a real one, including routine internal chatter between two vendor employees that nobody outside that mailbox could have written. The reuse costs nothing to maintain either, because the wrapper is finished, self-consistent and already in the sender's own voice.
A Playback Notice With Nothing to Play
That new block was styled as an alert from a call-management platform: a message duration, a high-priority tag, and a transcription preview that read that the full transcription was unavailable.
The empty preview is the design, not a defect. A transcription that renders answers the question for free; one that fails makes the button the only route to the answer, while looking like a routine platform glitch rather than a lure. Two calls to action sat under it, one offering to play the message and one offering to read the full transcription. Both resolved to the same destination.
See Your Risk: Calculate how many threats your SEG is missing
Two Poisoned Links Among Dozens of Clean Ones
Both buttons were wrapped in Microsoft's link-rewriting service, and the pre-rewrite target survived inside the wrapper's own original-source parameter, which is where the real destination was read, not inferred from a rendered preview. Both decoded to a single path on a domain registered in late 2020 through a Japanese hosting registrar and privacy-shielded behind that registrar. Nothing about the domain relates to voicemail, telephony, or the vendor. The path is a run-together string of voicemail, caller-identification and messaging fragments, the kind of directory name a kit ships with and nobody renames.
The registration is nearly six years old, so age heuristics will not flag it. The most plausible reading is a pre-existing site carrying an attacker-injected path rather than infrastructure stood up for this campaign, and who controls the underlying site is not established. No screenshot was captured for that destination and its verdict was recorded as clean, so what it served is not established either.
Those two links sat among dozens of genuine ones, so hovering to audit the message would have returned real destination after real destination before reaching either button.
The Automation Had Nothing to Grade
The platform's automated content insight did report a malicious link in this message, and it named that link by its display text, which read as the vendor's own domain. That link was the vendor's own marketing-automation tracking redirect, a shared platform thousands of legitimate senders route campaign links through, and its recorded verdict was a mixed result rather than malicious. The two buttons carrying the actual destination were recorded as clean. No confidence score was attached to the message.
The automated verdicts pointed at a benign tracker while the payload passed unremarked. What substantiated the incident was the person it was aimed at: she reported it herself, the report was approved manually, and the affected mailbox was quarantined roughly three days after the send. That is the human element doing the work the link verdicts could not.
A Known Sender Is a Harder Problem Than a New One
First-time-sender analysis is among the strongest behavioural signals in email security, and this sender was not new. The record shows prior legitimate correspondence between that mailbox and this organization, exactly the history the signal is supposed to reward.
Vendor email compromise inverts that reward. A supplier relationship becomes a delivery channel no header control can revoke, because revoking it means distrusting a domain behaving correctly at the protocol level. The vendor here is a victim, its brand and its customer relationships turned into the attack surface, which is why its name, its domain and the mailbox local part are all genericized here. Naming it as the attacker would be wrong twice over.
Two Things Worth Changing
The 2026 Verizon Data Breach Investigations Report puts the human element in 62% of breaches, phishing as the initial access vector in 16%, and credentials in 39% across the full kill chain. The 2025 FBI IC3 report records $3.05 billion in business email compromise losses in a single year. Neither figure moves while an attacker can borrow a mailbox that already has standing, because a borrowed mailbox answers every identity question correctly.
First, score content independently of the sender, which is the separation CISA's phishing guidance draws between validating a sender and handling a payload. Adaptive AI has signals here that authentication never touches: a notification block whose preview is empty by design, a stated purpose with no relationship to where its buttons resolve, and two destinations leaving an otherwise internal set of links.
Second, treat a clean verdict on one link as the narrow statement it is. A scanner reporting nothing on a destination it could not characterize is not a safe destination, and a flag naming one link says nothing about the other dozens. The fastest path to the truth here was a staff member who thought a familiar vendor's voicemail notice looked slightly wrong and said so, which argues for making reporting trivially easy and treating each report as a lead, not a ticket.
Indicators of Compromise
| Type | Indicator | Context |
|---|---|---|
| Domain | reikongaku[.]com | Landing domain for both calls to action. Created late 2020 through a Japanese hosting registrar and privacy-shielded behind that registrar, so not a fresh registration. The injected path is attacker controlled; ownership of the underlying site is not established by the record. |
| URL | hxxps://reikongaku[.]com/voicewavcalerIDsms/ | Final destination of both the play and the transcription buttons, reached through a Microsoft link-rewriting wrapper. Recorded scanner verdict was clean and no screenshot was captured, so the served content is unknown. |
| URL parameter | originalsrc inside the link-rewriting wrapper | Where the pre-rewrite destination was recovered. The rewritten href alone shows only the rewriting service's own hostname. |
vendor-mailbox@resident-services-vendor[.]example (genericized) | Bystander sender. A real employee mailbox at a real software vendor, operated by someone other than its owner. Domain and local part both genericized. | |
| Domain | resident-services-vendor[.]example (genericized) | Bystander sending domain, registered 2018, publishing DMARC quarantine at full coverage. Authenticated legitimately through its own Microsoft 365 tenant. No attacker linkage to the domain. |
| Header pattern | From and To naming the same mailbox | Self-addressed send, consistent with a blind-copied blast from a mailbox under third-party control rather than a targeted one-to-one message. |
| Lure structure | Voicemail playback block with an unavailable transcription preview | Fake call-management alert carrying a duration and a high-priority tag. The failed transcription preview makes the button the only route to the content. |
| Body content | Reused internal vendor support thread, dated the previous day | Genuine correspondence between vendor onboarding and customer-success staff, with real signatures, a working meeting-booking link and working product and social links, reused verbatim as a trust wrapper. |
| Auth result | SPF pass, DKIM pass (verified), DMARC pass, ARC pass on both seals, composite authentication pass | Every check cleared under the vendor's own domain. Header spoofing was not part of this attack. |
| Detection artifact | Automated insight naming a link by display text | The named link was the vendor's own marketing-automation tracking redirect on a shared platform, recorded as a mixed result. The two payload buttons were recorded clean. No confidence score was attached. |
| Response | Recipient report, manual approval, mailbox quarantined | The targeted staff member reported the message. Remediation landed roughly three days after the send. |
MITRE ATT&CK Mapping
| Technique | ID | How it appeared |
|---|---|---|
| Phishing: Spearphishing Link | T1566.002 | Two calls to action inside a fake voicemail block, both resolving through a link-rewriting wrapper to one path on an unrelated domain, delivered inside genuine reused correspondence. |
| Valid Accounts: Cloud Accounts | T1078.004 | The message was sent from a real vendor mailbox through the vendor's own cloud tenant, which is why every authentication check passed and why prior-correspondence history counted in the attacker's favour. |
Related attacks
| Attack | What happened |
|---|---|
| Perfect Authentication, Borrowed From a Real Mailbox | An EFT payment lure passed SPF, DKIM and DMARC cleanly, carried a genuine corporate legal disclaimer, and came from a real utility employee's mailbox. |
| The SPF Failure That Vanished Before Delivery | A partner's compromised mailbox sent an approval request that genuinely failed SPF at one hop in the middle of the chain. |
| A Hijacked University Mailbox Plays Process Server | An all-caps French legal summons with a 72-hour deadline landed from a real university mailbox. |
| The Email Addressed to Its Own Sender | A two line document-review pretext passed SPF, DKIM and ARC because it really did leave a medical practice's own Microsoft 365 mailbox. |
| When a Government Ministry's Mailbox Sends a Benefit Scam | A hijacked foreign government ministry mailbox passed SPF, DMARC, and compauth cleanly while pushing an unrelated country's benefit-program scam. |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.