TL;DR A VP of IT at a manufacturing company received a fake Amazon-style order receipt from a first-time Hotmail sender that passed SPF, DKIM, and DMARC. The subject line used Cyrillic homoglyphs to dodge keyword filters, and the entire lure lived inside a clean PNG image showing a $748.32 charge and a support number to call. This is a TOAD attack: no links, no malware, nothing for a scanner to flag. The only reliable signals were behavioral and visual, exactly what text- and link-centric filters cannot see.
Severity: High Callback Phishing Image-Based Phishing Impersonation MITRE: T1566.001 MITRE: T1036 MITRE: T1598.003

The subject line read "Infоrmation аbout your fееd (Update #661748)," and to a human eye it was ordinary English. To a text filter it was gibberish, because three of those vowels were not Latin letters at all. The attacker had swapped in Cyrillic homoglyphs, characters that render identically to o, a, and e but carry different Unicode code points. That single trick let a fake order-receipt scam sail past keyword matching and into the inbox of a VP of IT at an industrial manufacturing company.

What arrived was not a link. It was not malware. It was a picture of a receipt and a phone number, which is exactly why it worked.

A first-time Hotmail sender that passed every auth check

The message came from a free Hotmail account, dedir[.]disezu[@]hotmail[.]com, using the display name "John Sobirov." It was the first time this sender had ever emailed the organization. And it passed SPF, DKIM, and DMARC cleanly.

That combination trips people up, so it is worth being blunt about it. The email authenticated because it genuinely originated from a real Hotmail mailbox and traversed Microsoft outbound infrastructure the way any legitimate Hotmail message does. Authentication proves delivery hygiene. It does not prove trust. As the National Institute of Standards and Technology defines it, phishing succeeds by impersonation and deception, not by breaking cryptographic controls, and none of SPF, DKIM, or DMARC was designed to judge whether a sender's intent is honest.

Microsoft's own tenant even flagged the anomaly. The body was nearly empty apart from the "you don't often get email from this sender" banner that Outlook prepends to unfamiliar correspondents. That banner was the loudest technical signal in the entire message, and it is a behavioral one.

The payload was a receipt you could not scan

Everything the attacker wanted the victim to see was baked into a single PNG attachment. The image impersonated an Amazon-style order confirmation: a fabricated order number, a "Payment Successfully Processed" header, a total of $748.32, and, in a detail that sells the whole thing, the recipient's real corporate email address printed as the "Customer Email."

The file was a technically clean PNG. No embedded executable, no macro, no steganographic payload hiding in the pixels. A malware sandbox has nothing to detonate. A link scanner has no URL to follow. The receipt's instruction was the entire attack: call a support number immediately to stop the shipment before you are charged.

That number, 805-397-9600, is the hook. This is a TOAD attack, short for Telephone-Oriented Attack Delivery, and its defining move is to drag the victim off email and onto a phone call. Once the target dials, the scanning perimeter is behind them, and the exchange becomes a vishing call, the voice-phishing endgame. A human operator handles the rest, walking the caller toward a refund reversal, a remote-access session, or a "verification" payment. The 2024 Verizon Data Breach Investigations Report puts the human element in 68 percent of breaches, and callback schemes are engineered to exploit precisely that surface after every automated control has been satisfied.

Manufacturing organizations are a rational target for this play. Procurement, accounts payable, and IT leadership all deal in unexpected order and invoice traffic, so a surprise "you were charged" receipt lands as plausible rather than absurd. That is one reason we build manufacturing-specific email defense around behavioral context rather than signature lists.

How Themis read the message differently

Our Adaptive AI, Themis, does not start from "did this authenticate." It starts from "does this belong here." A first-time external sender on free webmail, targeting a specific senior executive, carrying an image-only body and the native unfamiliar-sender banner, is a cluster of anomalies no single one of which is damning but which together describe a targeted social-engineering attempt. Layer in visual and optical-character-recognition inspection of the attachment, which surfaces the fake receipt text and the embedded phone number that a text filter never sees, and the verdict is clear well before anyone reaches for the phone.

This is the gap that makes image-and-phone attacks so effective against traditional tooling. A secure email gateway, or SEG, indexes text, reputation, links, and file hashes. Hand it a clean image and a subject line written in the wrong alphabet and you have removed almost everything it grades on. IRONSCALES platform data shows SEGs miss an average of 67.5 phishing emails per 100 mailboxes each month, and content-free callback lures like this one live squarely in that miss rate.

See Your Risk: Calculate how many threats your SEG is missing

Indicators of Compromise

The MD5 is the durable match here. The filename follows an auto-generated scanner naming pattern (Scan__), so treat the Scan_ prefix, the _b661 suffix, and above all the hash as the reliable indicators rather than the exact timestamp.

TypeIndicatorContext
Emaildedir[.]disezu[@]hotmail[.]comFirst-time free Hotmail sender, display name "John Sobirov"
Phone805-397-9600Callback number embedded in the receipt image
FileScan__Fake Amazon-style order receipt, clean PNG, image-only payload
Hashbf5771d49a56feff568139181d4631da (MD5)Attachment hash
SubjectInfоrmation аbout your fееd (Update #661748)Cyrillic homoglyphs substituted for Latin o, a, e

This maps to three MITRE ATT&CK techniques: T1566.001 Spearphishing Attachment for the weaponized receipt image, T1036 Masquerading for the homoglyph subject that disguises the message, and T1598.003 Spearphishing via Service for the callback vector that solicits action over the phone.

Grade senders, not just signatures

The lesson is not "block Hotmail" or "flag every image." It is that authentication and content scanning answer questions this attack was built to avoid. When the subject line hides in another alphabet and the payload is a picture pointing at a phone number, the only signals left are behavioral and visual: is this sender new, is the target a VIP, did the platform itself warn that the correspondent is unfamiliar, and what does the attachment actually say when you read the pixels. The Microsoft Digital Defense Report 2024 and CISA's guidance on stopping the phishing attack cycle both push defenders toward exactly this shift, from perimeter reputation to behavioral judgment. Trust the anomaly cluster, and coach your VIPs that a receipt telling them to call a number is a prompt to slow down, not to dial. Across 35,000+ security professionals at 17,000+ organizations, the attacks that get through are rarely the ones with something obvious to scan.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
The Phishing Link Lived on a Domain That Didn't Exist Nine Hours EarlierA compromised university student account sent a phishing email that passed SPF, DKIM, and DMARC.
The Health Spending Account Alert That Rode a Benefits Administrator's Own InfrastructureAn Anthem-branded spending account notification routed through a legitimate benefits administrator's redirect infrastructure.
The GitLab Alert That Passed Every Filter (Except One Detail Nobody Checked)A GitLab sign-in alert cleared Proofpoint URL Defense and passed SPF/DMARC, then listed a private RFC1918 IP as the sign-in source.
The U.S. Bank Email That Came From a Lawyer Directory and Passed Every Authentication CheckA fully authenticated email from lawyerlegion[.]com displayed pixel-perfect U.S.
The Zelle Confirmation That Couldn't Spell Its Own Name: Template Artifacts, Placeholder Leaks, and a TOAD CallbackA Zelle payment confirmation from a Gmail address passed SendGrid authentication but failed DMARC for gmail.com.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.