TL;DR An agricultural commodity processor received what looked like a routine Datadog scheduled dashboard report. It was routine. The email came from Datadog's own branded sending domain, the attached PDF was auto-generated by Datadog's reporting pipeline, and all three links resolved to genuine Datadog dashboard and login pages that scanned clean. The attacker never touched Datadog's systems. They typed a fabricated Microsoft billing charge and a callback number into the report's customizable description field, so a trusted vendor delivered a vishing lure on their behalf. The payload was a phone number.
Severity: High Vishing Brand Impersonation Invoice Fraud MITRE: T1566.004 MITRE: T1598 MITRE: T1656

The email came from Datadog HQ. Not something dressed up as Datadog, not a lookalike domain with a swapped character. The sender was no-reply@dtdg[.]co, Datadog's own branded short domain for scheduled-report delivery and click tracking. The subject line read [Dashboard Report] Confirm Your Details for 9X5Y, with a day and time stamp appended the way Datadog's automated reports always append one. Attached was a 71 KB PDF, generated by a headless browser inside Datadog's own reporting pipeline. Three links sat in the body, and every one of them resolved to us3[.]datadoghq[.]com. All three scanned clean, because all three were genuinely Datadog.

One mailbox at an agricultural commodity processing and distribution company received it. The only thing in the message capable of causing harm was a line of text sitting where a report description belongs:

Report description: Defender 365 1-Year : Amount 375 USD. Receipt # 9X5Y . Didn't order? Phone +1 (856) 246-0137.

That phone number was the attack. Everything else was scaffolding, and Datadog built the scaffolding for free.

The feature was the vector

Datadog's scheduled reports are a mundane, useful thing. You point them at a dashboard, set a cadence, add a short description so recipients know what they are looking at, and the platform emails a rendered PDF snapshot on schedule. That description is a free-text field. Whoever configures the report decides what goes in it, and the platform faithfully reproduces it in the notification body and in the generated PDF.

So the attacker did not need to compromise anything. They configured a scheduled report, named it Confirm Your Details for 9X5Y, and typed a fabricated Microsoft billing charge plus a callback number into the description. From that moment on, delivery was handled by a vendor with an excellent reputation. Datadog rendered the PDF, titled it after the report, signed the mail, and relayed it through production sending infrastructure. The message the recipient opened was, technically speaking, an authentic Datadog notification. Its contents were a lie.

Separate that clearly from spoofing. There was no forged header, no homoglyph, no compromised third-party mailbox. MITRE ATT&CK catalogs this shape as T1656, impersonation, and the notable variant is when the impersonated brand is not imitated at all but recruited, unwittingly, as the courier.

Every verdict came back clean, correctly

The links in the body pointed at a Datadog dashboard behind us3[.]datadoghq[.]com/account/login, carrying the platform's normal scheduled-report tracking parameters. URL reputation engines rated all of it safe, and they were right to. There was no attacker-controlled landing page anywhere in this attack, because there was no credential harvest. Nothing needed to be hosted.

The attachment tells the same story. A 71,100-byte PDF, produced by Datadog's own rendering process, with document metadata describing itself as a Datadog invoice for a short alphanumeric reference, and clickable URI objects that also resolve to the real dashboard. Sandbox it and it behaves like what it is: a static page snapshot with benign links. The malicious content is prose, and prose does not detonate.

The authentication trail deserves to be read honestly rather than flattened. SPF passed, for 149[.]72[.]169[.]25 with an envelope sender of em6080[.]dtdg[.]co, the SendGrid infrastructure Datadog legitimately sends from. DMARC passed against a From domain of dtdg[.]co, with a policy action of none. Microsoft's composite authentication landed on compauth=pass reason=100, the strongest result it issues. DKIM, however, split across hops: the company's on-premises gateway recorded a pass for the signing domain, while the final hop at Microsoft reported that the body hash did not verify.

That divergence is not evidence of forgery. It is the fingerprint of a multi-hop path, from SendGrid to an on-premises appliance to internal mail hosts and finally into Microsoft 365, where an intermediate device modified the message after Datadog signed it. Both readings of the trail lead you astray. Read the pass and you clear a fraud. Read the DKIM failure as spoofing and you misdiagnose the case, because DMARC alignment was never the thing under attack. Nothing in RFC 7489 claims that the text inside an authenticated message is true.

See Your Risk: Calculate how many threats your SEG is missing

The lure was cheap on purpose

Look closely at the fake charge and the tradecraft is unpolished. "Defender 365" is not a Microsoft product name. The amount, 375 USD for a one-year term, is small enough to be plausible as a renewal nobody remembers approving. The receipt reference reuses the same token as the report title, so the subject line and the "receipt" corroborate one another without the attacker fabricating two things.

Then comes the hook, and the hook is the only sophisticated part: "Didn't order? Phone." It inverts the usual urgency. No deadline, no threat, no request. It offers help with a problem it just invented, and the natural response for a busy executive who never bought a Defender 365 license is to call and get it cancelled. That is a vishing setup, and once the target dials, the inbox controls are all behind them. On the call the attacker runs the script: a refund flow that requires remote-access software, a card number to process a reversal, banking details to route a credit. The 2023 FBI IC3 Internet Crime Report put business email compromise losses near $2.9 billion, and voice-assisted variants sit under T1566/004, phishing via voice and T1598, phishing for information. Neither leaves a file or a URL for a scanner to seize.

What actually flagged it

With no bad link, no bad attachment, and a clean composite authentication result, detection had to come from somewhere other than verdicts. It did. The sender was a first-time sender to the organization, with no prior mail relationship, arriving with a financial claim aimed at a high-value recipient. The content pattern matched a callback scam that the wider community had already resolved as phishing in similar incidents. IRONSCALES Adaptive AI weighed that combination and Themis surfaced it at 86% confidence, tagging it both as a vishing attack and as a message targeting a VIP recipient. Automated threat detection reported it, and the incident closed as phishing without a human ever needing to adjudicate it.

The 2024 Verizon Data Breach Investigations Report puts pretexting, the social-engineering family that covers business email compromise and invoice fraud, at the top of the social-engineering breach types, with a median transaction around fifty thousand dollars. CISA's phishing guidance makes the same point from the defender's side: the cycle has to be interrupted before the human decision, not after the file scan.

The takeaway is uncomfortable for anyone whose stack grades messages by artifact. Every artifact here was authentic. Real vendor, real domain, real links, real PDF, and authentication as strong as Microsoft's scoring gets. The fraud lived in a text box the platform invited a customer to fill in. When a vendor you trust will deliver arbitrary text on someone else's behalf, the only question left is whether the message behaves like the thing it claims to be.

Indicators of Compromise

TypeIndicatorContext
Senderno-reply@dtdg[.]coGenuine Datadog transactional sending address, not spoofed, carrying the injected lure
Envelope senderem6080[.]dtdg[.]coLegitimate Datadog SendGrid envelope domain, SPF pass
IP149[.]72[.]169[.]25SendGrid relay used by Datadog scheduled-report infrastructure
Relay hosto3[.]ptr4288[.]o3[.]sendgrid[.]dtdg[.]coFirst hop, Datadog's SendGrid sending host
Subject[Dashboard Report] Confirm Your Details for 9X5YDatadog scheduled-report subject format, report title chosen by the attacker
Attachmentconfirm-your-details-for-9x5y_[date].pdf71,100-byte PDF auto-generated by Datadog's reporting pipeline, date stamp masked
Hashc7d19fd1d7fb29185a23283a49bcda44MD5 of the attached PDF
URLhxxps://us3[.]datadoghq[.]com/account/loginGenuine Datadog login and dashboard link, clean, used for credibility
Phone+1 (856) 246-0137Callback number, the sole payload
Fake charge375 USD, "Defender 365 1-Year", receipt reference 9X5YFabricated billing line typed into the report description field
AuthenticationSPF pass, DMARC pass (action=none), compauth=pass reason=100, DKIM split across hops (gateway pass, body hash failure at Microsoft)Mixed DKIM signal explained by a multi-hop gateway path, not spoofing

MITRE ATT&CK Mapping

  • T1566/004, Phishing: Spearphishing Voice. The callback number was the entire payload and the intended point of contact.
  • T1598, Phishing for Information. The call script exists to extract payment and account details.
  • T1656, Impersonation. A fabricated Microsoft billing charge delivered by a genuine, uncompromised vendor platform.

See You Next Time

When a trusted platform lets a customer type anything into a field it will email on their behalf, that field is part of your attack surface. Read the behavior, not the sender.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 36,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
Real Intuit Invoice, Fake Geek Squad Bill, One Phone NumberA past-due Geek Squad invoice arrived through real Intuit QuickBooks infrastructure.
Amazon Said You Owe $879. The Phone Number Was the Payload.DKIM and DMARC passed for amazon.de.
Encrypted PDF Invoice Drops Through SPF, DKIM, and DMARC on a 6-Day-Old DomainA phishing attack weaponized an encrypted PDF with hidden AcroForm fields, sent from a 6-day-old Reuters lookalike domain that passed SPF, DKIM, and DMARC.
A Real Zoom Alert, Resent by the Attacker Who Asked for ItZoom really sent this sign-in alert.
The One PayPal Link That Dropped to Plain HTTPA genuine PayPal invoice, forwarded through mangled relay headers to five unrelated companies at once, passed every authentication check.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.