TL;DR A recreational-services franchise received a legitimate Demio webinar reminder sent through Mailgun on demio[.]com infrastructure. SPF, DKIM, and DMARC all passed. But a broken mail-merge field rendered a fake payment notice directly in the greeting, claiming $728.99 was processed and listing a callback number for help. A personal Gmail address stood in for the event contact, and the display name collided with a known internal contact. No links, no malware, just a phone number and a clean authentication record doing the attacker's work.
Severity: Medium Toad Callback Phishing Payment Fraud Display Name Impersonation MITRE: T1566 MITRE: T1598 MITRE: T1656

Every control on this email passed. The sending platform was real. The authentication was clean. There were no links to scan and no attachment to detonate. And yet the single most dangerous line in the message was never supposed to be there at all.

A recreational-services franchise received what looked like an ordinary webinar reminder from Demio, a legitimate event-hosting platform. The message was delivered through Mailgun on genuine demio[.]com infrastructure. SPF passed. DKIM passed with a valid signature from d=demio.com. DMARC passed. The spam confidence level came back at 1, effectively a vote of confidence from the receiving mail system. By every automated measure, this was a benign notification about a webinar titled "Norton."

Then a broken mail-merge field did the attacker's job for them.

When the Merge Field Breaks in the Attacker's Favor

Personalized emails are assembled from templates. A merge token like a first-name placeholder gets swapped for real data at send time. When that substitution fails or is deliberately abused, the raw contents of the token render as literal text in the finished email.

In this case, the greeting line and an image alt-text attribute did not resolve to a name. They resolved to a fabricated payment notice. Reconstructed from the raw HTML body, the injected string read as a garbled but unmistakable claim: a payment of $728.99 had been processed, a subscription was ready, and a "Team" was standing by at a phone number for help.

That phone number, +1 (800) 958-7164, is the entire attack. There is no credential-harvesting page to visit and no invoice to open. The message wants the target to pick up a phone and call. This is a telephone-oriented attack delivery, or TOAD. The email is only the lure. The real fraud happens on the call, where a human operator walks the victim through "canceling" a charge that was never made, often by collecting card details, remote-access approval, or a wire.

Two supporting signals raised the risk further. The listed event contact was a personal Gmail address rather than a corporate one, an odd choice for a real business webinar. And the sender display name collided with a known contact elsewhere in the organization's extended family, tripping a similar-display-name impersonation flag. On their own, each is a soft signal. Stacked with a fake payment notice and a callback number, they describe intent.

Anatomy of a Clean Email With a Dirty Payload

What makes this case worth studying is the mismatch between the envelope and the contents. The envelope is pristine. A real employee at a real company set up a real Demio event, and the reminder went out through a real email service provider (ESP) that thousands of businesses trust. Nothing about the transport was spoofed or forged.

The payload is entirely in the visible text. That is a deliberate evasion, whether the attacker corrupted the merge data intentionally or discovered that a malformed token would slip fabricated content past filters. Either way, the outcome is the same: authentication tells the recipient this email is genuine, and the recipient's own trust in that green checkmark becomes the vulnerability.

This pattern is not an outlier. The 2024 Verizon Data Breach Investigations Report found phishing present in 15 percent of breaches and identified the human element in 68 percent of them, and it clocked a median time of just 21 seconds for a user to click a phishing link and 28 seconds to submit data once they engage. The Microsoft Digital Defense Report 2024 similarly documents a shift toward attacks that abuse legitimate services and infrastructure to blend in. When the delivery is clean, the only thing left to defend is the human decision at the other end.

Mapping to MITRE ATT&CK

  • T1566, Phishing. The initial access vector is a phishing email, here delivered through an abused but legitimate ESP.
  • T1598, Phishing for Information. The callback path fits the reconnaissance-and-elicitation pattern behind telephone-oriented attacks, where the operator extracts payment or access details live on the call. MITRE's guidance on this technique is a useful reference for callback and voice-driven variants.
  • T1656, Impersonation. The display-name collision with a known internal contact is a direct impersonation play designed to borrow trust the sender has not earned.

Indicators of Compromise

All indicators are defanged. Do not interact with them directly.

IndicatorTypeNotes
notifications@demio[.]comSender addressLegitimate platform address, abused as the delivery envelope
demio[.]comSending domainLegitimate ESP infrastructure, full auth pass (SPF, DKIM d=demio.com, DMARC)
[redacted]@gmail[.]comContact addressPersonal Gmail listed as event contact instead of a corporate address
+1 (800) 958-7164Callback numberTOAD payload, injected via corrupted mail-merge token
"$728.99 payment processed"Lure textFabricated payment notice rendered in the greeting and image alt-text

Why Authentication Was Never the Point

The instinct after an incident like this is to ask which control failed. The honest answer is that none of them did, because none of them was ever designed to catch this. SPF, DKIM, and DMARC confirm that a message was sent by someone authorized to use a domain. They do not read the message. A legacy secure email gateway (SEG) filters on known-bad signals, and this email carried none. There was no malicious URL, no malware, no spoofed domain, and no authentication failure to trigger on.

Catching this requires reading the email the way a suspicious human would. The injected payment amount that contradicts any real subscription, the callback number where a webinar reminder would never place one, the personal Gmail contact, and the display-name collision are all language and behavior signals, not infrastructure signals. This is exactly where Adaptive AI earns its keep. Themis evaluates the content, sender relationship, and intent of a message rather than trusting a clean authentication record, and it treats a fabricated payment notice paired with a callback number as the coordinated pretext it is. Across the environments IRONSCALES protects, spanning 35,000+ security professionals across 17,000+ organizations, that behavioral read is what separates a benign event reminder from a vishing lure wearing one as a disguise.

The Cybersecurity and Infrastructure Security Agency's phishing guidance makes the same point from the defender's side: stopping the attack cycle early depends on recognizing social-engineering pretexts, not just blocking bad links. The FBI's 2023 Internet Crime Report underscores the stakes, with business email compromise and related fraud accounting for billions in reported losses.

The Takeaway

A perfectly authenticated email is not a safe email. When the payload is a phone number and a lie, the only defenses that matter are the ones that read intent. Behavioral analysis and continuous platform-level detection close the gap that authentication leaves wide open, and treating callback-and-payment pretexts as first-class threats is now table stakes for stopping business email compromise.

Want to know how many messages like this are already reaching your users? See your risk with a real-inbox assessment and find out what a clean authentication record is hiding.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
Clean Scan, Full Auth, One Phone Number: A Compromised School Account Carrying a TOAD PayloadA PDF marked clean by every scanner.
The Invoice That Never Existed: Geek Squad TOAD via a Blank-Extension JPEGA throwaway Hotmail account delivered a fake $559.47 Geek Squad invoice as a JPEG with no file extension.
A 16-Day-Old Domain, Zero Links, and One Phone Number: Anatomy of a Pure TOAD AttackA phishing email with zero links, zero attachments, and zero malicious URLs reached four mailboxes at a healthcare organization.
A Free Gmail Account Impersonating an Internal Employee Asked Payroll to Change a Bank AccountA free Gmail address displayed the name of a real internal employee and asked the payroll team to update direct-deposit banking information.
A Construction Bid Invitation Hid a Compromised Website Behind a Legitimate-Looking PDF LabelA bid-invitation email sent to a steel fabrication company via mass BCC contained a link labeled as a PDF bid preview.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.