TL;DR A past due notice arrived at the treasury function of a privately held industrial group carrying full, aligned authentication: SPF pass, two valid DKIM signatures including one for the domain in the From header, and a clean DMARC evaluation. Nothing in the headers was forged. The Reply-To pointed at a different domain registered six days earlier behind WHOIS privacy, and the attached invoice named that same six day old company in its own PDF metadata, generated in the minute the message was sent. Bank details were withheld, to be supplied only on reply.
Severity: High Business-Email-Compromise Invoice-Fraud Reply-To-Diversion Trusted-Infrastructure-Abuse MITRE: T1566.001 MITRE: T1583.001 MITRE: T1585.002

A past due notice reached the treasury function of a privately held industrial group, and every authentication check on it passed. Not the partial pass that a bulk sending platform earns on its own behalf, but a full aligned pass: SPF clean on the envelope, two valid DKIM signatures, one of them belonging to the exact domain printed in the From header, and DMARC evaluating clean against that same domain. Nothing in the headers was forged.

The fraud sat one line lower. The Reply-To pointed at a completely different domain, and that domain had existed for six days.

Authentication That Was Real, and Still Wrong

The envelope came in through a major cloud provider's bulk email service, so SPF passed on the platform's own sending identity in its Ohio region. On its own that is the weak kind of pass, saying only that a relay was allowed to relay. This message carried more: a second valid DKIM signature for the .org domain in the visible From address, which is the one that matters. That made DMARC evaluate against an aligned identifier and return a pass rather than the softer platform only result. Microsoft's composite authentication agreed and scored it clean.

That sending domain is not new. It was registered years earlier, sits behind a mainstream content delivery provider's nameservers, and appears nowhere else in this record as attacker infrastructure. The most economical reading is that a legitimate sender's ability to emit signed mail was borrowed, through a compromised account or an abused sending configuration. We withhold its name for that reason: whatever happened upstream, the domain owner is a party to the abuse, not its author.

That inverts a common review shortcut. An aligned pass under RFC 7489 proves that whoever sent this message controlled, or had access to something that controlled, the domain in the From header. It proves control. It says nothing about the legitimacy of the entity exercising that control, and nothing at all about the transaction the message requests. The 2024 Verizon Data Breach Investigations Report puts the human element in 68 percent of breaches and names pretexting, mostly business email compromise, as the leading social engineering type. Pretexting does not need a forged header. It needs a plausible request.

The Payee That Barely Existed

The reply path went to a mailbox on a domain whose WHOIS record showed creation six days before the message was sent, through a low cost registrar, under full privacy protection, on a budget nameserver service. Everything about that registration is cheap, anonymous and disposable, which is what makes domain age such a durable payment control. This is acquire infrastructure and establish accounts as a same week purchase: buy an identity, invoice with it, abandon it.

The display persona on the message described itself as a finance executive at that payee company. The From address, by contrast, was a generic sales alias on the borrowed .org domain. Two organizations, one message, and the only one the recipient was asked to talk to was the week old one.

See Your Risk: Calculate how many threats your SEG is missing

What the Attachment Said About Itself

The invoice was a 2,622 byte PDF, an older format version, not encrypted, with no JavaScript, no form actions, no embedded URLs and no exploit. Every scanner returned clean, and every scanner was right. There was nothing in it to detonate.

The disclosure was in its metadata. Both the author field and the producing application field named the six day old payee company, and the creation and modification timestamps fell in the same minute the email left. A document from a real accounts receivable process carries the fingerprint of the system that generated it and dates that track a billing cycle. This one was authored by the operation that mailed it, minutes before it mailed it, under a company name younger than most sales cycles. Attachment metadata is free to read, and on a payment request it is often the only field that was not chosen for the reader's benefit.

One smaller touch: the invoice prefix in both the filename and the subject line replaced a capital letter I with a lowercase L, which reads identically to a person and not at all to a rule matching the literal string.

The Request That Was Deliberately Incomplete

Under the invoice, the body carried a fabricated forwarded exchange between an invented internal requester and the purported finance executive, discussing an outstanding balance for coaching services, development work and a membership subscription, and noting that a copy should have been going to this treasury mailbox all along. It makes the recipient's own presence in the thread feel pre arranged. It also gave the campaign away: a corporate treasury does not receive personal coaching and membership dues, which marks this as a templated kit fired at a finance title rather than research against a real vendor relationship.

Then the one line that carried the whole operation, verbatim from the body: we will provide our bank details upon request. No account number, no routing number, nothing for a content policy to compare against a vendor master file. The endgame moves into a reply the attacker controls, which is why the 2023 FBI IC3 report counts roughly 2.9 billion dollars in reported business email compromise losses against attacks that frequently ship no payload at all. The money moves through a legitimate process that a person approves.

The Only Signals Left Standing

There was no attacker URL to reputation check: the three links in the message all pointed at Microsoft's own external sender guidance, part of the tenant's own warning banner, and all three graded clean. Attachment sandboxing had nothing, authentication had a pass, and three of the four surfaces a gateway leans on returned either silence or a green light.

What remained was relational and contextual, which is where Themis works. It labeled the message against a high value recipient with 89 percent confidence, reading a first contact sender against a treasury mailbox, urgency and promotional phrasing inconsistent with an established billing thread, sending behavior consistent with bulk mail, the divergence between the From and Reply-To apex domains, and a payee domain younger than a week. Both affected mailboxes were quarantined, one logging an error on the mitigation action, a reminder that a quarantine reported with an error still needs a human to confirm it landed. Worth naming plainly: the automated triage first bucketed this as bulk mail even while the case narrative described textbook invoice fraud. Both readings were true of the same message, and only one of them mattered.

Controls That Would Have Caught This Earlier

Compare the apex domain in the From header against the apex domain in the Reply-To, and treat divergence on any payment request to a finance mailbox as a hold rather than a note. Add payee domain registration age to the accounts payable checklist, with anything under three months blocking release. Read the metadata on invoice attachments: author, producer and creation time are cheap to check and hard for a kit to curate. And require that bank details arrive through a channel already on file, never through a reply to the message asking to be paid. CISA's phishing guidance and NIST's definition both frame it the same way: the control has to sit on the action, because the message itself can be made to look correct. That is the shape of business email compromise once headers stop being the interesting part.

Indicators of Compromise

TypeIndicatorContext
Domainrclnorthstone[.]comAttacker registered payee domain in the Reply-To. WHOIS creation six days before the send, low cost registrar, full privacy protection, budget nameservers.
Email (Reply-To)[local part withheld]@rclnorthstone[.]comThe diversion address and the operational payload of the message. Local part withheld because it reproduces a persona first name.
Email (From)Withheld: a generic sales alias on an established .org domainBystander infrastructure. Genuinely signed and DMARC aligned for that domain. Domain and local part both withheld, as the owner appears to be a victim of the abuse.
Email (envelope)[envelope token withheld]@us-east-2.amazonses[.]comReturn path on a bulk sending platform in its Ohio region. Platform infrastructure, not attacker owned.
FilelNV_C-349-02.pdf2,622 byte invoice attachment, scanner verdict clean. Invoice prefix substitutes a lowercase L for a capital I in both filename and subject.
Hash (MD5)d1043655f1e4eeb808b4b4f9edb2d277MD5 of the attachment as reported by the platform.
MetadataPDF author and producer fields naming the payee companyBoth fields name the six day old payee entity, with creation and modification timestamps in the same minute as the send.
PhraseWe will provide our bank details upon request.Body text. Defers account details to an off thread reply the attacker controls.
Header patterndkim=pass for the From domain plus dkim=pass for the sending platformTwo valid signatures. The aligned one, on the visible From domain, is what produced the DMARC pass.

MITRE ATT&CK Mapping

TechniqueIDApplication
Phishing: Spearphishing AttachmentT1566.001A clean, payload free invoice PDF sent to a named treasury mailbox as the pretext object.
Acquire Infrastructure: DomainsT1583.001Payee domain registered six days before use, under privacy protection at a low cost registrar.
Establish Accounts: Email AccountsT1585.002A finance executive persona stood up on that fresh domain to receive the reply and supply bank details.
Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
eCheck Retrieval Fraud: url.emailprotection.link Rewrapping and DMARC Fail Under a p=reject PolicyA payment fraud email instructed recipients to expect an eCheck from noreply@vitesse.io, with retrieval links rewritten through url.emailprotection.link.
The Invoice Was Older Than the Domain It Told You to PayA $19,900 vendor invoice reached the VP of Accounting at an insurance provider with SPF, DKIM and DMARC all passing under an enforced policy.
The Security Tool That Delivered the $48,500 Invoice FraudA $48,500 invoice fraud routed through a Votiro email sanitization relay, which paradoxically introduced an SPF softfail.
Gateway-Rewritten Links Flagged Malicious Inside a Law Firm Email With No DKIMA professional email with legal contract language arrived from a long-established law firm domain with no DKIM signature and DMARC p=none.
Accounts Payable Display-Name Spoof Delivers a Teams-Branded Payment Lure to a CFO via SendGridAttackers registered astevenltd.com, set the From display name to an Accounts Payable identity.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.