TL;DR A compromised school district Google Workspace account sent a vague payment status invoice lure with a generic PDF to 29 unrelated recipients across a dozen industries. The message passed SPF, DKIM, and DMARC cleanly, because the district enforced DMARC at p=reject and the mail came from the genuine account, not a spoof. Authentication cannot flag a real sender. The only tells were behavioral: a mismatched callback number, broken grammar, and a mailing list that spanned unrelated companies with no reason to receive the same invoice.
Severity: High Account Takeover Invoice Fraud Business Email Compromise MITRE: T1078 MITRE: T1566.001 MITRE: T1585.002

A U.S. school district had done the hard part right. Its domain enforced DMARC at p=reject, sp=reject, pct=100, the strongest posture the standard offers. A forged message claiming to come from that district would be dropped on the floor at the receiving edge, no questions asked.

It did not matter. An invoice lure went out from that district anyway, sailed through SPF, DKIM, and DMARC with a clean pass, and landed in 29 mailboxes across a dozen unrelated industries. One of those mailboxes belonged to a design-operations executive at a major U.S. automaker.

The reason it passed is the whole story. This was not a spoof. The attacker was logged into the real account.

Authentication Cannot Flag a Real Sender

Email authentication answers exactly one question: did this message actually come from a server allowed to send for this domain? When the answer is yes, every check goes green. That is precisely what happened here. The mail originated from the district's genuine Google Workspace tenant, signed with the district's own DKIM key (selector google), from an IP the district's SPF record authorizes. DMARC aligned because there was nothing misaligned to catch.

A p=reject policy is built to stop impersonators who forge your domain from infrastructure they do not own. It has no answer for an intruder who signs in to the mailbox and clicks send. From the receiving side, an authenticated message from a compromised account is indistinguishable from a legitimate one at the protocol layer. The stronger the domain's authentication, the more trust that stolen session inherits.

This is the uncomfortable inverse of every "just deploy DMARC" checklist. Good authentication hygiene protects everyone else from being impersonated as you. It does nothing to protect your correspondents once your own account is taken over. That is a different problem, and it lives entirely in behavior.

A Blast That Did Not Add Up

The content was thin on purpose. The subject line read [EXTERNAL] Dear: Payment status updated for order Token, a templated string with a placeholder that was never filled in. The body offered a single line of broken grammar, "Thank you for choosing us,. Invoice and details enclosed," followed by a customer help line. Attached was a generic PDF, 34,861 bytes, titled with the same vague subject and scanned clean, carrying no order number, no amount, and no reason for any specific recipient to have received it.

The distribution list is what gives the game away. Twenty-nine external addresses, spanning dental practices, a national laboratory, consumer brands, a food producer, a university, and the automaker executive. No shared vendor, no common project, no plausible reason for one invoice to reach all of them at once. A real accounts-payable notice goes to a party that placed an order. This went to a mailing list the attacker had, blasted from whatever mailbox they had most recently pried open.

Two more tells sat in plain sight. The in-body callback number, +1(983) 220-2388, geolocated to Colorado, nowhere near the district it claimed to represent. And the signature block reused the district's own legitimate public website link for a veneer of trust. That last touch is a common move: borrow a real, verifiable asset from the hijacked identity to paper over everything that does not hold up.

See Your Risk: Calculate how many threats your SEG is missing

Mapping to MITRE ATT&CK

The tradecraft maps cleanly across the MITRE ATT&CK framework:

  • T1078 Valid Accounts is the crux. The operator used credentials to a real Google Workspace mailbox, so all activity carried the account's genuine authorization and reputation.
  • T1566.001 Spearphishing Attachment covers the payload: a generic invoice PDF as the object the recipient was meant to open.
  • T1585.002 Establish Accounts: Email Accounts reflects the operator's reliance on a foothold in a legitimate email identity to launder the send.

Indicators of Compromise

The infrastructure here was the victim's own, so it is deliberately absent from this table. The compromised district account and its domains are not indicators to block; they belong to a victim. What follows are the campaign artifacts safe to watch for.

TypeIndicatorContext
Subject[EXTERNAL] Dear: Payment status updated for order TokenTemplated lure with an unfilled placeholder token
AttachmentDear: Payment status updated for order Token_1764689947[.]pdfGeneric 34,861-byte invoice PDF, no order detail, scanned clean
Attachment MD576150dde2d4e33dceeb60d4154305cceHash of the attached PDF
Phone+1(983) 220-2388In-body callback number geolocating to a different state than the sender

Detecting What Passes Every Check

Signature and reputation engines were never going to catch this. The sender was authenticated, the domain was reputable, the attachment scanned clean, and no link needed to be inspected. A gateway grading on those inputs delivers the message and files a green report. Detection has to move to relationship and behavior: a first-time sender to most recipients, a message pattern that does not fit the sender's history, an invoice with no order context, and a single send fanning out to organizations with nothing in common.

That relational read is where the IRONSCALES platform adds a layer static gateways miss. Themis, our Adaptive AI analyst, weighs the sender's normal behavior, the recipient spread, and the intent of the message rather than trusting a clean authentication pass on its own, and it learns from what 35,000+ security professionals across 17,000+ organizations report back. Because compromise, not forgery, is the harder half of the problem, pairing authentication with account takeover protection is what actually closes this gap.

The scale numbers back the priority. The 2024 Verizon Data Breach Investigations Report puts the human element in 68 percent of breaches and stolen credentials at the root of 38 percent of them, and the Microsoft Digital Defense Report 2024 documents the same shift toward abusing trusted accounts and services instead of breaking through the front door. The FBI's 2023 Internet Crime Report ranks business-identity and invoice fraud among the costliest categories year after year, and a hijacked, fully authenticated mailbox is one of the cleanest ways to run it.

The Takeaway

DMARC at reject is worth deploying, and this district was right to enforce it. Just be clear about what it buys. It stops the world from impersonating you. It does not stop an attacker who is already inside your account from trading on your good name, and it does not stop the authenticated blast that lands in your correspondents' inboxes with every check green. When the send is real and only the intent is fake, the defense is behavioral. Treat a clean authentication pass as the floor, not the verdict, and read the sender's behavior before you trust the message. CISA's guidance on recognizing and stopping phishing early is a solid team reference for building that reflex: https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
Shell International Impersonated in BEC Invoice Fraud: DMARC Failure Exposes the Lookalike Payment ChainAn attacker spoofed Shell International's From header with a debt-collection urgency lure, then pointed payment to two attacker-controlled domains.
Password-Protected PDFs Are the New Sandbox Killer: How a Compromised .gov Account Delivered an Unopenable PayloadA compromised government education account sent a password-protected PDF with the passcode in the email body, bypassing every automated scanner.
The Audit Request That Passed Every Authentication Check: How a Compromised Nonprofit Account Weaponized URL ShortenersA phishing campaign hijacked a legitimate nonprofit email account to send fraudulent audit requests with malicious URL shortener links.
The Confidential Mode Message That Had Zero Indicators of CompromiseA Gmail Confidential Mode message copied an internal employee's display name, passed SPF/DKIM/DMARC/ARC with every link pointing to Google.
Every Authentication Check Passed Because the Attacker Already Had the KeysA compromised telecom account sent a routine construction work order with one goal: get recipients to reply all.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.