Table of Contents
A department leader at an engineering firm received an order-shipping notice branded Geek Squad, the Best Buy tech-support arm. Routine enough. Except the email did not come from Best Buy. It came from Microsoft's own Dynamics 365 Marketing cloud, and it arrived with a spotless authentication record that most gateways read as proof of legitimacy.
That is the trick worth studying. The attacker did not spoof anyone or stand up a look-alike domain. They borrowed a real, trusted sending platform, wrapped it around a consumer brand, and pointed the whole thing at a phone number.
A First-Time Sender With a Perfect Record
The message originated from 13.71.171.6 on can.pb-dynmktg.com and carried a signature from dyn365mktg[.]com, the sending domain behind Microsoft Dynamics 365 Marketing. Because that infrastructure is genuinely authorized to send, the message earned SPF=pass, DKIM=pass, and DMARC=pass, with compauth scoring 100. On paper it was flawless.
It was also a first-time external sender to this organization, delivering a consumer retail lure to a corporate engineering mailbox. Those two facts do not belong together, and that mismatch is the entire point. Authentication confirms that a server was allowed to send. It says nothing about whether the brand in the body has any relationship to that server. Sender Policy Framework and DomainKeys Identified Mail were both satisfied here precisely because the sender never claimed to be Best Buy at the protocol level. They let Microsoft's marketing platform vouch for the envelope while Geek Squad did the talking in the body.
This is the pattern the Microsoft Digital Defense Report 2024 called out directly: attackers increasingly abuse legitimate cloud and marketing services rather than breaking authentication, because trusted infrastructure launders reputation better than any forged header can.
The Template Told On Itself
The lure impersonated a Geek Squad order confirmation, the kind of receipt that prompts a worried customer to call about a charge they do not recognize. But whoever built it left the scaffolding showing.
The body leaked Microsoft's own Northwind Traders placeholder, the fictional sample company that ships inside Dynamics 365 demo content, sitting right next to the real Geek Squad brand. A genuine Best Buy notice does not reference a Microsoft sample company. Its presence is a fingerprint of a Dynamics 365 Marketing template that was cloned or misconfigured and never fully scrubbed.
The address block made it worse. The notice listed a delivery address in Buffalo, New York, then stamped it with ZIP code 98052. That ZIP belongs to Redmond, Washington, which happens to be Microsoft's own headquarters, another artifact dragged along from the template rather than any real shipment. A shipping notice that cannot keep its own city and ZIP on the same coast is not a shipping notice.
The Payload Was a Phone Number
There was no credential-harvesting link and no malicious attachment. The single call to action was a phone number, +1 (805) 866-7568, presented as the line to call about the order. That makes this a callback, or vishing, attack: the goal is to get the target on the phone, where a live operator can talk them into a payment or remote-access session with no written trail.
The number itself was the final tell. An 805 area code geolocates to the central California coast, nowhere near the Buffalo address the email claimed. A legitimate national retailer routes support through a toll-free line, not a regional cell number that contradicts the shipping details three paragraphs up.
Vishing is deliberately effective against automated defenses. Link scanners and attachment sandboxes have nothing to chew on, which is exactly why callback lures keep working. The FBI's 2023 Internet Crime Report ranked callback and tech-support impersonation schemes among the most damaging categories reported that year, and the economics have not changed. The 2024 Verizon Data Breach Investigations Report found pretexting, most of it business email compromise, is now the top social-engineering incident type, with a median transaction near 50,000 dollars.
Mapping to MITRE ATT&CK
The tradecraft lines up with a few techniques in the MITRE ATT&CK framework:
- T1566.002 Spearphishing Link covers the delivery, a targeted message riding trusted marketing infrastructure with a tracked redirect chain.
- T1656 Impersonation covers the Geek Squad and Best Buy brand deception layered over Microsoft's platform.
- T1598.004 Spearphishing Voice covers the callback hook, moving the victim off email and onto a phone line for the actual theft.
Indicators of Compromise
| Type | Indicator | Context |
|---|---|---|
| Phone | +1 (805) 866-7568 | Vishing callback number, area code geolocates to California against a Buffalo body address |
| Domain | dyn365mktg[.]com | Microsoft Dynamics 365 Marketing sending domain, abused as trusted delivery infrastructure |
admin@unqcd106dce85d6f01189f56045bd5bd.s05.dyn365mktg[.]com | Sending address behind a generic personal display name | |
| URL | public-can.mkt.dynamics[.]com | Marketing redirect host used for the tracking and unsubscribe link |
| Reference | C117658675095 | Fabricated shipment tracking number in the lure body |
Why Reputation Alone Would Have Missed It
Here is the uncomfortable part. Every authentication signal was green, and the mail rode a domain that most reputation engines score as trusted. A gateway that leans on SPF, DKIM, DMARC, and sender reputation would have delivered this straight to the inbox, because by those measures it is a legitimate Microsoft marketing send.
Microsoft's own antispam did not stop at authentication. It scored the content and reputation mismatch as SCL=5, and the message was quarantined rather than delivered. That is the whole lesson: the artifacts that mattered lived in the body and the behavior, not the headers.
See Your Risk: Calculate how many threats your SEG is missing
This is where behavioral analysis earns its keep. Themis, the Adaptive AI analyst on the IRONSCALES platform, reads the relationship between the claimed brand, the actual sending platform, the demo-data leakage, and a phone-only call to action the way a trained analyst would, and flags the vishing attempt even when the envelope is spotless. That behavioral layer is exactly what augmenting Microsoft 365 is for, catching the intent that native filtering and authentication miss. It is the same instinct that protects the 35,000+ security professionals across 17,000+ organizations who lean on that second set of eyes.
The Takeaway
Trusted infrastructure is the new spoof. When an attacker sends from a platform your filters already respect, authentication stops being evidence and starts being camouflage. The defense is to read the message, not just the headers: a first-time sender pushing a consumer brand into a corporate inbox, a template leaking sample-company data, a shipping notice whose own address does not agree with itself, and a payload that is nothing but a phone number. Those signals were all present here, and they are what turned a perfect authentication record into a quarantined phish.
Related attacks
| Attack | What happened |
|---|---|
| Amazon Said You Owe $879. The Phone Number Was the Payload. | DKIM and DMARC passed for amazon.de. |
| A Geek Squad Calendar Invite With No Links, No Malware, and a Phone Number | A Google Calendar invite claimed a $359.99 Geek Squad charge was hitting the recipient's billing cycle. |
| Pandora Renewal Scam: No Links, Just a Callback | A fake Pandora Premium renewal notice carried no links and no attachments. |
| The SharePoint File Share That Came From Microsoft's Own Infrastructure | A high-fidelity Microsoft 'file shared with you' notification delivered a SharePoint credential-phishing link hosted on Microsoft's real infrastructure. |
| McAfee Invoice Scam Weaponized a Google Calendar Invite 71 Minutes After Domain Registration | A same-day registered domain abused Google Calendar invites to deliver a McAfee/Webroot invoice scam with a callback phone number. |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.