TL;DR An attacker registered a Microsoft 365 tenant to impersonate a boutique trust and asset manager, then emailed a public offshore energy company's treasury team a $27 million funding package that made no financial sense. The domain passed SPF and DKIM because the attacker owned it outright, and published no DMARC record at all. A 1.1MB PDF branded as closing documents carried the pretext, while six links pointed only to real companies' genuine social profiles, borrowing their credibility. Human review caught the mismatch and quarantined both mailboxes.
Severity: Medium Brand Impersonation Financial Fraud Business Email Compromise MITRE: T1566.001 MITRE: T1656 MITRE: T1585

A publicly traded offshore energy company does not raise a Series A. Series A funding is early-stage startup capital, the money a two-year-old software firm chases before it has revenue. So when a message landed in two mailboxes on the corporate treasury team, one of them belonging to the VP of Treasury, pitching a $27 million Series A subscription package, the financial premise was broken before anyone opened the attachment.

That is the tell worth sitting with. This attack did not fail because a scanner caught a bad link or a sandbox detonated a payload. Every technical control that reads server headers passed it. It failed because a human being read the pitch and knew a public company does not take a Series A check.

A Trust With No Paper Trail

The sender presented as a principal at a boutique trust and asset-management firm, complete with a formal signature block, a family-office narrative, and the tone of an ongoing negotiation. The message was structured to read as a live thread rather than a cold approach, the kind of stitched conversation that makes a reader assume prior context they never actually had.

None of the firm existed in any verifiable form. It had no public business-registry footprint, no regulatory filings, no corporate record that a treasury analyst could pull. The phone numbers in the signature failed carrier validation, meaning they did not map to any active line. The persona was built entirely to survive a first glance, and nothing more.

The pretext arrived as a 1.14MB PDF titled as closing and subscription documents for the fictional funding round. In the incident record the attachment was never opened or inspected in a sandbox, which is precisely how a document like this is meant to travel: as an authoritative-looking artifact that a rushed reader treats as proof of a deal already in motion.

Authentication That Proves Ownership, Not Honesty

Here is where the case gets instructive. The sending domain was registered in 2013, hidden behind WHOIS privacy protection, and running on genuine Microsoft 365 mail infrastructure. SPF passed. DKIM passed, signed under the domain's own onmicrosoft.com selector. ARC passed. Microsoft's composite authentication logged compauth=pass. On every server-level signal, this was a clean, well-behaved message.

It passed because the attacker owned the domain outright. That is the whole trick. DMARC, SPF, and DKIM confirm that a message genuinely originated from a server authorized to send for a given domain. They say nothing about whether the human behind that domain is who they claim to be, or whether the deal in the body is real. When a criminal registers their own domain and mailbox, they can satisfy every alignment check while the content is pure fabrication.

The one seam was DMARC. The domain published no _dmarc record at all, so the receiving edge fell back to a best-guess pass. A missing DMARC policy is common on domains that exist only to send a handful of fraudulent messages. Nobody sets up reporting and enforcement for a persona they intend to burn.

Borrowing Credibility From Real Companies

Fabricating a trust firm from scratch is thin cover on its own. So the attacker stitched two real, independently verifiable companies into the thread. One was an established financial institution, the other a legitimate technology services firm. Neither had any connection to the scheme. They were referenced by name to manufacture the sense that this deal sat inside a real network of reputable parties.

The six outbound links in the message reinforced the illusion. Rather than pointing to a credential-harvesting page, as most phishing does, every link resolved to one of those real companies' genuine social-media profiles: their actual X, YouTube, LinkedIn, and Facebook pages. A recipient who clicked to verify would land on authentic corporate accounts and come away reassured. It is brand-borrowing rather than link-based theft. The links were props, not payloads, and their legitimacy was the point.

See Your Risk: Calculate how many threats your SEG is missing

Mapping to MITRE ATT&CK

The tradecraft lines up cleanly across the MITRE ATT&CK framework:

  • T1585 Establish Accounts covers the foundation: a purpose-built Microsoft 365 tenant and a fabricated principal persona created solely to run this pitch.
  • T1566.001 Spearphishing Attachment covers the delivery, the branded PDF carrying the funding-package pretext into targeted treasury mailboxes.
  • T1656 Impersonation covers the invented trust firm and the two borrowed brand identities used to prop it up.

Indicators of Compromise

TypeIndicatorContext
Sender emailransom@rclummis[.]comFabricated trust persona, self-addressed From and To
Sender domainrclummis[.]comRegistered 2013, WHOIS privacy, no DMARC record, genuine O365 mail infra
AttachmentLummis Family Series Funding Docs.pdf1,136,432 bytes, branded closing and subscription docs, not sandboxed in the record
File hash (MD5)db686a242d7b99ee793cb77dad8e9636The funding-package PDF
BehavioralSix links to real companies' authentic social profilesBrand-borrowing for credibility, no credential-capture page

Detection and What to Watch For

Signature and reputation engines were never going to stop this. There was no malicious URL to blacklist, no malware to detonate, and the domain's authentication was flawless. Detection has to move to intent: a first-contact sender proposing a large financial transaction, a firm with no verifiable footprint, a threaded conversation with no genuine prior history, and links that point outward to unrelated brands rather than to the sender's own domain.

This is the layer static gateways miss. Themis, the Adaptive AI analyst on the IRONSCALES platform, weighs the relationship between the claimed identity, the sending domain, the thread history, and the destinations of every link the way a trained analyst would, rather than stopping at a green auth verdict. The 2024 Verizon Data Breach Investigations Report puts the human element in 68 percent of breaches and names pretexting, largely business email compromise, as the top social-engineering incident type, with a median BEC transaction near $50,000. The Microsoft Digital Defense Report 2024 documents the same shift toward abusing trusted services and clean infrastructure instead of breaking them, and the FBI's 2023 Internet Crime Report has long ranked business and investment fraud among the costliest categories reported. Across 35,000+ security professionals and 17,000+ organizations, the pattern IRONSCALES sees most is exactly this: fully authenticated mail carrying fabricated intent.

The Takeaway

A clean authentication result is a statement about plumbing, not about people. This message passed SPF, DKIM, and compauth because the attacker built the pipe themselves, then filled it with a company that does not exist and a deal no public treasury team would ever entertain. The defense that worked here was human judgment backed by a system that reads context, and that is the combination worth investing in. Verify counterparties in a registry, validate phone numbers, and treat unsolicited closing documents as a claim to be checked rather than a fact to be filed. See where impersonation and business email compromise risk hides in your own mail flow, because the next fabricated firm is already drafting its pitch.

CISA's guidance on recognizing and stopping phishing early is a solid reference for building that reflex across a team: https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
The Procore Footer Was Real. The Document Was Not.Every link scanner called the Procore and ExxonMobil URLs clean.
The B2B Content Marketing Email That Borrowed a Brand, a Relay Allow-List, and a Security Vendor's Own URL WrapperA polished B2B research report offer used SelectHub branding, passed through an allow-listed mail relay at SCL -1.
A Pixel-Perfect Sephora Delivery Notice Shows Why Email Authentication Alone Can't Protect YouA fully authenticated Sephora delivery notification passed SPF, DKIM, and DMARC with perfect scores.
The Email That Passed Every Security Check (Because Adobe Sent It)A phishing campaign targeting school district staff used Adobe's own sending infrastructure, real DKIM signatures.
The Phishing Infrastructure Was Canva. The Delivery Mechanism Was Canva. The Authentication Was Canva.An attacker signed up for Canva, built a phishing lure as a design, and used the platform's own sharing feature to deliver it.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.