Table of Contents
A PDF landed in a financial controller's inbox on 21 August 2026 claiming to be that employee's own monthly attendance record. It greeted the reader as "Hello Team Member," and then, in the attendance table's Emp Name column, it printed an email address.
Not a name. An address, sitting in the field where a person's name belongs. The header above the table read "For your records - [EMPLOYEE-MAILBOX]". Further down: "Prepared for: [EMPLOYEE-MAILBOX]". The data row read "Emp Code [REDACTED] | Emp Name [EMPLOYEE-MAILBOX] | Designation STAFF".
That is the whole case in one artifact. The victim is an Austrian airline-catering and gourmet-hospitality group with 4,432 mailboxes. Its Human Resources function knows every one of those people by name. The document impersonating that function did not.
One field, filled into every slot
A genuine HR system reads from an employee record, so it can print a legal name, a staff number that resolves, a department and a manager. A forged one has whatever the operator harvested. Here that was one mailbox address, and the template filled all three personalization slots from it. The greeting fell through to the literal string "Team Member" because even a first name was unavailable.
This is MITRE T1566.001, spearphishing attachment, and the tell is not in the headers. It is rendered in the table, visible to the reader. Most attachment lures ask you to interpret a sender domain. This one asks you to notice that your own employer addressed you by email address.
A pretext engineered to be boring
Almost every lure in this class runs on pressure: a payslip to confirm, an invoice past due.
This document removes pressure on purpose. "This is for your reference only - no follow-up is required." Then: "This snapshot is generated automatically for all team members." It closes with "We hope you're having a great week."
No deadline, no threat, no payment request. That inverts what awareness programmes train people to flag. The 2026 Verizon Data Breach Investigations Report puts pretexting at 6% of initial access vectors and phishing at 16%, with 62% of breaches involving the human element. A pretext that asks nothing of you is still a pretext, and it survives the "does this feel urgent" check by design.
An HR vocabulary that does not exist
The interior detail is where the effort went. Its title reads "MONTHLY ATTENDANCE SNAPSHOT" under a subtitle naming the victim's own Human Resources. The period reads "Period: 14 July - 14 August 2026", day columns run Jul14 through Jul20, and clock entries look like "9:16 AM-16:59PM".
Then there is a twelve-code leave legend: AB Absent, AL Annual Leave, SL Sick Leave, BT Business Trip, OD Off Day, WFH Work from Home, LWL Leave Work Location, DNJ Did not Join, plus PL, ML, EL and MT for paternity, marriage, exam and maternity leave.
None of that is the victim's schema. It is invented, and invented well enough that few employees would question it, which leaves the personalization failure as the only inconsistency a reader had to catch.
One more piece of forged bureaucracy matters if you write screening logic. Inside the PDF sits a fake opt-out: "This is an automated internal communication. You may unsubscribe from these monthly updates by replying 'opt-out'." A real RFC 8058 unsubscribe header is decent evidence that mail is marketing, not an attack. This one is prose inside an attachment, invisible to that check and every header rule you have.
The attacker wrote nothing
The message body contained no attacker-authored content at all. Top-level Content-Type was multipart/mixed, and what rendered in the client was two injected blocks: Microsoft's first-contact notice, and the victim's own red-bordered external-sender caution banner.
The only prose in that email was the defender's own warning. The attacker supplied a subject line and a PDF.
Four mailboxes were hit in the same burst with rotating subjects. The controller received "[External] Timesheet record - Jul-Aug - [VICTIM-COMPANY]" at 14:38:02Z; three colleagues received "[External] Timesheet snapshot - [VICTIM-COMPANY] - August 21, 2026" between 12:43:17Z and 12:43:32Z. Per-recipient subject variation inside one send is a template feature, not an accident.
Two clean verdicts and one human
The payload is a single QR code, a technique known as quishing, held as an image on page one of the PDF, encoding a German domain with no connection to the victim or to any HR platform in the path. The document frames scanning it as a convenience: "You can use the QR code if you would like to see the full detailed version online", captioned "Scan for full attendance details".
The attachment graded clean. The link derived from that QR code graded clean as well. Neither had anything to grade: a page-one image and an unremarkable domain carry no signature and no known-bad history. That is the structural problem with QR payloads in attachments: the destination never renders in the mail client, and the scan happens on a phone your controls do not reach. What was served at the other end is not established and no landing page was captured: this is a German domain reachable only by scanning the code.
Both CISA's phishing guidance and the NIST definition of phishing anchor on the deception, not the file verdict. The FBI IC3 2024 report still ranks phishing first by complaint volume.
What caught this was a person. An employee at the victim reported the message, and the record shows all four delivered copies permanently deleted. That is the same signal 36,000+ security professionals across 18,000+ organizations feed back into the IRONSCALES community, where one report on a clean-scoring attachment protects the other mailboxes in the burst.
See Your Risk: Calculate how many threats your SEG is missing
A secondary note for detection engineers. The true origin hop recorded spf=fail from a bare IP with PTR InfoDomainNonexistent, dkim=none and dmarc=none, then relayed through a third-party Microsoft 365 tenant on a High Volume Email path to arrive with compauth=pass. We have covered that laundering pattern in its own teardown.
Indicators
| Type | Indicator | Context |
|---|---|---|
| URL | hxxps://quantidx[.]de/p42D/ | Page-one QR image destination; verdict clean |
| Sender | foundations@bfccwll[.]com | Display name "Attendance Reporting Services 15850119"; first-time sender |
| IP | 173[.]195[.]100[.]158 | Origin-hop submitting host, PTR InfoDomainNonexistent |
| Attachment | 08709_staff_[VICTIM-COMPANY].pdf | 62,278 bytes, md5 8cacf572634a90025c272a50ffbb80ce, verdict clean |
| Pattern | "Team Member" greeting plus a mailbox in an employee-name field | Personalization sourced only from the recipient address |
Hunt the personalization, not the urgency
The durable detection is cheap and it generalises. Any document presenting itself as an internal HR, payroll or attendance record, arriving from outside your tenant, that addresses the recipient by email address rather than by name, is forged.
Two rules follow. A third party cannot legitimately issue your internal HR records, so an external sender producing one is disqualified before you read a word of it. And no HR system sends its own employees to a stranger's domain by QR code. Neither test needs a verdict, a sandbox or a reputation score.
The lure did not need to feel dangerous to work. It needed to feel like paperwork, and it very nearly did.
Related attacks
| Attack | What happened |
|---|---|
| The RFP Email With No Body and No Attacker Infrastructure | The message body held no words at all. |
| The RFP Was Addressed to the Company That Sent It | A fully authenticated request for proposal arrived with a clean three-page PDF. |
| The PDF Scanner Couldn't Open the Attachment (But the Victim Could) | A password-protected PDF bypassed every automated scanner because none of them could open it. |
| One Target List, Six Weeks of Conference Invites | A personalized industry-summit invitation carried a brochure PDF the scanner called malicious. |
| The QR Code That Knew Your Email Address Before You Scanned It | A phishing PDF embeds a QR code with the recipient's email pre-encoded in base64. |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.