TL;DR A compromised mailbox at an established vendor sent a close replica of a Microsoft Planner project invite to four people at a UK sports marketing and data consultancy. Each recipient got a separately generated subject line naming their own first name and a different invented entity word, which defeats subject clustering. The message authenticated cleanly, the single attacker link scanned Clean, and Themis returned no confidence score. A human recipient caught it by reading the destination host, and two end users reported it before an analyst made the malicious call.
Severity: High Vendor Email Compromise Brand Impersonation Malicious Link MITRE: T1566.002 MITRE: T1566

Four people at the same company received four different emails in fifty minutes. Same attack, same link, four separately generated subject lines. Each opened with that recipient's own first name, and each named the same invented joint entity differently: Alliance, Workforce, Partnership, Network.

The lure was a Microsoft Planner notification. You have been invited to a project. Segoe UI tables, a Teams-purple button reading Open in browser, and the genuine Planner footer copy about why you are getting this email.

It was sent from inside a real vendor's Microsoft 365 tenant, from a mailbox the recipients had traded messages with before. Nothing in the automated stack called it. The single attacker link came back Clean, Themis returned no confidence score at all, and Microsoft scored the message SCL:1, meaning not spam. A recipient read the destination host, saw it was wrong, reported it.

Planner Is the Disguise Nobody Is Watching

Project-invite notifications are the cheapest possible pretext because they are workflow noise. Nobody treats one as a decision, and collaboration platform notifications are a surface most programs audit last.

It closely replicates the real invite: layout, button color, boilerplate strings, and genuine Microsoft URLs left in as padding (go.microsoft.com, tasks.office.com, planner.cloud.microsoft, a privacy link). All of them scanned clean, because all of them are real.

Then the detail worth quoting. A fabricated legitimacy line in the footer naming both organizations: this notification is generated through the vendor's use of Microsoft 365 and is intended strictly for the recipient's company. Microsoft does not write that sentence. Someone added it because compliance boilerplate is what people skim.

The link text presented the destination as a shared external group between the two companies. The one attacker URL appeared three times, each carrying an identical 104-character hex token: a per-victim identifier tying any click to one mailbox.

Four Subjects, Four Recipients, One Campaign You Cannot Cluster

Between 13:34 and 14:24 UTC on 2026-08-19, four mailboxes in the consultancy's marketing practice received four distinct subject lines. Not template variations. Separately generated, each built from the recipient's first name plus one word from a rotating set, for an entity that does not exist.

Subject-line clustering is a real and widely used detection primitive. Twenty copies of one subject across a tenant in ten minutes is a campaign, easy to score. Four unique subjects to four mailboxes in fifty minutes is four one-offs, each scored alone.

The generator left fingerprints. The prepositions are not native English: included to, added to.

The 2026 Verizon Data Breach Investigations Report found that AI-assisted text in malicious emails doubled year over year, and that the impact is operational rather than a novel technique. This is what operational looks like. Verizon still puts phishing at 16% of breaches as an initial access vector and the human element in 62%, up from 60%. Stable numbers. The cost of a bespoke subject line is not.

Why Every Authentication Check Passed

This is vendor email compromise, or VEC, not an unrelated domain being abused. The record is explicit: not a first-time sender, and both organizations had corresponded in both directions. The supplier relationship is the asset being spent.

The message originated in the vendor's own Exchange Online mailbox via MAPI submission, then egressed through the tenant's cloud email-signature service, which appended the genuine corporate signature block on the way out. At the final hop: spf=pass, dkim=pass aligned to the vendor domain, dmarc=pass, compauth=pass reason 100, under an enforced DMARC policy of p=quarantine at 100%. ARC passed at both hops.

The sequencing is what makes that spotless. At the appliance hop the message was not yet signed, and the original authentication results record dkim=none and dmarc=none for that stage. The tenant's DKIM signature is applied after the appliance modifies the body, so the delivered message is signed over the modified body and nothing breaks.

That inverts a pattern we have covered twice: a signature relay at a compromised partner tenant that made SPF fail mid-chain with ARC carrying the earlier pass forward, and the same class of service stapling a corporate signature onto a compromised vendor account's mail. The appliance is not the story here. The ordering is.

A secure email gateway (SEG) exists to answer reputation and authentication questions. This message answered all of them correctly.

See Your Risk: Calculate how many threats your SEG is missing

The Automated Stack Did Not Call This One

The URL scanner returned a Clean verdict on the attacker domain and captured a visual-detection screenshot on 2026-08-20. Themis produced no confidence score and no phishing insight messages, only a VIP Recipient label. Microsoft marked the message SCL:1 / SFV:NSPM.

What worked was a person. Two end users reported it, citing a suspicious link and an impersonation attempt, and a human analyst then made the malicious verdict. Note what the record still does not say: no captured credential page exists for the landing URL, so what it served is not established. That tag is a label, not an observation.

That is the human layer doing work the models did not, and the argument for wiring user reporting into detection rather than a help-desk queue. IRONSCALES platform data covers 36,000+ security professionals across 18,000+ organizations feeding that loop, against a baseline of 67.5 phishing emails per 100 mailboxes each month.

Mitigation then landed unevenly: one mailbox permanently deleted, one mitigated or reverted, two recorded as Error with no mitigation date.

An Aged Domain, Not a Fresh One

Newly-registered-domain heuristics would have contributed nothing. WHOIS on the landing domain shows creation in April 2013, a large retail registrar, shared hosting nameservers and DNSSEC unsigned. Whether it is compromised hosting or attacker-controlled is not established, and the registrant is an uninvolved third party. Thirteen years of history, reached from an authenticated vendor mailbox, gives a reputation engine nothing to bite on.

TypeIndicatorContext
URLhxxps://u-vgroup[.]com/tafel/empire?proxy=<104-hex, truncated>Only attacker link, 3x per message. Scanned Clean
Kit markeru:9e0a0ea411dd4884, Teams-purple #5B5FC7 CTA labelled Open in browserBody comment token, replica button
SubjectFirst name plus Alliance, Workforce, Partnership or Network4 mailboxes, 50 minutes

What to Change on Monday

Map this to T1566.002, spearphishing link, with valid accounts (T1078) as the access path. Both the CISA phishing guidance and the NIST definition frame phishing as an access problem, the right frame for a message with no attachment and one link.

Stop treating subject-line similarity as a load-bearing campaign signal. Cluster on the destination host, the link token shape and the template, which stayed identical while every subject differed. The Microsoft Digital Defense Report 2024 and the FBI IC3 2024 report both document how much attacker volume rides inside trusted channels.

Treat an authenticated vendor as a trust boundary, not a trust exemption. Business email compromise (BEC) detection keyed on sender reputation is blind here, because the reputation is genuine. Verizon's gateway telemetry puts BEC at 3% of the blocked attack mix in Figure 54 against 80% plain phishing.

Then make platform-notification verification a habit. The plan named in this email did not exist. One person checked the host and the campaign collapsed.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
When the SharePoint Notification Is Real But the Share Is the AttackA file-sharing notification arrived from what looked like a vendor contact.
Free Gmail Sender, Nigerian IP, Freshly Registered Reply-To: Inside a Bapco Energies Vendor BECAttackers impersonated Bahrain's national energy company using a free Gmail sender and freshly registered lookalike reply-to domains to redirect vendor...
The CEO's Name Was Real. The Mailjet Account Behind It Wasn't.An attacker impersonated the CEO of an email security company using a legitimate Mailjet ESP account with full SPF/DKIM pass.
The $0.01 Email That Was an Account-Fraud Dry RunA one-cent ACH test confirmation landed in accounts payable inboxes with full DKIM and DMARC authentication.
The Fake Login That Sends You to the Real MicrosoftA fully authenticated invoice lure delivered through SendGrid dropped a victim on a fake Microsoft sign-in page.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.