TL;DR A corporate controller at a private addiction-treatment and recovery services provider received a plain-text notice claiming a Microsoft+ Premium subscription had renewed for a three-year term at $482.99. The message came from a free Gmail account that passed SPF, DKIM, and DMARC with a perfect composite authentication score. There were no links, no attachments, and no invoice to open. The only instruction was to call a number and cancel the charge. Themis scored the message at 90 percent confidence and the platform quarantined it roughly six seconds after delivery, before anyone could dial.
Severity: High Callback Phishing Brand Impersonation Payload-Free Phishing MITRE: T1566.004 MITRE: T1656 MITRE: T1598.004

The subject line read Subscription Renewal Processed, and the body claimed a "Microsoft+ Premium" plan had just been billed for a three-year term at $482.99. There was no invoice, no link to a billing portal, no tracking pixel, and nothing for a sandbox to detonate. The message was plain text, about a dozen lines, and all it asked the reader to do was pick up a phone.

It landed in the mailbox of a corporate controller at a private addiction-treatment and recovery services provider, which is the design. Whoever sent it did not need malware. They needed one finance professional to believe an unexpected charge had already cleared.

Full authentication and a spam verdict in the same headers

The message came from a free Gmail account, meenaeshwar495[@]gmail[.]com, and it authenticated cleanly. SPF passed for gmail[.]com. DKIM verified with d=gmail[.]com. DMARC passed on the strength of both. Microsoft composite authentication returned compauth=pass reason=100, the highest confidence value it issues.

There was a single hop. The host mail-pl1-x632[.]google[.]com handed the message straight into the target tenant. No relay chain, no hijacked marketing platform, no content-disarm appliance breaking alignment. From an authentication standpoint this was a textbook clean delivery, because it was one: a real consumer mailbox sending through Google outbound infrastructure.

That is the trap. As the NIST definition of phishing makes plain, the technique runs on impersonation and deception, not on defeating cryptography. SPF, DKIM, and DMARC answer whether a message was spoofed or altered in transit. None of the three judges whether the sender means well.

The tenant antispam engine did notice something. It assigned a spam confidence level of 5 and a spam category, enough to hold the message on content grounds alone. Perfect authentication and a spam verdict sitting in the same message is not a contradiction. It is a reminder that the two systems grade different questions.

A renewal notice Microsoft would never send

Set the billing details next to a real vendor receipt and the whole thing comes apart. The plan name, "Microsoft+ Premium", does not exist. The product line beneath it cited Microsoft Azure SQL Database, a genuine cloud service that nobody buys as a personal three-year subscription. The amount, $482.99, was specific enough to alarm and small enough to look plausible on a corporate card. The customer identifier was a bare six-digit number, 582703, formatted like nothing in the real billing stack.

What was missing says more. Authentic renewal mail carries an order or invoice identifier, a link into the account portal, and a support path on the vendor domain. This message had none of those. The footer still pasted in a copyright line naming Microsoft Corporation, borrowed as a trust cue while the sending address stayed an unrelated consumer mailbox. The stamped renewal date read the way a person writes a date, spelled-out weekday first, not the way a billing system emits one.

The display name was a lowercase alias mirroring the recipient's own mailbox name, so at a glance the note looked like it came from the reader's own account, since most mail clients surface the display name and hide the address behind it.

The phone number is the whole attack

The only actionable string in the body was +1 (802)-304-2484, offered as the line to call to cancel the renewal before the funds moved. That one detail defines the category. This is telephone-oriented attack delivery, or TOAD, and its purpose is to pull the target off email, where inspection happens, and onto a live call, where it does not. Once the victim dials, the exchange becomes a vishing call and a human operator improvises from there: remote access to "process the refund", a card number read aloud, a wire to reverse a charge that never happened.

The economics favor the attacker. The 2024 Verizon Data Breach Investigations Report places the human element in 68 percent of breaches, and the 2023 FBI IC3 Internet Crime Report tallies roughly $2.9 billion in reported business email compromise losses. A callback lure costs a burner mailbox and a phone line.

Aiming it at a treatment and recovery provider is not random. Clinical organizations run lean finance teams that approve a steady stream of cloud renewals, so a surprise charge reads as routine administrative noise instead of an attack. That is why healthcare email security has to weigh sender behavior, not message content alone.

See Your Risk: Calculate how many threats your SEG is missing

Six seconds from delivery to quarantine

Automated detection closed this one with no human in the loop. Our Adaptive AI, Themis, scored the message at 90 percent confidence and classified it as a vishing attack, and the platform quarantined it about six seconds after it arrived. One mailbox was touched. Nobody reported it, because nobody needed to; the case resolved automatically as phishing.

The signals that carried the verdict were all behavioral. A first-time external sender on free webmail. A display name mirroring the recipient. A billing pretext aimed at the person who authorizes payments. A body with no links, no attachments, and a phone number as its only instruction. Individually none proves anything. Together they describe a targeted social-engineering attempt, the cluster a content-and-reputation gateway is worst at reading. IRONSCALES platform data shows secure email gateways miss an average of 67.5 phishing emails per 100 mailboxes each month, and payload-free lures like this one live inside that gap.

The CISA guidance on stopping the phishing attack cycle argues the same point from the process side: assume some of these reach a person, then build the verification habit that stops them there.

Indicators of Compromise

TypeIndicatorContext
Emailmeenaeshwar495[@]gmail[.]comFirst-time free Gmail sender, no prior correspondence
Display name[recipient username]Lowercase alias mirroring the recipient's own mailbox name
Hostmail-pl1-x632[.]google[.]comSingle sending hop, legitimate Google outbound infrastructure
Phone+1 (802)-304-2484Sole call to action, the callback number for the fake cancellation line
SubjectSubscription Renewal ProcessedBilling pretext, plain-text body, zero links and zero attachments
Auth resultSPF=pass, DKIM=pass (d=gmail[.]com), DMARC=pass, compauth=pass reason=100Full authentication from a genuine consumer mailbox
Billing artifactMicrosoft+ Premium, $482.99, customer identifier 582703Invented plan name, amount, and identifier matching no real billing format

Mapping to MITRE ATT&CK

Three techniques cover it. T1566.004 Spearphishing Voice is the callback delivery itself, the phone number standing in for a link. T1656 Impersonation covers the borrowed brand, the copyright footer, and the mirrored display name. T1598.004 is the information-gathering counterpart: what an operator would solicit once the call connected, from card details to account access.

Judge intent, not authentication

The lesson is not that free webmail is dangerous or that plain text is suspicious. It is that this message satisfied every control built to answer whether it was tampered with, and failed the only question that mattered. No cloud provider settles a disputed subscription charge over a phone number pasted into an email. Give the people who approve payments a standing rule: an unexpected charge gets verified in the vendor portal or on a number already on file, never on the number printed in the notice. Across 35,000+ security professionals at 17,000+ organizations, the messages that travel furthest usually have nothing left to scan.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
Pandora Renewal Scam: No Links, Just a CallbackA fake Pandora Premium renewal notice carried no links and no attachments.
It Passed Every Auth Check Because the Shopify Store Was RealA Norton-branded charge-dispute notice arrived through Shopify's own mailer platform with SPF, DKIM, and DMARC all passing.
Cyrillic Homoglyphs Hide a TOAD Receipt ScamA first-time Hotmail sender passed every authentication check.
A Fake Scotiabank Voicemail Was Actually an HTML File Asking You to Call an AttackerA Scotiabank-branded Interac e-Transfer alert carried an attachment disguised as a voicemail MP3.
The Law Firm Name That Used Invisible Characters to Pass AuthenticationA phishing email impersonating Alston & Bird LLP used homoglyph characters in the display name and rode Google Drive sharing infrastructure to pass SPF.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.