TL;DR A director-level executive at an Australian manufacturing company received an advance-fee (419) scam promising a $25,000,000 payout. The email name-dropped a prominent public figure as an FBI official to borrow authority, then instructed the recipient to send their name, address, date of birth, and phone number to a Gmail address impersonating an official at Bank Negara Malaysia, the country's central bank. The message came from a recently registered, privacy-protected domain relayed through an unrelated company's mail via a bulk-mail reseller. SPF softfailed, DKIM was unsigned, and DMARC returned temperror. There was no technical legitimacy anywhere, only a stolen name.
Severity: High Advance Fee Fraud Impersonation Social Engineering Phishing MITRE: T1566 MITRE: T1656

The subject line read "FBI query{CODE:210}." The body promised $25,000,000. And to collect it, a director-level executive at an Australian manufacturing company was told to email their name, home address, date of birth, and phone number to a Gmail account claiming to speak for Malaysia's central bank.

None of it was real. But it is worth taking apart, because it shows how little technical machinery an attacker actually needs when the whole scheme runs on a borrowed name.

See Your Risk: Calculate how many threats your SEG is missing

The Pitch: A Fortune, a Federal Badge, and a Blank Form

This is a textbook advance-fee scam, the family of fraud often called a 419 scam. The formula is old: promise a windfall, then extract fees or personal data before the imaginary payout can be released.

What made this one notable was the authority it tried to borrow. The message name-dropped a prominent public figure it presented as an FBI official, using that name to make a fictitious $25 million fund release sound sanctioned by U.S. federal law enforcement. That framing is the con. No government agency emails private individuals to hand over an inheritance, and none asks a recipient to prove their identity by replying with a date of birth and phone number to an unverified address.

The FBI's 2023 Internet Crime Report tracks exactly this category. Advance-fee and confidence schemes remain among the most persistent complaint types year over year, precisely because they cost the attacker almost nothing to send and occasionally land a life-changing payout.

The request itself was the payload. There was no malware to detonate and no credential-harvesting page to scan. There was a promise of money and a form to fill out. That is the pattern CISA's phishing guidance describes when it warns that phishing is a means of eliciting a response, not always a means of dropping a file.

A Central Bank That Communicates Through Gmail

Here is where the story falls apart under one second of scrutiny.

The "payout processing" was routed to a Reply-To of shamsiahmohamadyunusbnegara@gmail[.]com, an address posing as an official at Bank Negara Malaysia, the country's central bank. A national central bank does not coordinate a $25 million fund release through a free consumer webmail account. That single detail invalidates the entire premise, regardless of how official the surrounding language sounds.

The sending infrastructure was just as hollow. The From address, zawhein@royaleverestmyanmar[.]com, used a recently registered domain shielded behind WHOIS privacy protection (WHOIS is the public registration record for a domain). The message did not even originate from its own infrastructure. It was relayed through an unrelated business's mail system, authenticated as a third-party mailbox, and pushed out through a bulk-mail reseller. In other words, one compromised or rented sending channel spraying a template that had nothing to do with the domain in the From line.

This is impersonation stacked on impersonation: a fake FBI official vouching for a fake central bank contact, delivered through borrowed plumbing.

The Authentication Told the Whole Story

For an attack that tried to sound this official, the technical signals were remarkably weak.

  • SPF softfailed. Sender Policy Framework checks whether the sending server is authorized for the domain. A softfail means it was not clearly authorized.
  • DKIM was absent. DomainKeys Identified Mail cryptographically signs a message so a receiver can confirm it was not altered and came from the claimed domain. This message was unsigned.
  • DMARC returned a temporary error. Domain-based Message Authentication, Reporting and Conformance ties SPF and DKIM together against the visible From domain. A temperror means it could not even complete the evaluation.

Composite authentication landed at compauth=none with reason=408. There was no meaningful authentication anywhere in the header.

As Microsoft's Digital Defense Report 2024 documents, identity-based and social-engineering attacks continue to scale because they sidestep technical controls entirely. This one did not bother to defeat authentication. It simply relied on a recipient reading the words and not the headers.

Mapping It to MITRE ATT&CK

Two techniques cover the tradecraft cleanly:

  • T1566 (Phishing): the delivery of a fraudulent message designed to elicit a response, in this case personal identifying information.
  • T1656 (Impersonation): assuming the identity of trusted parties, here both a named law-enforcement official and a central bank representative, to manufacture credibility.

Indicators of Compromise

TypeIndicatorContext
Domainroyaleverestmyanmar[.]comSender domain, recently registered, WHOIS-privacy protected
Emailzawhein@royaleverestmyanmar[.]comFrom address
Emailshamsiahmohamadyunusbnegara@gmail[.]comReply-To posing as a Bank Negara Malaysia contact
Sender behaviorRelay authenticated as a third-party mailbox via a bulk-mail resellerDelivery channel unrelated to the From domain
Auth resultSPF softfail; DKIM none; DMARC temperror; compauth=none reason=408No meaningful authentication
SubjectFBI query{CODE:210}Authority-borrowing lure

Why a Gateway Waves This Through and Behavioral AI Does Not

A payload-focused Secure Email Gateway (SEG) has almost nothing to work with here. No attachment to sandbox, no URL to reputation-check. The weak authentication would raise a flag on a good day, but low-quality signals like a softfail and a temperror are exactly the kind of inconsistent input that spam scoring alone struggles to weigh.

The 2024 Verizon Data Breach Investigations Report found the human element present in 68% of breaches and phishing in 15% of them, with the median business email compromise transaction sitting around $50,000. Attacks like this one are engineered for that human element. They are cheap, they scale, and they only need to work once.

This is where Themis, the Adaptive AI at the core of the IRONSCALES platform, evaluates the message the way an analyst would. It weighs the mismatch between an authoritative claim and a consumer Gmail reply channel, the fresh privacy-shielded domain, the request for personal data, and the absent authentication together, rather than hunting for a payload that was never there. For a director-level target at a manufacturer, that VIP context raises the scrutiny further.

The lesson generalizes beyond this one email. Phishing that arrives with no link and no attachment is not a lesser threat. It is often the harder one to catch, because it hides in plain language.

The Takeaway

Treat any unsolicited promise of money as hostile by default, especially when it invokes a government agency or a bank and routes the reply through a free webmail account. A real institution never asks you to prove your identity by emailing personal details to Gmail. When the authority is loud and the authentication is silent, the name is the whole attack.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
Microsoft Bookings as a Weapon: When DMARC Says Trust Me and ARC Quietly DisagreesA phishing email sent from bookings.microsoft.com passed every authentication check.
Authenticated Education Sender, Malicious Study-Abroad Link, and a Student File as BaitAn authenticated Vietnamese education sender passed SPF, DKIM.
His Name in the From Field, Someone Else's Bank Account: Political Donation Impersonation via bluevision24.comA newly registered, WHOIS-redacted domain impersonated a named public figure using exact display-name spoofing.
This Phish Wanted Your LINE QR Code, Not Your PasswordA Japanese-language email asked a corporate inbox to reply with its LINE QR code.
Perfect Authentication, Zero Payload: The Yahoo Free-Mail BEC That Microsoft Flagged but Didn't BlockA Yahoo free-mail account with perfect SPF, DKIM, and DMARC authentication sent a zero-payload account change request to a state government health agency.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.