TL;DR An Action Required, sign-the-contract email spoofed a national food distributor, a real 25-year-old vendor, and landed in a company president's inbox. It carried no legitimate authentication at all: SPF softfail, DKIM absent, DMARC fail, compauth=none. The mail actually came from a German cloud host through a throwaway domain, and its garbled body leaked fragments of a recycled kit. The single call to action was a Microsoft SafeLinks wrapper that decoded to a credential-harvesting form hosted on the legitimate monday.com platform.
Severity: High Brand Impersonation Credential Harvesting Business Email Compromise MITRE: T1566 MITRE: T1566.002 MITRE: T1585.002 MITRE: T1204.001

A contract-signing lure landed in the inbox of the president of a specialty food distribution company, and it wore the name of a national food distributor, the kind of 25-year-old vendor that thousands of restaurants order from every week. The pretext was ordinary: Action Required, sign the contract. What makes the case worth a closer look is how little the attacker bothered to do to earn that trust. Not one authentication check passed. There was not even a DKIM signature to fail, because the message was never signed in the first place.

Most brand-impersonation attempts at least try to look authentic at the transport layer. This one did not. It bet everything on a familiar vendor name and an urgent verb, and that bet reached a VIP mailbox anyway.

The Spoof That Did Not Try

The From header used the distributor's genuine domain, a name registered back in 1998. But the message never touched any of that vendor's mail infrastructure. It originated from 51.89.54[.]13, a generic cloud hosting IP in Germany whose reverse DNS resolves to ip13.ip-51-89-54[.]eu, and it was actually routed through an unrelated throwaway domain, 2b77c4eef[.]info.

The authentication verdict was unambiguous. SPF returned softfail, because that German IP is not authorized to send for the distributor's domain. DKIM was absent entirely. DMARC failed. Microsoft's composite authentication logged compauth=none with reason=404. Every mechanism that exists to prove a sender is who it claims to be either failed outright or was never present, and the email still reached the recipient the attacker most wanted: the person with authority to sign a contract.

That is the uncomfortable part. Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and DMARC are inputs to a delivery decision, not a universal hard gate. When the wrapping infrastructure carries some reputation and no analyst-grade layer is reading intent, a message that fails every server-level check can still cross the threshold.

A Kit Held Together With Tape

The body itself gave away its origins. It was a garbled, multi-brand-stuffed template with fragments of unrelated content bleeding through the seams: Agilent product links and Korean-language kit artifacts that had no business appearing in a food-distribution contract notice. That mess is the signature of a recycled or rented phishing kit, reused across campaigns and never fully cleaned between runs.

For a defender, the sloppiness is a gift and a warning at once. A gift, because the leftover artifacts are a loud tell that the message is templated fraud. A warning, because the operator did not need a clean build to succeed. The kit only had to render a plausible Sign Contract button, and the rest of the deception rode on the spoofed brand and the recipient's habit of trusting a vendor name.

Microsoft SafeLinks, Turned Into a Delivery Vehicle

The single call to action was wrapped in a Microsoft SafeLinks URL. SafeLinks is the Defender for Office 365 feature that rewrites links so they can be re-checked at click time, and its presence in a message reads as a reassuring sign that the mail passed through a Microsoft-protected tenant. Here it did the opposite of reassure. The wrapper decoded to a form hosted on forms.monday[.]com, the legitimate work-management platform.

Rather than register a lookalike domain and stand up its own credential page, the attacker pointed the lure at a real monday.com form and let it serve as the contract-signing and credential harvesting trap. The destination inherited monday.com's reputation and a valid TLS certificate, so a link-reputation check had nothing obvious to flag. Abusing trusted software as a service this way is now standard tradecraft: the Microsoft Digital Defense Report 2024 documents the same shift toward riding legitimate services instead of breaking them.

See Your Risk: Calculate how many threats your SEG is missing

Mapping to MITRE ATT&CK

The tradecraft maps cleanly to a few techniques in the MITRE ATT&CK framework:

  • T1566.002 Spearphishing Link covers the core delivery: a socially engineered contract lure whose payload is a wrapped link to a hosted form.
  • T1585.002 Establish Accounts: Email Accounts covers the throwaway sending domain and cloud host stood up to spray the kit.
  • T1204.001 User Execution: Malicious Link covers the final step, where the recipient clicks through to the monday.com form.

Indicators of Compromise

IndicatorTypeNotes
2b77c4eef[.]infoSending domainThrowaway domain used to relay the spoof masquerading as the distributor
51.89.54[.]13Sending IPGeneric cloud host in Germany, ip13.ip-51-89-54[.]eu, unauthorized for the spoofed brand per SPF
hxxps://forms.monday[.]com/forms/69358e965d66c431f48542cd429e5a83?r=use1Landing formSafeLinks-wrapped CTA hosting the contract-signing credential trap on legitimate SaaS
donotreply@[distributor-domain]Spoofed FromReal brand domain in the header, with no valid authentication behind it

What Actually Catches This

Signature and reputation tooling was never going to be the hero here. The final destination sits on a legitimate SaaS platform, the link arrived pre-wrapped by Microsoft, and there is no attachment or malware to fingerprint. The signals that matter are relational: a header From on a real vendor's domain that carries no SPF, DKIM, or DMARC support, a body stuffed with brand fragments that do not belong together, and a trusted-brand button that resolves to a generic form rather than that brand's own site.

That is the gap augmenting Microsoft 365 with behavioral analysis is built to close. Themis, the Adaptive AI analyst on the IRONSCALES platform, weighs the claimed brand against the actual sending path, the kit tells in the body, and the mismatch between the vendor name and the form it points to, the way a trained analyst would, and flags the impersonation even when every server-level verdict has already fired or, as here, failed. The 2024 Verizon Data Breach Investigations Report puts the human element in 68 percent of breaches, and the FBI's 2023 Internet Crime Report ranks business-identity and vendor impersonation among the costliest fraud categories reported that year. This case pulled exactly that lever, aimed at exactly the right person.

The Takeaway

A recognizable vendor name is a trust shortcut, and this attacker spent every other resource betting that the shortcut alone would work. It nearly did. The defense is to stop treating a familiar brand in the From field as proof of anything and to verify the path: authentication results, the true sending host, and where a button actually lands before anyone clicks. When a contract you did not expect asks you to sign through a link, the safe move is to confirm it through a channel you already trust, not the one that arrived unannounced. CISA's guidance on recognizing and stopping phishing early is a solid reference for building that reflex across a team: https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
The Procore Footer Was Real. The Document Was Not.Every link scanner called the Procore and ExxonMobil URLs clean.
A Pixel-Perfect Sephora Delivery Notice Shows Why Email Authentication Alone Can't Protect YouA fully authenticated Sephora delivery notification passed SPF, DKIM, and DMARC with perfect scores.
The Email That Passed Every Security Check (Because Adobe Sent It)A phishing campaign targeting school district staff used Adobe's own sending infrastructure, real DKIM signatures.
The Phishing Infrastructure Was Canva. The Delivery Mechanism Was Canva. The Authentication Was Canva.An attacker signed up for Canva, built a phishing lure as a design, and used the platform's own sharing feature to deliver it.
When the Sender Domain Is Also the Phishing Kit Host: Dual-Purpose Domain CompromiseAn attacker compromised a legitimate manufacturing company domain and used it two ways at once: as the authenticated sending address and as the host for...

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.