TL;DR A European aerospace and industrial engineering firm received a French bank device-renewal lure sent through an abused US college mailing account. Two captures of the same destination, taken two days apart, show two different responses: a Credit Agricole-branded security-verification page behind a CAPTCHA, and a French geo-restriction notice that printed the visitor's own detected country back at it. Every link verdict in the record says Clean. That verdict recorded what the kit chose to show, not what the kit was. Themis flagged the mail anyway and all three copies were mitigated within seconds.
Severity: High Credential Harvesting Brand Impersonation MITRE: T1566.002

A phishing page told us where we were standing.

The link arrived in a message delivered on 15 May 2026 to a European aerospace and industrial engineering firm. Captured two days later, the destination served a plain French notice: "Ce service n'est pas accessible depuis votre localisation geographique." Underneath sat a panel with two labelled fields. "Pays detecte." "IP." The page had worked out where the request came from, decided that location was not welcome, and printed its finding back at the visitor.

The capture taken on the send date shows the same URL behaving differently: a dark page carrying the Credit Agricole logotype, headed "Verification de securite," demanding a code from a CAPTCHA image before anything else would load.

Every link verdict in the incident record reads Clean.

Two Captures, Two Days, Two Different Answers

Both pages were viewed directly and stored against the same incident. Neither is a page any bank serves. The landing domain, portail-client-mail[.]net, is not a Credit Agricole domain, and Credit Agricole is a bystander here: its brand and palette were copied without its involvement.

What we have is two observations and their dates. Whether the operator changed configuration between them, whether the kit varies per request, or whether the CAPTCHA page was only ever served inside a narrow geography, is not established, and we will not narrate an escalation we cannot prove.

What a Clean URL Verdict Actually Measures

Both responses are anti-analysis layers, one keyed on automation and one on location, and the request that arrived got back nothing to score either time. So nothing scored.

A URL verdict records the response one request received, at one moment, from one network position. It is not a property of the destination. When the destination chooses its own answer, the verdict describes the attacker's configuration, not the attacker's intent. The kit picked the answer. The inspection wrote it down.

That is why the geo-block capture matters. A geofence usually leaves no trace in the defender's evidence, because a bland error page is exactly what it is built to look like. This one annotated itself. It named the country it had refused and printed the address it had refused, which tells you the filtering was real and deliberate. A French block page, on a French bank lure, turning away a request that presented as German.

A Renewal Deadline Set for Tomorrow

The lure body is a purpose-built HTML template, not a reused thread. Its pretext is regulatory: "Action requise: Renouvellement de votre peripherique de confiance," framed as data protection under "directive DSP2," the French naming of the EU revised Payment Services Directive. PSD2 is real and public, which is what makes it serviceable.

Two details do the heavy lifting. The deadline: a message sent on 15 May says that from 16 May, any device not renewed will be blocked as a security measure. One day. And the reassurance: "Cette procedure de reconnaissance d'appareil ne necessite pas de changement de mot de passe." No password change needed. The lure pre-empts the one instinct that would have saved the recipient, then offers one button, "Renouveler mon appareil."

The page behind that button was CAPTCHA-gated when we captured it, and no credential form was recorded, so we will not describe one. Themis labelled the incident Credential Theft and the pretext agrees, but the harvesting step was never seen.

See Your Risk: Calculate how many threats your SEG is missing

The Sending Path Passed Everything, and That Is Not the Story

SPF passed. DKIM passed, with a real domain-authentication signature. DMARC and composite authentication passed too, at the true origin: one hop through an email service provider's own outbound infrastructure into Microsoft's Swiss datacenter, no forwarding, no relay.

All of that passed because it was true. The mail really was sent through a bulk-mail account belonging to a US technical college, an uninvolved bystander whose sending account was abused. How that account came to be used is not established: valid domain authentication proves only that the authentication exists and that this subuser sent the message.

We have covered hijacked sender domains and bulk-mail trust chains more than once, and the lesson holds: authentication answers "how did this reach the internet," never "is this true." The new thing sits at the other end of the link.

Three mailboxes were hit inside two and a half hours on 15 May, across two subject lines, each copy carrying a different invisible trailing character: a zero-width space, a soft hyphen, a Mongolian vowel separator. Deliberate evasion or template artifact is inferred; the effect is not. Subject strings that render identically but differ in bytes defeat exact-match rules, which is how one burst reads as three unrelated events. Microsoft scored it SCL 1, SFV NSPM, CAT NONE, BCL 0.

Indicators

TypeIndicatorContext
Domainportail-client-mail[.]netLanding domain behind the tracked link; served both captured pages
URLhxxps://portail-img-ca.s3.ap-south-1.amazonaws[.]com/image.jpgBanner image on a bucket named for the impersonated brand
Page stringPays detecte and IP labels under Service temporairement indisponibleGeo-block response printing the visitor's own location
Page stringFooter Cette verification protege contre les acces automatisesCAPTCHA gate ahead of the content
Page titleCA - Actualisation Mobile; CSS #00825E with #E30613Kit branding copied from the bank
UnicodeU+200B, U+00AD, U+180EOne invisible trailing character per subject

The provider's outbound ranges and click-tracker hostnames belong to a legitimate service and a bystander customer, so they are deliberately absent.

What Caught It, and What to Change

Themis scored the incident at 88 confidence with a Credential Theft label, plus two community-reputation insights drawn from resolutions of similar incidents, and all three mailboxes are recorded as mitigated within seconds of delivery. Be precise about the basis, though: the state is automatically resolved as phishing, the reporter is automated threat detection, no human analyst verdict exists, and the sender history shows zero human safe verdicts and zero release requests. Confirmation rests on the two captured pages, which is why capturing them mattered.

So: stop treating a clean URL verdict as evidence of a safe destination. Treat it as one observation with a timestamp and a vantage point attached, re-inspect from other positions at other times, and preserve the response, not just the score. Then weigh credential harvesting signals from the mail itself, the pretext, the sender relationship, the community history, alongside the link verdict rather than under it. That is the design behind Adaptive AI and agentic analysis and behind URL inspection that reports what it saw.

The 2026 Verizon Data Breach Investigations Report puts phishing at 16% of breaches as initial access, credentials in 39%, the human element in 62%, and a gateway attack mix (Figure 54) of 80% plain phishing, 10% malware-laden, 5% callback, 3% BEC. Most of what a secure email gateway (SEG) blocks is this shape, and the technique is MITRE ATT&CK T1566.002. CISA and the Microsoft Digital Defense Report 2024 both track the drift toward identity-first attacks that pass every technical check, and NIST defines phishing around deceiving a person, which no URL scanner can measure. IRONSCALES platform data across 36,000+ security professionals in 18,000+ organizations puts the baseline at 67.5 phishing emails per 100 mailboxes monthly.

A kit that answers a scanner differently than it answers a target will always produce a clean verdict for the scanner. The only defensible response is to stop asking the link what the message is.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
The Procore Footer Was Real. The Document Was Not.Every link scanner called the Procore and ExxonMobil URLs clean.
The Phishing Infrastructure Was Canva. The Delivery Mechanism Was Canva. The Authentication Was Canva.An attacker signed up for Canva, built a phishing lure as a design, and used the platform's own sharing feature to deliver it.
How ARC Re-Signing and an IP Allow-List Turned Three Authentication Failures Into SCL -1A phishing email claiming to be a OneDrive share from an outlook.com address originated from a county government mail server.
Cloning the Defender: How Attackers Weaponized IRONSCALES Branding Against a Security Company's Own InboxAttackers cloned IRONSCALES visual branding and routed it through a compromised Brazilian professional domain via Amazon SES.
The Security Vendor That Broke the EvidenceA phishing email impersonating a SharePoint file share passed SPF and DMARC.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.