Table of Contents
A phishing page told us where we were standing.
The link arrived in a message delivered on 15 May 2026 to a European aerospace and industrial engineering firm. Captured two days later, the destination served a plain French notice: "Ce service n'est pas accessible depuis votre localisation geographique." Underneath sat a panel with two labelled fields. "Pays detecte." "IP." The page had worked out where the request came from, decided that location was not welcome, and printed its finding back at the visitor.
The capture taken on the send date shows the same URL behaving differently: a dark page carrying the Credit Agricole logotype, headed "Verification de securite," demanding a code from a CAPTCHA image before anything else would load.
Every link verdict in the incident record reads Clean.
Two Captures, Two Days, Two Different Answers
Both pages were viewed directly and stored against the same incident. Neither is a page any bank serves. The landing domain, portail-client-mail[.]net, is not a Credit Agricole domain, and Credit Agricole is a bystander here: its brand and palette were copied without its involvement.
What we have is two observations and their dates. Whether the operator changed configuration between them, whether the kit varies per request, or whether the CAPTCHA page was only ever served inside a narrow geography, is not established, and we will not narrate an escalation we cannot prove.
What a Clean URL Verdict Actually Measures
Both responses are anti-analysis layers, one keyed on automation and one on location, and the request that arrived got back nothing to score either time. So nothing scored.
A URL verdict records the response one request received, at one moment, from one network position. It is not a property of the destination. When the destination chooses its own answer, the verdict describes the attacker's configuration, not the attacker's intent. The kit picked the answer. The inspection wrote it down.
That is why the geo-block capture matters. A geofence usually leaves no trace in the defender's evidence, because a bland error page is exactly what it is built to look like. This one annotated itself. It named the country it had refused and printed the address it had refused, which tells you the filtering was real and deliberate. A French block page, on a French bank lure, turning away a request that presented as German.
A Renewal Deadline Set for Tomorrow
The lure body is a purpose-built HTML template, not a reused thread. Its pretext is regulatory: "Action requise: Renouvellement de votre peripherique de confiance," framed as data protection under "directive DSP2," the French naming of the EU revised Payment Services Directive. PSD2 is real and public, which is what makes it serviceable.
Two details do the heavy lifting. The deadline: a message sent on 15 May says that from 16 May, any device not renewed will be blocked as a security measure. One day. And the reassurance: "Cette procedure de reconnaissance d'appareil ne necessite pas de changement de mot de passe." No password change needed. The lure pre-empts the one instinct that would have saved the recipient, then offers one button, "Renouveler mon appareil."
The page behind that button was CAPTCHA-gated when we captured it, and no credential form was recorded, so we will not describe one. Themis labelled the incident Credential Theft and the pretext agrees, but the harvesting step was never seen.
See Your Risk: Calculate how many threats your SEG is missing
The Sending Path Passed Everything, and That Is Not the Story
SPF passed. DKIM passed, with a real domain-authentication signature. DMARC and composite authentication passed too, at the true origin: one hop through an email service provider's own outbound infrastructure into Microsoft's Swiss datacenter, no forwarding, no relay.
All of that passed because it was true. The mail really was sent through a bulk-mail account belonging to a US technical college, an uninvolved bystander whose sending account was abused. How that account came to be used is not established: valid domain authentication proves only that the authentication exists and that this subuser sent the message.
We have covered hijacked sender domains and bulk-mail trust chains more than once, and the lesson holds: authentication answers "how did this reach the internet," never "is this true." The new thing sits at the other end of the link.
Three mailboxes were hit inside two and a half hours on 15 May, across two subject lines, each copy carrying a different invisible trailing character: a zero-width space, a soft hyphen, a Mongolian vowel separator. Deliberate evasion or template artifact is inferred; the effect is not. Subject strings that render identically but differ in bytes defeat exact-match rules, which is how one burst reads as three unrelated events. Microsoft scored it SCL 1, SFV NSPM, CAT NONE, BCL 0.
Indicators
| Type | Indicator | Context |
|---|---|---|
| Domain | portail-client-mail[.]net | Landing domain behind the tracked link; served both captured pages |
| URL | hxxps://portail-img-ca.s3.ap-south-1.amazonaws[.]com/image.jpg | Banner image on a bucket named for the impersonated brand |
| Page string | Pays detecte and IP labels under Service temporairement indisponible | Geo-block response printing the visitor's own location |
| Page string | Footer Cette verification protege contre les acces automatises | CAPTCHA gate ahead of the content |
| Page title | CA - Actualisation Mobile; CSS #00825E with #E30613 | Kit branding copied from the bank |
| Unicode | U+200B, U+00AD, U+180E | One invisible trailing character per subject |
The provider's outbound ranges and click-tracker hostnames belong to a legitimate service and a bystander customer, so they are deliberately absent.
What Caught It, and What to Change
Themis scored the incident at 88 confidence with a Credential Theft label, plus two community-reputation insights drawn from resolutions of similar incidents, and all three mailboxes are recorded as mitigated within seconds of delivery. Be precise about the basis, though: the state is automatically resolved as phishing, the reporter is automated threat detection, no human analyst verdict exists, and the sender history shows zero human safe verdicts and zero release requests. Confirmation rests on the two captured pages, which is why capturing them mattered.
So: stop treating a clean URL verdict as evidence of a safe destination. Treat it as one observation with a timestamp and a vantage point attached, re-inspect from other positions at other times, and preserve the response, not just the score. Then weigh credential harvesting signals from the mail itself, the pretext, the sender relationship, the community history, alongside the link verdict rather than under it. That is the design behind Adaptive AI and agentic analysis and behind URL inspection that reports what it saw.
The 2026 Verizon Data Breach Investigations Report puts phishing at 16% of breaches as initial access, credentials in 39%, the human element in 62%, and a gateway attack mix (Figure 54) of 80% plain phishing, 10% malware-laden, 5% callback, 3% BEC. Most of what a secure email gateway (SEG) blocks is this shape, and the technique is MITRE ATT&CK T1566.002. CISA and the Microsoft Digital Defense Report 2024 both track the drift toward identity-first attacks that pass every technical check, and NIST defines phishing around deceiving a person, which no URL scanner can measure. IRONSCALES platform data across 36,000+ security professionals in 18,000+ organizations puts the baseline at 67.5 phishing emails per 100 mailboxes monthly.
A kit that answers a scanner differently than it answers a target will always produce a clean verdict for the scanner. The only defensible response is to stop asking the link what the message is.
Related attacks
| Attack | What happened |
|---|---|
| The Procore Footer Was Real. The Document Was Not. | Every link scanner called the Procore and ExxonMobil URLs clean. |
| The Phishing Infrastructure Was Canva. The Delivery Mechanism Was Canva. The Authentication Was Canva. | An attacker signed up for Canva, built a phishing lure as a design, and used the platform's own sharing feature to deliver it. |
| How ARC Re-Signing and an IP Allow-List Turned Three Authentication Failures Into SCL -1 | A phishing email claiming to be a OneDrive share from an outlook.com address originated from a county government mail server. |
| Cloning the Defender: How Attackers Weaponized IRONSCALES Branding Against a Security Company's Own Inbox | Attackers cloned IRONSCALES visual branding and routed it through a compromised Brazilian professional domain via Amazon SES. |
| The Security Vendor That Broke the Evidence | A phishing email impersonating a SharePoint file share passed SPF and DMARC. |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.