TL;DR A general manager at a national in-home care services provider received an unbranded payment notice earlier this month. The sending domain had been registered in the late 1990s and its mail authenticated correctly on every mechanism, because the mailbox behind it belonged to a real property-management business and had stopped answering only to its owner. The single hyperlink was a Google Forms shortlink that resolved to a collection page on Google's own domain. Sender reputation, authentication and destination reputation all read favorably. Adaptive AI scored it credential theft at 83 percent on content and behavior alone.
Severity: High Credential-Harvesting Account-Takeover Platform-Abuse Payment-Fraud-Lure MITRE: T1566.002 MITRE: T1598.003 MITRE: T1078

A general manager at a national in-home care services provider opened a payment notice earlier this month that had no logo, no attachment, and no brand to accuse of anything. The body was a plain bordered table headed as a payment notification, announcing that a debit request had been settled. Underneath sat a customer identifier, a paid date, a billing memo reading BILLPAY, and a check and draft reference number. There was no dollar amount. There was one hyperlink, labeled as a way to view the transaction details.

That link resolved to a form hosted on Google. The message that carried it came from a business domain registered in the late 1990s, more than twenty-nine years before the send, and every authentication mechanism the receiving side checked returned a pass. Both ends of this chain were reputable assets. That is the whole reason it is worth taking apart.

Both Ends of the Chain Belonged to Someone Legitimate

Most teardowns have an artifact at the center of them: a domain registered last week, a homoglyph in a brand name, a macro-bearing attachment, a broken alignment check. This one has none. There was no lookalike domain, because the sending domain was real and old. There was no impersonated brand, because nothing in the message claimed to be anyone. There was no attachment to analyze, because none was sent. And there was no authentication failure, because the mail genuinely came from the infrastructure it claimed to.

At the recipient's mail system, the sealed authentication results recorded a DKIM pass signed by the sending domain with an ordinary selector, an SPF pass on the envelope sender, a DMARC pass under a published quarantine policy covering both the domain and its subdomains, and an intact chain of custody across the relays. An earlier internal hop, captured before the sending tenant applied its signature, shows no signature and no policy evaluation. That earlier line is a snapshot of a message in transit, not a verdict, and reading it as one inverts the finding. The results the recipient's own mail system produced are the authoritative ones, and they were clean.

They were clean because the mailbox was real. The sending domain belongs to a property-management business, its registration predates most of the tooling that would evaluate it, and it had accumulated decades of ordinary sending history. An operator working from inside that mailbox does not have to defeat the identity layer. It inherits it, along with everything the domain has earned. The account takeover is the technique, and clean authentication is not evidence against it. Clean authentication is a downstream consequence of it.

The Destination Was a Form on Google's Own Domain

The single call to action was a Google Forms shortlink that redirected to a form view page on Google's document platform. Data collection was offloaded entirely to that page. Whatever the form asked for, it asked from inside infrastructure no organization can plausibly block and no reputation service will score badly.

The scan results split in a way worth noticing. The shortlink itself returned a mixed result with a partial verdict, which is what a redirect with unknown intent behind it earns. The resolved page scored clean, because it genuinely was a page on Google's domain. So the accurate statement is not that every check came back clean. It is that there was no infrastructure or reputation signal in either direction. The shortener produced ambiguity and the destination produced approval, and neither produced a blockable artifact. MITRE tracks this pattern both as a spearphishing link for access and as a link used to solicit information directly, and the abused hosting platform is a bystander in both readings.

See Your Risk: Calculate how many threats your SEG is missing

The Notice Was Built Out of Fabricated Specifics

Look at what the body actually contained. A customer identifier. A paid date matching the day of the send. A memo field reading BILLPAY, the kind of string that appears on a real bank statement. A draft reference number formatted as though a system had issued it. Precise-looking fields arranged to imply a transaction had already happened.

The fabrication is visible without resolving anything, because the notice contradicts itself. The subject line cites one reference number and the body table cites a different one. A real billing system does not disagree with its own subject line about which transaction it is reporting. Two reference numbers for one payment is the seam in the template.

The one field a genuine payment settlement notice would always carry is the amount, and the amount is missing. That absence is the mechanism. A recipient who processes vendor payments cannot resolve a settled debit with no total attached without going somewhere to look, and the only place to go was the link. The lure does not need a brand when it can manufacture a question.

The headers carry one more shape worth reading. The visible sender and the visible recipient were the same address, the sender's own, while actual delivery went to the general manager's mailbox. A message addressed to its own sender and delivered elsewhere is a blind-copied blast, not correspondence. Whoever was operating in that mailbox was working a list.

The Signal Came From the Message, Not Its Metadata

Nothing in the infrastructure was going to raise this. Themis, our Adaptive AI analyst, scored it credential theft at 83 percent confidence and additionally tagged it as reaching a high-value recipient. That score came from content and behavior: the transaction link was assessed as malicious, the wording and structure of the notice matched financial-pretext patterns, and the sender had never corresponded with this mailbox before. Community resolution history from similar incidents across the network agreed with high confidence. The incident was automatically resolved as phishing with one mailbox affected.

This is what detection looks like when there are no indicators to trade. The 2026 Verizon Data Breach Investigations Report puts the human element in 62 percent of breaches, phishing as the initial access vector in 16 percent, and credentials somewhere in the chain of 39 percent. The 2025 FBI IC3 Annual Report recorded 3.05 billion dollars in reported business email compromise losses inside a total of 20.877 billion dollars. Those losses are not concentrated in exotic payloads. They accumulate through messages that look like ordinary business correspondence, which is exactly what an authenticated notice from a decades-old domain is.

What This Changes About a Clean Verdict

Three habits get contradicted here at once. A well-aged sending domain is treated as reassuring, and this one was twenty-nine years old and compromised. Aligned authentication is treated as a trust signal, and here it was a faithful report about a hijacked account. A recognizable destination domain is treated as safe, and here it was Google hosting the collection page.

Every one of those checks asks who owns an asset. None asks who is operating it right now, or what for. Defenses that model sender relationships, flag first-time correspondents, read financial pretexts in the body, and make reporting frictionless are the ones with anything left to grade. Both CISA and NIST frame phishing as a deception problem rather than an artifact problem, and this case is the argument for why that framing matters. Guarding against credential harvesting that runs on borrowed reputation at one end and borrowed hosting at the other means grading the message, because the message was the only thing the attacker actually made.

Indicators of Compromise

TypeIndicatorContext
URL (shortlink)hxxps://forms[.]gle/QDJimBkA57HZQQyf8Attacker-created Google Forms shortlink, the sole call to action in the message; scored mixed result with a partial verdict
URL (landing page)hxxps://docs[.]google[.]com/forms/d/e/1FAIpQLScp3J6kRwofRlwaWC8hDG7v0vCAjZUoYwiq1A4GopJtR29-1g/viewformAttacker-created form instance on Google's own domain, functioning as the data-collection endpoint; scored clean
Body artifactBordered plain-text table headed as a payment notificationUnbranded lure body announcing that a debit request had been settled
Body artifactLink text reading "VIEW TRANSACTION DETAILS"Single hyperlink in the message, the only interactive element
Lure fieldCustomer ID 35355568Identifier in the notice body lending the fabricated transaction specificity
Fabricated fieldCheck and draft reference D194000Body reference number; does not match the different reference number cited in the subject line, an internal contradiction in the notice
Lure fieldMemo value BILLPAYStatement-style memo string typical of real bank remittance notices
Header patternVisible sender and visible recipient identical, actual delivery elsewhereSelf-addressed header consistent with a blind-copied blast from a hijacked mailbox
BehavioralFirst-time sender to the affected mailboxNo prior correspondence history despite the transactional framing
Auth resultSPF pass, DKIM pass with an aligned signing domain, DMARC pass under a quarantine policy, sealed chain intactGenuine aligned authentication produced by a real, compromised sending tenant
DetectionAdaptive AI credential-theft classification at 83 percent, high-value-recipient labelVerdict derived from content and behavior, with no adverse infrastructure signal available

MITRE ATT&CK Mapping

TechniqueIDApplication
Phishing: Spearphishing LinkT1566.002A single hyperlink was the entire delivery mechanism, with no attachment and no embedded payload
Phishing for Information: Spearphishing LinkT1598.003The link led to a form whose only function was to collect what the recipient typed into it
Valid AccountsT1078Sending from a legitimate, established mailbox inherited that domain's authentication and reputation rather than bypassing it
Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
When SPF, DKIM, and DMARC All Pass. And the Email Is Still PhishingA fully authenticated phishing email (SPF pass, DKIM pass, DMARC pass) used a legitimate nonprofit platform to deliver credential-harvesting links with...
Perfect Authentication, Borrowed From a Real MailboxAn EFT payment lure passed SPF, DKIM and DMARC cleanly, carried a genuine corporate legal disclaimer, and came from a real utility employee's mailbox.
The Password Reset That Shipped Its Own API Key in a Shortened URLA phishing email weaponized Firebase's password-reset flow by embedding a live API key, one-time reset token.
The Encrypted Message That Opened in a Design Preview ToolA phishing email claimed to contain an encrypted message but directed recipients to a MagicPatterns design preview page instead of Microsoft's secure...
The Insurance Claim That Passed Every Check (Progressive's Own Infrastructure Sent It)A credential theft attempt sent through Progressive Insurance's own Salesforce Marketing Cloud infrastructure.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.