TL;DR A salary and bonus review notice landed in mailboxes at a global technology company with SPF passing, DKIM passing against two selectors, DMARC passing on the header From and Microsoft composite authentication scoring it 100. None of that was forged. The message was delivered through a major North American retailer's own marketing cloud sending platform, an unrelated third party abused as a delivery service. The display name showed a payroll brand, the footer signed off as the recipients' own benefits team, and the single button resolved to a credential page registered days before the send.
Severity: High Credential-Harvesting Trusted-Infrastructure-Abuse Brand-Impersonation MITRE: T1566.002 MITRE: T1684.001 MITRE: T1583.001

A compensation notice reached mailboxes at a global technology company and answered every identity question correctly. SPF passed. DKIM passed against two separate selectors. DMARC passed on the header From. Microsoft composite authentication scored the message 100 and stamped it as a pass. There was nothing forged anywhere in the envelope, and no authentication failure for a gateway to act on.

The reason is straightforward and uncomfortable. The message went out through a major North American retailer's own bulk-mail sending platform, a Salesforce Marketing Cloud tenant operated in that retailer's name. The infrastructure was real, the signatures were real, and the sending reputation behind them was earned over years of legitimate retail campaigns. The content had nothing to do with that retailer at all. It was an internal-looking salary and bonus review addressed to employees of a completely different company.

Every Authentication Check Passed, Legitimately

Authentication answered in the retailer's name, not the attacker's. SPF passed against a sending host inside the retailer's own outbound mail infrastructure. DKIM produced two valid signatures, one from the retailer's bulk-mail domain and one from the marketing cloud platform's shared signing domain using a standard feedback-loop selector. DMARC evaluated the header From against those signatures and returned a pass.

That last verdict deserves a closer look, because it is easy to read as protection. The policy published on the sending domain was set to none. Even if alignment had failed, no enforcement was available. A DMARC pass reports that the visible sender matches a domain that cryptographically claims the message. It reports nothing about whether the content belongs to that sender. The published specification in RFC 7489 is precise about this scope, and this message sat exactly inside the gap it leaves open.

A Payroll Brand in the Display Name, a Retailer in the Envelope

The display name shown to recipients was rendered as an ADP notifications address, borrowing a payroll platform that employees genuinely expect compensation mail from. The actual envelope sender was an account alias on the retailer's bulk-mail domain. Two unrelated organizations, one in the part of the header a person reads and one in the part a filter checks, and neither of them the company whose benefits team the message claimed to be.

The body reinforced the internal story with details an outsider should not have. It addressed the recipient by full name, described an annual merit increase and bonus as already decided, and signed off as a benefits support alias on the recipients' own apex domain. A single button carried the entire payload, described as a compensation and bonus view, and the message stated a hard expiry date to compress the decision. MITRE tracks this masquerade as impersonation, and its value here was not technical sophistication. It was that every element a recipient could check by eye agreed with every other element.

See Your Risk: Calculate how many threats your SEG is missing

The Click Path Ran Through Trusted Ground

The button did not point at anything suspicious on first inspection. It resolved first through a link protection rewrite, then through the retailer's own legitimate click-tracking host, a domain that scanners grade clean because it genuinely is clean. Reputation scoring at that hop returns the answer the attacker wants, since the hop belongs to a real retailer running real campaigns.

The destination behind the redirect was a separate domain built for one purpose, registered days before the send through a privacy-shielded registrar and fronted by a large content delivery network. Its name read as a generic employee HR portal, chosen to be plausible for any workforce rather than any particular one. Scanner analysis returned a malicious verdict, and community intelligence had already flagged the same domain in unrelated phishing incidents. A secondary shortlink in the message encoded the same chain. MITRE classifies the acquisition of purpose-built domains as infrastructure acquisition, and the interval between registration and use is the tell: infrastructure this fresh has no history to grade.

What Flagged It Anyway

Our Adaptive AI scored the message as credential theft against a high-value recipient at 64 percent confidence. The incident was approved manually rather than auto-resolved, and the malicious link verdict, the domain age and prior community intelligence all corroborate the classification. That confidence figure is worth sitting with. It is not a certainty, and it should not be, because nothing in the identity layer was wrong. The signal came from the relationship, not the reputation: a retailer's bulk-mail platform delivering internal compensation notices to a different company's staff is a pairing with no legitimate business explanation, whatever the signatures say.

That is the shape of the detection problem in credential harvesting generally. The 2024 Verizon Data Breach Investigations Report puts stolen credentials in 38 percent of breaches, the single most common initial action, with the human element a factor in 68 percent. Verizon also measured the median time to click a phishing link at 21 seconds and to submit data at 28 seconds. A message that authenticates cleanly and reads as internal payroll mail does not need to survive scrutiny for long.

The Control That Actually Applies

Blocking the sender is not the answer here, and blocking the retailer's platform would break legitimate mail for every organization that receives it. The durable controls are the ones that evaluate the message rather than its credentials. Sender relationship history establishes whether a bulk-mail platform has ever delivered internal HR content to this workforce before. Display name analysis catches a payroll brand presented over an unrelated signing domain. Destination analysis follows a redirect past the clean tracking hop to the domain that actually serves the page. And the newly registered final destination remains the strongest single indicator in the chain.

Both CISA and NIST frame phishing around deception of the recipient rather than compromise of the transport, which is precisely why an authentication pass is a weak safety signal. Trusted infrastructure abuse inverts the assumption that authentication is a filter. When the platform is real, authentication becomes a delivery advantage the attacker did not have to build.

Indicators of Compromise

TypeIndicatorContext
Domainemployee-hr-portal[.]comFinal credential-harvest landing page. Registered days before the send through a privacy-shielded registrar, name servers at a large content delivery network. Scanner verdict malicious, and previously flagged by community intelligence in unrelated incidents.
URLhxxps://lnk[.]ie/7C9YSSecondary shortlink call to action encoding the same redirect chain to the landing page.
Display namenotifications@adp[.]comPayroll brand rendered as the visible sender, unrelated to the domain that actually signed the message.
Signing domains1[.]y[.]mc[.]salesforce[.]com selector fbldkim1Shared marketing cloud feedback-loop signing domain producing the second valid DKIM signature.
Redirect host[retailer click-tracking subdomain, genericized]Legitimate click tracker belonging to the abused retailer, used to cloak the final destination. Scanner verdict clean. Bystander infrastructure, genericized here and listed for pattern recognition only.
Envelope senderaccount@[retailer bulk-mail domain, genericized]Real bulk-mail sending alias on the retailer's own platform. Passed SPF and DKIM and aligned for DMARC under a policy of none.
Lure themeAnnual salary and bonus review with a stated hard expirySingle-button compensation notice addressed by full name and signed as the recipients' own benefits support alias.

MITRE ATT&CK Mapping

TechniqueIDApplication
Phishing: Spearphishing LinkT1566.002Single hyperlink payload delivered as a compensation review button, routed through a legitimate tracking host to a credential-harvest page.
ImpersonationT1684.001Payroll brand in the display name plus a benefits support signature on the recipients' own apex domain, presented over unrelated authenticated infrastructure.
Acquire Infrastructure: DomainsT1583.001Generic employee HR portal domain registered days before the send through a privacy-shielded registrar, with no reputation history to grade.
Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
The Fireflies Meeting Recap That Never Happened: Dual-Brand Impersonation via Amazon SESA phishing campaign combined Fireflies.ai meeting recap templates with Microsoft Teams branding to target a financial controller.
The Law Firm Name That Used Invisible Characters to Pass AuthenticationA phishing email impersonating Alston & Bird LLP used homoglyph characters in the display name and rode Google Drive sharing infrastructure to pass SPF.
The Procore Footer Was Real. The Document Was Not.Every link scanner called the Procore and ExxonMobil URLs clean.
When 'Release from Quarantine' Is the AttackA fake quarantine digest weaponized email security workflows, embedding JWT tokens in 'Allow' and 'Manage' buttons while masking one link's true...
A Pixel-Perfect Sephora Delivery Notice Shows Why Email Authentication Alone Can't Protect YouA fully authenticated Sephora delivery notification passed SPF, DKIM, and DMARC with perfect scores.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.