Table of Contents
The landing page rendered the retailer's own storefront. Working search bar, "Shop by department", log in and register links, the loyalty card in the header, a live product carousel underneath. Over the top of it sat a centred white modal: "Welcome. You have been selected to participate in our customer satisfaction survey", a set of five best-selling skincare products from a named sponsor, one button reading "Start survey".
The email that led there impersonated a major UK high-street pharmacy chain. It arrived at the generic info@ inbox of a UK fresh-produce import and wholesale business on 14 February 2026. And it authenticated: spf=pass, dkim=pass, dmarc=pass, compauth=pass reason=100.
None of those passes were forged. That is the part worth sitting with.
Christmas gift sets on an email sent 14 February
The tell is in the background, not the modal.
Behind the survey prompt, the replica storefront was still merchandising the holidays. A ten-pound Tuesday promotion with stocking fillers. Electrical price drops. Fragrance gift sets. A free shimmer face palette from the brand's own cosmetics line. All of it on a page reached from a message delivered on 14 February.
Whether that storefront was framed live from the brand's site or served from a saved copy was not established. What the capture shows is that the content was not current. Somebody built this page, and then time moved on without it.
That is a useful class of indicator because it survives the things attackers are good at. Kit authors can copy markup byte for byte, mirror the CSS, keep the search box functional. Freshness is harder. A replica ages against the real site every day it stays up, and seasonal retail merchandising ages loudly.
The body of the lure was equally careful in the places that are easy. Navy brand header, the wordmark, "We'd love your feedback", a promise of a free gift for completing a short survey, a copyright line naming the retailer's UK entity and a closing note that the message was sent to a registered customer. Exactly one link. No attachment, no QR code, nothing for a scanner to detonate. This is T1566.002 in its plainest form.
It also echoed the recipient's own mailbox address back at them, presented as a "Customer login ID". A cheap trick, and an effective one, because it makes a bulk send read like an account record.
Every check passed, because the domain was real
Here is the authentication chain as the recipient gateway recorded it.
The From header carried the retailer's brand as a display name over a mailbox on a consumer ISP's own domain, with a local part built to look like a rewards programme. SPF passed, designating the ISP's outbound relay. DKIM passed with a verified signature, and the signing domain was that same ISP domain. DMARC passed with action=none, aligned on the header From. The composite authentication check returned pass with reason=100, its highest-confidence verdict.
Nothing here is a bypass. The sending domain genuinely belonged to the organization whose infrastructure sent the mail, and that infrastructure genuinely signed it. DMARC is working exactly as designed, and the design has a boundary: it tells you a message is authorised to use a domain. It does not tell you who wrote it.
The originating hop is where that boundary gets uncomfortable. The message was submitted to the ISP's mail platform from a residential dynamic broadband address on the ISP's own consumer network, with a PTR record announcing exactly that. The ISP's own authentication results for that internal hop recorded the client address as a permitted sender and passed it forward. A consumer broadband client authenticated to its provider's relay, and the provider DKIM-signed the result.
Who that client was cannot be established from the record. A dynamic-IP customer authenticating to their own ISP relay is equally consistent with a compromised residential account, a throwaway signup, or an onward relay accepting mail it should not. The verifiable finding is narrower and more useful: an aligned pass says nothing about who typed the message.
See Your Risk: Calculate how many threats your SEG is missing
What the mail flow did, and what it did not explain
The recipient's spam stack scored the message SCL:-1 with SFV:SKN, and the affected mailbox record shows "No Action Taken" on delivery.
SFV:SKN means the message was marked non-spam before filtering ran. That state comes from an allow-list entry or a mail flow rule on the recipient side, not from anything the sender did. Why filtering was skipped on this message was not determined, and it should not be read as a consequence of the authentication results above. Two separate observations, reported separately.
The platform's own sender record rated this sender risk_level high. It was a first-time sender, and the sender-to-organization flag was false, meaning nobody else in the tenant had ever received mail from that address. The recipient's gateway did stamp the body with its external-sender caution banner, which is the recipient's own control firing, not part of the lure. A banner appeared. A filter did not.
Those are the signals a checker cannot produce, and they are what Adaptive AI is built to read: a sender scored against an organization's real communication history instead of against a list. The incident was automatically resolved as phishing, with no human verdict on file.
Why the numbers keep pointing at the same gap
Phishing accounts for 16% of breaches as an initial access vector in the 2026 Verizon Data Breach Investigations Report, unchanged year over year, and 62% of breaches involve the human element, up from 60%. Figure 54 of the same report puts plain phishing at 80% of the attack mix reaching email gateways, against 10% malware-laden, 5% callback and 3% BEC (business email compromise). The volume is not in exotic payloads. It is in messages like this one.
The Microsoft Digital Defense Report 2024 documents the same shift toward identity-shaped attacks over malware, and CISA guidance is blunt that authentication controls address spoofing, not impersonation. The FBI IC3 2024 report counts phishing as the most-reported complaint type by volume for the year. IRONSCALES platform data across 36,000+ security professionals and 18,000+ organizations puts 67.5 phishing emails per 100 mailboxes each month.
Indicators
| Type | Indicator | Context |
|---|---|---|
| URL | hxxps://mygalle[.]s3[.]dualstack[.]us-east-1[.]amazonaws[.]com/0[.]html | Public object serving a replica retailer storefront behind a survey modal. Scanner status "Mixed Result" |
| Sender local part | customers-online-rewards-program@ | Rewards-programme local part on an unrelated consumer ISP domain, under a retail brand display name |
| Header | dmarc=pass action=none with compauth=pass reason=100 | Fully aligned. The display name is the only forged identity |
| Header | SCL:-1 with SFV:SKN | Marked non-spam before filtering ran, from a recipient-side allow-list or mail flow rule |
| Subject pattern | Event Rewards Survey (From | Reference number lends the appearance of an account record |
| Body artifact | Recipient mailbox echoed as "Customer login ID" | Makes a bulk send read as personalised |
The part that does not scale
Filtering that leans on alignment will keep passing messages like this, because the alignment is real. The retailer whose storefront was copied did nothing wrong, and neither did the brand named as prize sponsor. Both are victims of the impersonation.
What breaks the message is the pairing a checker never sees: a consumer brand in the display name over a mailbox that has no relationship to that brand, sent to an organization that has never heard from it, pointing at a page still merchandising Christmas in the middle of February.
Read the identity, not just the signature.
Related attacks
| Attack | What happened |
|---|---|
| The B2B Content Marketing Email That Borrowed a Brand, a Relay Allow-List, and a Security Vendor's Own URL Wrapper | A polished B2B research report offer used SelectHub branding, passed through an allow-listed mail relay at SCL -1. |
| When the SharePoint Notification Is Real But the Share Is the Attack | A file-sharing notification arrived from what looked like a vendor contact. |
| SAM.gov CAGE Code Scam Passes Every Auth Check | A fee-solicitation scam impersonated a mandatory SAM.gov registration requirement, put the target's real CAGE code in the subject line, and passed SPF. |
| A Carrier-Registry Phish With a Browser's CSS Pasted In | Thirteen paragraphs of this carrier-registry lure still carried a browser's computed-style dump under a foreign markdown-renderer class name. |
| Every Link Was Real: DocuSign Reply-To Diversion With a Same-Day Domain | A phishing email sent through legitimate DocuSign infrastructure passed SPF, DKIM, and DMARC with perfect scores. |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.