Table of Contents
The email announced itself as "QuickBooks Payment." Every routing header told a different story. The envelope-from and the Return-Path both resolved to messages-noreply[@]linkedin[.]com, LinkedIn's own outbound notification address. One brand in the display name, an entirely different brand in the plumbing.
This is cross-brand impersonation, and it is one of the more elegant sleights of hand we see. NIST defines phishing as tricking a target into revealing sensitive information or taking a harmful action by masquerading as a trustworthy entity, and here the masquerade runs two brands deep. Most impersonation borrows a single identity. This attacker stacked two, wrapping QuickBooks branding around a forged LinkedIn envelope, betting that a recipient would read the friendly sender name and never inspect what was underneath.
The target was the marketing communications team at a B2B manufacturer in the interiors-and-furnishings space. Four mailboxes received near-identical variants, so this was a spray, not a single spear. Nobody there does accounts payable, which makes the QuickBooks pretext an odd fit and hints that the attacker was working from a scraped list rather than real reconnaissance.
The Envelope Says LinkedIn, the Auth Says Forgery
Here is the part worth slowing down on. If this message had genuinely originated from LinkedIn's mail servers, LinkedIn's SPF record would have passed. It did not.
SPF returned a softfail for linkedin[.]com because the sending IP was not on LinkedIn's authorized list. DKIM was absent entirely. DMARC failed, and it failed against linkedin[.]com policy carrying an oreject action, meaning LinkedIn's own published record instructed receiving servers to reject any message that fails alignment.
Read that back. The attacker forged a LinkedIn envelope from infrastructure LinkedIn never authorized, and LinkedIn's own authentication stack correctly told the world to throw the message away. LinkedIn was not breached. Neither was Intuit. Both brands were abused from the outside. This is exactly the outcome a well-configured DMARC posture is supposed to produce.
And yet the email reached the inbox. It came through on a relay hop after the reject verdict was already on record. This is the core teaching point of the case: an authentication failure, even an explicit reject policy, is guidance that downstream mail infrastructure can honor or ignore. A verdict is not a wall. When the 2024 Verizon Data Breach Investigations Report names pretexting, largely business email compromise (BEC), as the top social-engineering incident type, this is the delivery reality underneath that statistic.
The sending IP, 188[.]125[.]36[.]243, geolocates to a static block in Poland, inconsistent with any LinkedIn or Intuit sending region. That single field alone contradicts both brands the message claimed to represent.
A Payment Confirmation That Asks For Nothing
The body is where the psychology lives. It rendered as a fully personalized QuickBooks payment notice: a vendor payment of 43,364 dollars, a specific invoice number, an authorization ID, and the recipient's own email address echoed back into the template. It looked like a real QuickBooks confirmation styled after Intuit's genuine QuickBooks Payments notices from quickbooks[@]notification[.]intuit[.]com.
Critically, it did not ask for credentials. It did not request a wire. It confirmed a transaction that never happened.
That restraint is the design. A confirmation-style pretext builds false confidence and normalizes the sender. The recipient is not asked to do anything risky, so the usual alarm bells stay quiet. The intended reaction is either a reply ("I don't recognize this payment, can you check?") that opens a conversation, or simple conditioning that makes a later, sharper ask feel routine. It is the patient front end of a fraud, not the fraud itself.
Nearly every link in the message was wrapped through a Mimecast redirect. Some of those hops resolve to legitimate Intuit legal and support pages, which is precisely what makes the wrapping useful cover. One host, track[.]m6web-tracking[.]com, is not documented Intuit infrastructure and looks like an engagement tracker. The notable evasion here is the redirect wrapping itself, which obscures the true destinations behind a trusted-looking gateway URL. We did not observe a confirmed credential-harvesting landing page in this case, and it would be wrong to claim one.
See Your Risk: Calculate how many threats your SEG is missing
Indicators of Compromise
| Type | Indicator | Context |
|---|---|---|
messages-noreply[@]linkedin[.]com | Forged envelope-from and Return-Path; display name "QuickBooks Payment" | |
| IP | 188[.]125[.]36[.]243 | Origin IP, static block in Poland; not authorized by LinkedIn or Intuit |
| URL | hxxps://url[.]us[.]m[.]mimecastprotect[.]com | Redirect wrapper on links tagged domain=elink.prd.intuit[.]com; some hops resolve to legitimate Intuit pages |
| Domain | track[.]m6web-tracking[.]com | Undocumented tracking host, not confirmed Intuit infrastructure |
| Reference | Invoice 40YH89OK868 / Auth ID QBMU0258793381 | Fabricated identifiers in the payment-confirmation body |
Mapping the Technique
The attack maps cleanly to three MITRE ATT&CK behaviors. It is Spearphishing Link (T1566.002) in delivery, since the payload is a set of wrapped URLs rather than an attachment. It is Masquerading through display-name impersonation (T1036.005), with the twist that the display name impersonates a different brand than the envelope domain. And it leans on Establish Accounts and abuse of a real platform's outbound identity (T1585), forging a linkedin.com envelope to launder reputation.
This is the gap SPF, DKIM, and DMARC cannot close on their own. All three authentication checks produced verdicts, and the message still arrived. What separates a caught message from a delivered one at that point is whether something models the relationship between sender identity and content.
That is where Themis, the IRONSCALES Adaptive AI, earns its place. Impersonation detection flagged the cross-brand mismatch directly: QuickBooks branding presenting on a LinkedIn envelope from a Polish IP is a pattern that does not match any legitimate sender the platform has ever seen for either brand. The signal was the mismatch itself, not the authentication result. IRONSCALES platform data shows SEGs (secure email gateways) miss an average of 67.5 phishing emails per 100 mailboxes each month, and cross-brand forgeries that technically fail auth but still deliver are exactly the kind that slip through a verdict-driven filter.
For manufacturers in particular, where vendor and invoice traffic is constant and finance-adjacent teams get targeted through side doors like marketing, email security built for manufacturing has to reason about sender identity, not just check a box on authentication headers. The 2024 Verizon report puts the median BEC transaction near 50,000 dollars, and a 43,364 dollar fake confirmation is squarely in that lane. CISA's phishing guidance and the Microsoft Digital Defense Report 2024 both underline the same shift: attackers increasingly abuse legitimate infrastructure and trusted brands rather than fighting to defeat authentication head-on.
Trust the Identity, Not the Verdict
The takeaway is compact. When a message fails authentication and still reaches a user, the authentication result has already told you everything it can. The decision that matters next is whether the sender identity, the envelope domain, and the branded content agree with each other. In this case they did not, and reading that disagreement is what caught the attack. Build detection that questions the identity behind the message, not just the checkmark in the header.
Related attacks
| Attack | What happened |
|---|---|
| Three Domains, One Scam: The RFQ That Routed Replies to a Freshly Built Lookalike | An RFQ email passed SPF, DKIM, and DMARC through one domain, impersonated a construction supplier through a second. |
| Barrick Gold Impersonation via Fabricated Lookalike Domains: Procurement Fraud Reaches a Banking Target | Attackers fabricated two lookalike domains for Barrick Gold and sent procurement solicitations from a consumer-ISP origin with no SPF, DKIM, or DMARC. |
| W-9 Exfiltration via a LinkedIn Lookalike Domain: When Your CDR Relay Breaks DMARC | An attacker impersonated a bank's own BSA officer by exact display name, used a freshly-registered .us sender domain. |
| CEO Impersonation via Gmail: The Channel-Switch BEC That Moves the Conversation Off Email | An attacker created a throwaway Gmail address bearing a cybersecurity CEO's name and targeted a channel manager with a single request: reply by text. |
| Take It to WhatsApp: The BEC Opener With No Money Ask | A free Gmail account posed as the CEO and asked one senior sales leader for a single thing: a WhatsApp number. |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.