TL;DR An email carrying the display name QuickBooks Support impersonated Intuit while its From address resolved to aceaccountings[.]com, an unaffiliated marketing domain registered in September 2023. Sent through the Mailercloud bulk platform, it passed SPF, DKIM, and DMARC on that domain, laundering a brand it has no tie to. A fabricated software discontinuation notice manufactured urgency, then a Schedule A Call Back button routed the reader to a Calendly booking page. The real social engineering waited on the phone call, a classic telephone-oriented attack delivery pattern.
Severity: Medium Brand Impersonation Callback Phishing Social Engineering MITRE: T1566 MITRE: T1566.002 MITRE: T1598 MITRE: T1656

Every authentication check on this email came back green. SPF passed. DKIM passed. DMARC passed. The From header read QuickBooks Support. And none of it meant what a reader would assume.

The sending domain, aceaccountings[.]com, was registered on September 6, 2023 and has no relationship to Intuit or QuickBooks of any kind. Reputation scans flagged it as a low-trust marketing domain. It authenticated itself perfectly, which is the entire trick. The message cleared the full SPF, DKIM, and DMARC gauntlet not by forging Intuit, but by proving its own identity while wearing a display name that pointed somewhere else.

There was no attachment. There was no credential-harvesting page. The email asked the reader to do exactly one thing: schedule a call.

A Clean Auth Record for a Domain That Is Not QuickBooks

The message was blasted through Mailercloud, a legitimate bulk-email platform, from the sending host mail.ov1002.mailecloud[.]com at IP 167[.]114[.]10[.]205. SPF passed on that address. DKIM signatures verified for both aceaccountings[.]com and the platform domain. DMARC passed with header.from=aceaccountings[.]com and an action of none.

That is a fully intact authentication chain, and it says nothing about the brand in the display name. Sender Policy Framework validates the server that sent the mail. DomainKeys Identified Mail validates that the body was not tampered with in transit. Neither one checks whether the domain has any authority to speak for QuickBooks. When the sending domain is unrelated to the brand being impersonated, a green DMARC verdict is authentication laundering: real cryptographic signatures wrapped around a lie about identity.

The lure leaned on manufactured urgency. Under a generic Dear QuickBooks User greeting sat a fabricated software discontinuation notice, a supposed end-of-life policy for QuickBooks Desktop that pressed the reader to act before a deadline. The body carried an embedded open-tracking pixel to confirm which recipients had viewed the message, then a single Schedule A Call Back button as the only meaningful call to action.

The Call Is the Payload

That button did not open a login page. It routed through a tracking link on the attacker-controlled subdomain mc.aceaccountings[.]com and landed on a Calendly booking page, calendly[.]com/specialist-advisors/book-qb-meeting. The reader was invited to book a slot with a QuickBooks specialist who does not exist.

This is the mechanic that makes the case worth studying. The email is not the attack. It is the doorway to the attack. The real social engineering waits on the phone call the victim schedules themselves, where a live operator walks them toward remote access, a payment, or a credential handover with no email artifact to inspect. Security teams know this pattern as telephone-oriented attack delivery, and it is a close cousin of vishing. Because the email contains no malicious link to a spoofed portal and no weaponized attachment, most signature and reputation engines have nothing to catch. The message was categorized as bulk mail and auto-quarantined to Junk, yet it kept returning across several mailboxes at a mid-size company over several days, each recipient another chance for one person to pick up the phone.

See Your Risk: Calculate how many threats your SEG is missing

The reason attackers keep reaching for the phone is simple economics of trust. The 2024 Verizon Data Breach Investigations Report puts the human element in 68 percent of breaches and names pretexting, most of it business email compromise, as the top social-engineering incident type, with a median transaction of roughly 50,000 dollars. The FBI's 2023 Internet Crime Report describes tech-support and call-center impersonation fraud among the costliest categories it tracks, which is precisely the endgame a QuickBooks-support callback is built to reach. The Microsoft Digital Defense Report 2024 documents the same broad shift toward abusing trusted services and legitimate infrastructure rather than breaking them.

Mapping to MITRE ATT&CK

The tradecraft lines up with a handful of techniques in the MITRE ATT&CK framework:

  • T1566 Phishing and T1566.002 Spearphishing Link cover the delivery, a socially engineered message whose CTA routes through a tracking link to an external booking page.
  • T1656 Impersonation covers the core deception, the QuickBooks Support display name standing in for a brand the sending domain has no connection to.
  • T1598 Phishing for Information covers the open-tracking pixel and the callback funnel itself, both designed to identify and qualify a live human target before the phone conversation begins.

Indicators of Compromise

TypeIndicatorContext
Domainaceaccountings[.]comImpersonation sender domain, registered Sep 6 2023, no Intuit or QuickBooks affiliation
Emailsupport@aceaccountings[.]comFrom and Reply-To address used for the QuickBooks Support impersonation
Domainmail.ov1002.mailecloud[.]comMailercloud bulk-send infrastructure, sending IP 167[.]114[.]10[.]205
URLhxxps://mc.aceaccountings[.]com/links/[token]/3372594Schedule A Call Back tracking link on attacker-controlled subdomain
URLhxxps://calendly[.]com/specialist-advisors/book-qb-meetingCalendly booking page where the victim schedules the callback

Detection and What to Watch For

Static gateways were always going to struggle here. The infrastructure is legitimate, the authentication is clean, and there is no link to a fake portal and no attachment to detonate. Detection has to move to behavior and intent. The signals that matter are a mainstream brand in the display name paired with a From domain that has no tie to it, a young sending domain riding a bulk marketing platform, an open-tracking pixel on a message that claims to be a support notice, and a call to action whose only destination is a scheduling page rather than the brand's real site.

This is where our Adaptive AI adds a layer that reputation checks miss. Themis, the analyst engine on the IRONSCALES platform, reads the relationship between the claimed brand, the actual sending domain, and the off-platform booking funnel the way a trained analyst would, and flags the impersonation even when every server-level check comes back green. That perspective is drawn from 36,000+ security professionals across 18,000+ organizations, the kind of cross-tenant visibility a single mailbox cannot see. CISA's guidance on stopping phishing at the recognition stage is a solid reference for building that reflex across a team: https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one

The Takeaway

A green DMARC pass is not a trust badge. It tells you a domain sent its own mail cleanly, nothing more, and an attacker who registers a throwaway domain can earn that pass in an afternoon. When the domain behind a familiar brand name is a stranger, and the only thing the message wants is for you to pick up the phone, the authentication result is the least interesting fact on the screen. Verify the sending domain against the brand it claims, treat unsolicited support deadlines as a pressure tactic, and confirm any account or software notice directly with the vendor before dialing a number an email handed you. Pairing that habit with behavioral detection is what closes the gap this campaign was built to exploit, and it is the same discipline that blunts business email compromise when the next impostor comes calling.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 36,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
McAfee Invoice Scam Weaponized a Google Calendar Invite 71 Minutes After Domain RegistrationA same-day registered domain abused Google Calendar invites to deliver a McAfee/Webroot invoice scam with a callback phone number.
The Partner Invite That Used the Wrong Sending DomainA calendar invite appeared to be from an IRONSCALES employee arranging an ANZ distribution call.
The Geek Squad Invoice With a Hidden Executable in the ImageA callback phishing attack delivered a fake Geek Squad invoice as an image with MZ/PE executable bytes embedded in the JPEG.
The Fake Invoice That Wasn't Even the Right File TypeA callback phishing attack used a PNG image disguised as a JPEG to deliver a fake Geek Squad invoice.
Salesforce Pardot Infrastructure Weaponized in Fabricated-Thread CRM Consulting PhishA phishing campaign abused Salesforce Pardot and ExactTarget infrastructure to deliver a fabricated-thread CRM consulting lure with full SPF, DKIM.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.