Table of Contents
The message that opened this case arrived at the chief financial officer of a regional financial services organization, and it contained no words. Its entire body was one inline image, referenced by content identifier and a little under 31 KB, with no clickable link anywhere in the message. The picture depicted a two-message internal conversation. At the top, a short note addressed to the finance chief by his first name and signed with his own manager's first name: the invoice is past due, coordinate payment today, and code it to professional fees, risk advisory. Beneath it, under a forwarded-message rule, a header block showed an accounts-receivable persona at a free consumer webmail address having sent a past due notice days earlier to the manager's real internal mailbox.
Neither of those two messages was ever sent. The platform holds no record of anything from the accounts-receivable persona to the manager, and nothing from the manager to the finance chief. Both hops were painted.
The Forgery Carried Its Own Chain of Custody
What makes this construction unusual is not that a thread was faked. It is that the fake was rendered as pixels and populated with a genuine internal reporting line. The picture named a real person at the organization, at his real internal address, positioned exactly where he sits in the hierarchy, one level above the target. It supplied a route by which the request supposedly arrived, an approver whose authority the recipient does not question, and a general-ledger coding instruction, pre-answering the two questions any accounts function asks about an unfamiliar invoice: who signed off, and where does it get booked.
Because all of that is a bitmap, there is nothing to compare against reality: no quoted header to inspect, no address to resolve, no sender field to check against the corporate directory. The only outward inconsistency lived in the envelope, where an external address at an attacker-controlled domain wore the manager's display name. The domain gave little away either: it sat behind a privacy service on mainstream cloud DNS, and it was not a freshly registered throwaway.
What the Attachments Were For
Two documents rode along. One was an invoice billing the organization tens of thousands of dollars for a cybersecurity architecture assessment and an enterprise risk governance framework, with wire and electronic transfer instructions, a beneficiary matching the vendor persona, and a bank identifier code naming a large US bank with no connection to the fraud. Its only working point of contact was a mailto at a free consumer webmail domain: no vendor website, no corporate domain, no telephone number.
The second was a filled and signed US tax identification form for the same vendor, carrying an office address and a nine-digit taxpayer number typed one character at a time into the boxed field. A web search finds no company matching the payee's name. The vendor, its number, its signature and the whole engagement were invented. Both documents are supporting props, and neither is where the persuasion happened.
Six Days of Nothing, Then the Victim Made It Real
Whoever built this worked fast on the day. The blank form had been downloaded and kept for about six months, then filled in and saved straight out of a browser's built-in PDF viewer, in the same minute the lure went out.
Then nothing happened for six days.
See Your Risk: Calculate how many threats your SEG is missing
On the evening of the sixth day, the finance chief acted on the picture. From his own authenticated mailbox he forwarded the whole thing internally, in his own voice, adding that he had just seen it and asking that the payment be expedited. Within four minutes, copies of that forward were sitting in two more internal mailboxes, one of them belonging to the very manager the image had impersonated.
That is what separates this from every fabricated-thread case we have taken apart. No mailbox was taken over. The attacker needed one person with signing influence to believe a drawing, and the victim's own send action converted an external forgery into internally originated mail from the most senior finance officer in the building. Defenders who reason that internal mail carries less risk had that assumption inverted in a single click. Attackers reuse identity, not infrastructure, which is why business email compromise defence has to model relationships rather than message content.
Why the Automated Read Pointed Away From the Real Threat
One note for anyone triaging a case like this from a scan report. The deep-inspection pass rated the harmless signed tax form the higher risk of the two documents, on the strength of an embedded executable signature and a supposedly malformed container. Neither holds up. The file contains exactly one coincidental two-byte signature inside a compressed stream, no executable header at all, and the pointer that would locate one reads thousands of times past the end of the file. The container is not obfuscated: it is the ordinary cross-reference-stream layout a browser writes when it saves a filled form, which a parser that only understands the older table format fails to read. Meanwhile the invoice carrying the wire instructions was rated lower.
Containment Had to Reach Inside the Tenant
No authentication story exists for either hop, because no raw headers were supplied with this case. That absence is the point: the hop that actually delivered this attack to its audience needed no authentication argument at all, since it originated inside the tenant from a real mailbox belonging to a real employee.
Detection here was human, late, and performed by the victim, who reported his own forward as an impersonation attempt the following day. Containment then had to work backwards into internally originated mail: all four copies across the three internal mailboxes were quarantined. That is the honest shape of the control that mattered, and why our Adaptive AI treats internal mail as in scope rather than trusted, and why the human element belongs inside the detection loop instead of alongside it. Pretexting, the category covering business email compromise, is the most common social-engineering pattern in the 2024 Verizon Data Breach Investigations Report, which puts the median transaction at roughly $50,000 and finds the human element in 68% of breaches. The FBI's 2023 Internet Crime Report records about $2.9 billion in reported losses of this kind.
The lesson is narrow. Approval is a process, not an artifact, and certainly not an image. Any payment instruction referencing an internal approver should be confirmed with that approver through a channel the message did not supply, as CISA guidance and the NIST definition of phishing both frame it. Here, one such call to a manager sitting one office away would have ended the attack before it was ever forwarded.
Indicators of Compromise
| Type | Indicator | Context |
|---|---|---|
| Domain | novacdn[.]net | Attacker-controlled sending domain, privacy-protected registration, mainstream cloud DNS, DNSSEC unsigned |
info@novacdn[.]net | Sending mailbox for the single external message, wearing the display name of the recipient's own manager | |
financedepartment@ at a free consumer webmail provider | Attacker-controlled local-part for the fabricated accounts-receivable persona; appears only inside the picture and as the invoice contact. The provider is abused infrastructure | |
| Content-ID | cid:msgbody@novacdn[.]net | Reference for the single inline image that constituted the entire external message body |
| File | message.png (31,009 bytes) | The rasterised forged internal approval. This is the payload |
| Hash (MD5) | b39e707a2a7009a6740df793a92f5e66 | message.png |
| Hash (SHA256) | 26454094a3bd699c4bcc329f21491b57cd8fb1e684dd894ba2376b198cfafcc8 | message.png |
| File | W_.pdf (37,252 bytes) | Flattened, signed tax identification form for the fabricated payee |
| Hash (MD5) | a04b950bb6fe6b65da2848b83e2a2fc6 | W_.pdf |
| Hash (SHA256) | 46bbbcaa360fd8e2902ce214948f6e99ec8b5db01a1129d3ff0801a67c52356b | W_.pdf |
| File | NCI12309914.pdf (66,891 bytes) | Fabricated wire and electronic transfer invoice |
| Hash (MD5) | 5f1489fa511ffc435c34169b4a87b6db | NCI12309914.pdf |
| Hash (SHA256) | 114053c51bbbda06e9a120f36525dd40056f32d20ccac5be09c233b12ebb055f | NCI12309914.pdf |
| Identifier | NCI12309914 | Fabricated invoice number, reused in the external subject line and inside the image |
MITRE ATT&CK Mapping
- T1566.001 Phishing: Spearphishing Attachment. Invoice and tax form sent to a single senior finance recipient.
- T1684.001 Impersonation. An external address wearing an internal manager's display name, with that manager's authority reproduced inside the image.
- T1583.001 Acquire Infrastructure: Domains. A privacy-registered domain on mainstream cloud DNS.
- T1036 Masquerading. A fabricated vendor persona, approval chain and forwarding header, presented as ordinary internal correspondence.
Related attacks
| Attack | What happened |
|---|---|
| The Reply-To Was One Letter Off: How a Typosquat Domain Turned a Gmail BEC Into a Payment Diversion | A Gmail-authenticated BEC used a typosquat Reply-To domain and a hidden HTML mailto mismatch to impersonate a steel distributor's credit manager. |
| The $47,320 Invoice That Came With a W-9 and a Personal Bank Account | A payment diversion attack bundled a $47,320 invoice with ACH/wire remittance instructions pointing to a personal bank account. |
| One Missing Letter, One Stolen Payment: A Reply-To Typosquat That Beat the Spam Score | A typosquatted Reply-To domain misspelled 'Missouri' as 'Missuori' to intercept invoice payments. |
| Past Due Invoice, Future Wire Fraud: How a BEC Campaign Passed Every Authentication Check | A BEC invoice diversion attack impersonated a known vendor contact through SendGrid, passed SPF/DKIM/DMARC. |
| The Graduation Sash Invoice That Every Security Check Approved | A $3,645 invoice for 55 custom graduation sashes arrived at a school district, sent through Shopify's legitimate email infrastructure. |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.