TL;DR An invoice-fraud email arrived from a real, decade-old Bermuda fintech domain with SPF, DKIM, and DMARC all passing cleanly, so conventional gateway logic saw nothing wrong. The tell was inside the template: the message signed off as an unrelated business-coaching franchise, and the footer still carried a Hong Kong ISP privacy-policy link left over from a previous campaign. The ask was a bare, urgency-only demand to settle a referenced invoice before the end of the day. Adaptive AI flagged it on a community-pattern signal alone, and a human analyst confirmed the fraud on the brand mismatch and the leftover link.
Severity: High Business-Email-Compromise Invoice-Fraud Credential-Abuse MITRE: T1566.001 MITRE: T1585

An invoice demand landed in the inbox of a US-based oncology treatment practice, and on paper it was flawless. The sending domain, hitch[.]bm, belonged to a real Bermuda-registered company that had been on the internet for the better part of a decade. SPF passed. DKIM passed. DMARC passed with an alignment reason of 100. To any gateway checking the technical envelope, this was a clean, authenticated message from an established business. The only thing wrong with it was everything the authentication could not see.

The ask was deliberately thin. There were no bank account numbers in the body, no payment portal, no wire instructions, and no attachment full of macros. Just a single PDF styled as an invoice, roughly 420KB, that static and antivirus scanning waved through as clean, paired with a bare, urgency-only demand to settle a referenced invoice number before the end of the day. Everything about the message was engineered to feel routine to a busy finance inbox and to give an automated filter nothing to grab onto.

Authentication that told the truth about the wrong thing

The reason this message authenticated so cleanly is also the reason it was dangerous. hitch[.]bm is not a domain an attacker registered last week to spoof a brand. It is a genuine, aged company domain, and the mail really did originate from that domain's own sending infrastructure. When the mail flow is legitimate, SPF, DKIM, and DMARC all align by design. The most likely explanation is that the sending capability behind that domain was abused or compromised, not that someone forged their way into looking like it.

This is the trap in trusting authentication as a verdict on trustworthiness. SPF, DKIM, and DMARC answer a narrow question: did this message come from where it claims to come from? They say nothing about whether the request inside is real. A compromised or abused legitimate account inherits all the reputation and all the passing checks of the real owner, which is exactly why account takeover is such a durable delivery method. Protecting the sending identity itself, through account takeover protection, matters precisely because a clean auth result is not a clean bill of health.

A signature block for a different brand

The first crack in the story was the signature. The message authenticated as the Bermuda company, but it signed off as a completely unrelated brand, a business-coaching franchise with no connection to the sender domain and no connection to an invoice for an oncology practice. Two different identities were stapled to the same email, and they could not both be genuine.

That contradiction is a fingerprint of a recycled phishing kit. Attackers running invoice fraud at volume do not hand-craft each message. They work from a template and swap in a fresh target, a fresh invoice number, and a fresh subject line, then fire it off. When they move fast, they forget things. Here they forgot to replace the signature block from a previous campaign, leaving the coaching franchise's branding sitting under a message it had nothing to do with.

The leftover link that gave it away

The second, more damning artifact was in the footer. Buried at the bottom of the HTML was a privacy-policy link pointing at hxxps://netvigator[.]com/en-en/privacy[.]html, the privacy page of a Hong Kong internet service provider. It was clean, it was harmless on its own, and it had absolutely no reason to be there. It matched neither the Bermuda sender domain nor the coaching franchise in the signature nor the oncology practice being targeted.

A leftover link like this is the digital equivalent of a receipt from a different store falling out of a repackaged box. It is template residue: HTML lifted from one campaign, dropped into another, and shipped without a full scrub. On its own the link was not an attack. As evidence, it was conclusive. Three unrelated identities in one email is not a coincidence, it is a reused kit.

A quiet payload by design

It is worth dwelling on how little the message actually contained, because the emptiness was the strategy. No bank details meant nothing for content filters to fingerprint. The clean PDF meant sandbox detonation found nothing to detonate. The whole message leaned on one pressure lever, a same-day deadline on a referenced invoice, betting that urgency plus a passing auth result plus a plausible-looking PDF would move a payment before anyone stopped to verify the vendor.

This is textbook business email compromise economics. The 2024 Verizon Data Breach Investigations Report puts the median transaction amount in a business email compromise incident at roughly $50,000, and it names pretexting, the social-engineering category that includes BEC, as the top social-engineering type of the year. The report also found the human element present in 68% of breaches. Attacks like this one are cheap to send and profitable to land, which is why disciplined business email compromise protection treats every unsolicited payment demand as unverified until confirmed through a channel outside email.

How the fraud was actually caught

None of the technical checks a legacy gateway relies on fired here. Authentication passed. The attachment scanned clean. There was no malicious link to blocklist and no known-bad domain to match. The case surfaced instead on a behavioral community-pattern signal, with the platform's Adaptive AI confidence sitting at only 50%, low enough that it read as a signal to escalate rather than an automatic verdict.

That escalation put the message in front of a human analyst, who confirmed the fraud on exactly the two tells no auth check could ever produce: the signature block for a brand unrelated to the sender, and the leftover Hong Kong ISP footer link exposing the recycled template. The message was manually approved as malicious not because of a signature match or an external blocklist, but because the story it told about itself did not hold together. Machine pattern-detection narrowed the field, and human judgment closed it, which is how you catch the attacks that are designed to pass every box a filter can tick.

Indicators of Compromise

IndicatorTypeNotes
hitch[.]bmSending domainReal, decade-old Bermuda company domain; sending capability abused or compromised, not attacker-registered
support[@]hitch[.]bmSender addressDisplay name "HITCH Support"; authenticated cleanly (SPF, DKIM, DMARC all pass)
hxxps://netvigator[.]com/en-en/privacy[.]htmlFooter linkLeftover Hong Kong ISP privacy-policy link; clean but unrelated to any party in the message, exposing the recycled kit
Invoice-themed PDF, ~420KBAttachmentStatic and AV scan clean; no bank or payment details in body
Business-coaching franchise brandingSignature blockImpersonated brand unrelated to the sending domain and the target

MITRE ATT&CK Mapping

TechniqueIDHow it showed up
Phishing: Spearphishing AttachmentT1566.001Invoice-themed PDF delivered as the lure alongside an urgency-only payment demand
Establish AccountsT1585Abuse of a legitimate, established company's own authenticated sending infrastructure

For a broader baseline on defending against attacks that start with a message like this one, CISA's phishing guidance on stopping the attack cycle is a useful reference, and the 2024 Verizon Data Breach Investigations Report documents just how often the human element, not a technical failure, is the way in.

See You Next Friday

Clean authentication is a starting point, not a conclusion. When a message passes every technical check but signs off as the wrong brand and carries a footer link from a company nobody in the conversation has heard of, the template is talking. The attackers here did the hard part, standing up authenticated delivery, and then gave themselves away on the easy part, forgetting to finish the cut-and-paste. Read the whole message, verify every payment demand off-channel, and remember that the residue an attacker leaves behind is often the clearest evidence you will get.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 36,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
eCheck Retrieval Fraud: url.emailprotection.link Rewrapping and DMARC Fail Under a p=reject PolicyA payment fraud email instructed recipients to expect an eCheck from noreply@vitesse.io, with retrieval links rewritten through url.emailprotection.link.
The Security Tool That Delivered the $48,500 Invoice FraudA $48,500 invoice fraud routed through a Votiro email sanitization relay, which paradoxically introduced an SPF softfail.
Gateway-Rewritten Links Flagged Malicious Inside a Law Firm Email With No DKIMA professional email with legal contract language arrived from a long-established law firm domain with no DKIM signature and DMARC p=none.
Accounts Payable Display-Name Spoof Delivers a Teams-Branded Payment Lure to a CFO via SendGridAttackers registered astevenltd.com, set the From display name to an Accounts Payable identity.
BEC Wire Diversion via Compromised Authenticated Vendor: PDF Bank Instructions From a Domain That Passed DKIM and DMARCA payment-diversion BEC attack arrived from an authenticated cold-chain logistics vendor domain that passed DKIM, DMARC, and composite auth.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.