TL;DR A PDF attached to a fake internal payroll notice told the reader their compensation was approved for adjustment effective 2026-05-07 11:50:13, an effective date rendered to the second. The file's own creation timestamp was one second after that, and the message reached the gateway one second later again. The document's employee identification field and its document reference were both just the recipient's email address, the greeting used a shared mailbox name as if it were a person, and the exit instruction pointed at a verification code the platform never recovered. Four mailboxes at one organization, all quarantined.
Severity: High Impersonation Malicious Attachment Social Engineering MITRE: T1566.001

The PDF said the raise took effect at 2026-05-07 11:50:13.

Not that day. That second. A compensation adjustment, approved and effective to the second, printed twice in a two-page payroll notice: once in the body text as "your compensation has been approved for adjustment effective 2026-05-07 11:50:13", and once in a labelled field reading "EFFECTIVE DATE / 2026-05-07 11:50:13".

The file's own metadata gives it away. The stored copy carries a creation timestamp of D:20260507115014Z, one second after the effective time it announces. The message carrying it has a Date header of Thu, 7 May 2026 11:50:15 +0000, and the earliest transit hop logged the same second. The salary effective date was never a business fact. It was the generator's clock, caught mid-tick and pasted into a sentence about someone's pay.

Four mailboxes at a UAE-based food import and distribution group were hit inside about four minutes. All four messages were quarantined. The verdict that closed the case was human, not automated.

Two Seconds From Build To Inbox

MomentSourceValue
Stated compensation effective timePDF body text and EFFECTIVE DATE field2026-05-07 11:50:13
PDF creation timestamp/CreationDate in the attachmentD:20260507115014Z
Message timestampDate headerThu, 7 May 2026 11:50:15 +0000
Earliest transit hopFirst Received line11:50:15

That sequence belongs to the copy stored on the incident, and it is the whole argument. Nobody drafting a compensation letter produces the file one second after the moment it declares as effective. A per-recipient generator does, because both values come from the same call to the system clock.

The stored copy was personalized to one mailbox. The substitution pattern makes it likely the others were too, but only that one attachment was retained, so that is as far as the evidence goes.

One note on what is absent from this post. The visible body of the message was a verbatim internal email thread lifted from an unrelated organization and used as padding, so nothing here describes what the lure said. The lure had no writing of its own. The attachment is the story.

The Merge Fields Never Filled

Once the clock is visible, the rest of the template stops hiding.

The field labelled "EMPLOYEE IDENTIFICATION" holds the recipient's email address. So does "DOCUMENT REFERENCE", which prints the string COMP-2026- with that same address appended. "PROCESSING DEPARTMENT" names the victim organization's own human resources function. The greeting is the word "Dear" followed by the mailbox local part, which in this case belongs to a shared branch inbox rather than to a person, and the confidentiality notice repeats that same local part in capitals as the sole intended recipient.

Then there is the stray quotation mark. A lone unmatched double-quote sits on its own line in the extracted text, exactly where a merge field resolved to nothing and left its punctuation behind.

None of this is obfuscation. It is a document assembled by a script with one input, the recipient address, spent everywhere a human identity was supposed to go.

An Exit Instruction With Nothing To Exit Through

The closing move is quotable in full: "To finalize this compensation update, please review and electronically sign the secure documentation by scanning the verification code below." Above it sits the reassurance "Secure Encrypted Connection". A heading reads "Electronic Acknowledgment Required".

The instruction is verified. The code is not. Analysis of the raw bytes found zero /URI link annotations, no /JS, no /OpenAction and no /AA, and the platform recovered no code and no destination from the file. What can be said is narrower than a payload claim: the document tells the reader to finish the transaction with a camera, and the far end of that hop was never recorded by anything in the mail path.

That is the design. Move the target onto a device the email security stack does not inspect, and the message you actually sent stays empty.

Fully Readable, And Still Clean

This attachment was not opaque. Its fonts carry ToUnicode maps and text extraction recovers 1,375 characters cleanly. It is a two-page PDF 1.4 with 73 streams and 26 image objects, produced by a toolchain whose /Producer string reads Qt 4.8.7, consistent with an HTML-to-PDF converter of the wkhtmltopdf family. The platform scan verdict was clean, and that verdict was correct. Nothing in the file executes.

Payload-oriented inspection is simply the wrong instrument here. The 2026 Verizon Data Breach Investigations Report puts the email gateway attack mix at 80% plain phishing, 10% malware-laden, 5% callback, and 3% business email compromise, or BEC (Figure 54). Phishing is the initial access vector in 16% of breaches, and 62% of breaches involve the human element. A secure email gateway, or SEG, built to adjudicate attachments and links has nothing to adjudicate in a two-page document that contains neither.

See Your Risk: Calculate how many threats your SEG is missing

The same report notes that AI-assisted text in malicious email doubled year over year while the techniques themselves stayed familiar. That is what this document is. Cheap generation at volume, with the assembly seams left in.

A Rejected Message That Came Back Signed

The delivery path gets one paragraph. The pattern where a message passes DMARC at the final hop while its ARC chain fails earlier already has a full teardown in this series, and this case is a second sighting rather than a new argument.

As recorded, the true origin hop produced spf=fail, dkim=none and dmarc=fail with action=oreject, and those results are preserved in the first ARC authentication results set. The message then left a Microsoft-hosted tenant outbound path that DKIM-signed it, and the recipient gateway read spf=pass, dkim=pass, dmarc=pass and compauth=pass with reason 100. Microsoft's own ARC validation reported the chain broken, with cv=fail on the second seal and arc=fail (48). Whether any domain or tenant on that path was compromised is not established, and the lesson holds without it: the full pass described the last hop, not the message's history. DMARC monitoring tells you what your own domain is doing, and treating inbound authentication as a single verdict is how a rejected message arrives trusted.

Indicators

TypeIndicatorContext
Document stringEFFECTIVE DATE / 2026-05-07 11:50:13Stated salary effective date, rendered to the second
PDF metadata/CreationDate D:20260507115014ZFile built one second after its own stated effective time
PDF metadata/Producer (UTF-16BE) Qt 4.8.7Consistent with an HTML-to-PDF converter of the wkhtmltopdf family
Document patternCOMP-2026- plus the recipient email addressDOCUMENT REFERENCE field populated with the mailbox
Document patternDear plus the mailbox local partGreeting addressed to a shared inbox as though to a person
Document stringby scanning the verification code belowTerminal instruction moving the target off the inspected channel
Attachment structure/URI 0, /JS 0, /OpenAction 0, /AA 0No links, no script found, no automatic action
HeaderX-Priority: 1, Importance: HighUrgency flags on a first-time external sender
Display name patternVictim company name concatenated to Earnings_HR_reviewFabricated internal HR system identity
Subject patternVictim company name run into May Incentive Summary UpdateThe same concatenation defect in the subject line

What Caught It

Not the scanner, which was right to call the file clean. Not the AI analyst either: on this incident Themis returned a null confidence, no labels, and empty insight arrays.

A person reported it. The report came from a named internal security mailbox at the victim organization, and the resolution is recorded as a human malicious verdict with zero safe votes and no release requests. That is the control that held, and it is why the human layer is not a soft add-on to detection. IRONSCALES platform data puts the volume behind it at 67.5 phishing emails per 100 mailboxes each month, reported and triaged across 36,000+ security professionals in 18,000+ organizations.

MITRE tracks this as spearphishing attachment, T1566.001. For the wider pattern, CISA phishing guidance covers stopping the attack cycle at its first phase, and the Microsoft Digital Defense Report 2024 surveys the same threat landscape at scale. NIST defines the technique by intent rather than by artifact.

The practical lesson is cheaper than any of that. Read the document as a document. Ask whether its fields resolve, whether its identifiers identify anything, and whether the dates it asserts are dates a business would ever assert. A compensation letter that knows what second it is was built by a machine two seconds before it reached you.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
The Partner Invite That Used the Wrong Sending DomainA calendar invite appeared to be from an IRONSCALES employee arranging an ANZ distribution call.
The .com That Wasn't the .org: TLD Confusion in a Payroll Email With an Empty BodyA payroll email about annual salary and benefits arrived from the .com version of a nonprofit's domain.
Someone Filed a False Positive on This Azure TOAD Scam. Here's Why That's the Whole Point.An attacker built a real Azure subscription, created a resource group and metric alert rule.
The Flow Failure Alert That Came From the Wrong TenantAn attacker spoofed a Microsoft Power Automate flow failure alert using a test tenant subdomain that nearly matched the target's production domain.
Microsoft Bookings as a Weapon: When DMARC Says Trust Me and ARC Quietly DisagreesA phishing email sent from bookings.microsoft.com passed every authentication check.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.