TL;DR A recurring campaign impersonated SAM.gov, the U.S. federal contractor registration system, with a renewal 'Final Notice' sent through commercial bulk-mail infrastructure. The From domain and a mismatched Reply-To were look-alike names, both registered the same day, and links routed through tracking redirectors to a non-government confirm-registration page. The lure quoted the company's real CAGE code and Unique Entity ID to manufacture legitimacy. Authentication largely passed, but under a p=none policy that enforced nothing. Every scanned link came back clean, so the tell was identity, not payload. Themis flagged the campaign on reputation and community pattern history.
Severity: High Brand Impersonation Credential Harvesting MITRE: T1566.002 MITRE: T1583.001

A message landed in the customer-service inbox of a mid-size manufacturing company with a subject that reads like a bureaucratic ultimatum: a "Final Notice" to renew the firm's federal contractor registration before it lapsed. The display name said "SAM Renewal Notification." The body warned that eligibility to receive federal awards was about to expire. To close the deal, it quoted the company's real SAM.gov CAGE code and Unique Entity ID, the exact identifiers a legitimate registration would carry.

For a company that does business with the federal government, this is a well-aimed lure. SAM.gov, the System for Award Management, is where entities register to bid on and receive federal contracts. A lapsed registration is a real operational problem. The email was engineered to convert that anxiety into a click.

There was just one thing wrong with it, and it was the thing almost nobody checks. Not a single domain in the entire chain was a government domain.

An official warning from a decidedly unofficial sender

The From address was noreply@samsregistration[.]com. The Reply-To pointed somewhere else entirely, tina@samsfulfillment[.]com, a different domain from the one in the From header. A genuine federal notification does not arrive from a commercial look-alike, and it certainly does not ask you to reply to a second, unrelated commercial domain.

The naming was deliberate. "samsregistration" and "samsfulfillment" borrow the "SAM" prefix to ride on the authority of the real system without ever claiming a .gov address, which the attacker could never obtain. The whole design leans on a habit most recipients share: we read the display name and the subject line, register "SAM" and "Final Notice," and skip the part of the address that actually matters.

Two domains, born the same day, on bulk-mail rails

The infrastructure told the rest of the story. Both the sending domain, samsregistration[.]com, and the eventual landing domain, samsupports[.]com, were registered on the very same day through the same registrar. Same-day registration of the two domains a campaign needs is a classic disposable-infrastructure fingerprint. These are not aged assets with a reputation to protect. They are throwaways stood up for one run.

Delivery rode commercial bulk-mail infrastructure, a marketing email service provider, using its sending IPs and relay domains. That choice is what made the authentication look reasonable. SPF passed for the look-alike domain because the message really was sent through an authorized bulk-mail IP. DMARC passed as well, but the policy behind it was set to p=none, which asks receiving servers to take no action on failures. A pass under p=none is a green light that enforces nothing. DKIM validated at the originating filter and then showed a failure after transit through Microsoft 365, the kind of drift intermediate processing can introduce, and not on its own a reliable verdict either way.

Put together, the authentication story is the point: every check a gateway is trained to trust returned an answer that looked acceptable, and none of it said anything about whether the sender was who it claimed to be. Authentication proves control of a domain. It says nothing about the domain deserving trust. This is exactly the gap a legacy secure email gateway leaves open, and it is worth knowing how wide that gap runs across your own mail flow. IRONSCALES publishes a SEG gap analysis tool for measuring it.

Real identifiers, a clean scan, and a page that was not the government

The links in the body did not point straight at the destination. They routed through tracking redirectors on track[.]samsregistration[.]com, which decoded to samsupports[.]com/confirm-registration/, a commercial renewal page with no relationship to any federal system. The landing domain published no MX, SPF, DMARC, or DNSSEC records at all, consistent with a page built to collect submissions rather than to run as a real mail-handling business.

Here is the part that makes this campaign hard for automated tooling. When the redirect chain was scanned, it came back clean. There was no malware waiting at the end, no exploit, no drive-by. The credential and information harvest lived in a form on a plausible-looking confirmation page. To a scanner asking "is this file or destination malicious," the honest answer was no. The danger was never in the payload. It was in the identity: commercial, disposable infrastructure claiming the authority of a federal system, personalized with genuine public SAM.gov data that anyone can look up.

That is why this one was flagged on reputation and community pattern history rather than on a technical block. IRONSCALES Themis, our Adaptive AI, recognized the domain-identity mismatch and the recurring shape of the campaign, which had hit the same customer-service mailbox several times over roughly two months, each notice a small variation on the last. Community classification history across the network had already seen this pattern. A lure that scans clean but keeps coming back from throwaway look-alike domains is a behavioral signal, and behavioral signal is precisely what pattern-and-reputation detection is built to catch when the payload gives nothing away.

What security teams should take from this

Government-impersonation lures work because the underlying obligation is real and the identifiers are public. The 2024 Verizon Data Breach Investigations Report puts phishing in 15 percent of breaches and the human element in 68 percent of them, and pretexting of this kind is the fastest-growing corner of social engineering. Attackers do not need malware when a convincing page and a public CAGE code will do.

A few durable habits blunt this class of attack. Treat any federal renewal notice from a non-.gov domain as false by default. Read the full email address and the Reply-To domain, not just the display name. Renew registrations only by navigating directly to the official site, never through a link in an inbound message. And back the human habit with detection that weighs sender identity and campaign history rather than payload alone. If you want to see how that looks against live examples like this one, request a demo.

Indicators of compromise

IndicatorTypeNote
samsregistration[.]comSending domainLook-alike, registered same day as landing domain
samsfulfillment[.]comReply-To domainMismatched from the From address
samsupports[.]comLanding domainNon-government confirm-registration page; no MX/SPF/DMARC/DNSSEC
track[.]samsregistration[.]comRedirectorTracking hop decoding to the landing page
noreply@samsregistration[.]comFrom address"SAM Renewal Notification" display name
tina@samsfulfillment[.]comReply-To addressDiverges from the sending domain
jsmtp[.]net, jngomktg[.]netBulk-mail relayCommercial ESP infrastructure used for delivery

MITRE ATT&CK techniques

For a plain-language reference on this class of threat, see CISA's phishing guidance and the 2024 Verizon Data Breach Investigations Report.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
The Procore Footer Was Real. The Document Was Not.Every link scanner called the Procore and ExxonMobil URLs clean.
A Pixel-Perfect Sephora Delivery Notice Shows Why Email Authentication Alone Can't Protect YouA fully authenticated Sephora delivery notification passed SPF, DKIM, and DMARC with perfect scores.
The Email That Passed Every Security Check (Because Adobe Sent It)A phishing campaign targeting school district staff used Adobe's own sending infrastructure, real DKIM signatures.
The Phishing Infrastructure Was Canva. The Delivery Mechanism Was Canva. The Authentication Was Canva.An attacker signed up for Canva, built a phishing lure as a design, and used the platform's own sharing feature to deliver it.
When the Sender Domain Is Also the Phishing Kit Host: Dual-Purpose Domain CompromiseAn attacker compromised a legitimate manufacturing company domain and used it two ways at once: as the authenticated sending address and as the host for...

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.