TL;DR One employee mailbox received a fabricated McAfee subscription renewal receipt with no links and no attachments. The sender was a first-time Gmail account submitting from a client IP geolocated in Bangkok with no PTR record, and the display name on the message was the real name of the mailbox owner, so the mail appeared to arrive from the recipient's own identity. The only call to action was a support phone number, listed twice. Gmail authentication passed cleanly. Adaptive AI labelled the message vishing at 90 percent confidence and the incident resolved automatically.
Severity: High Callback-Phishing Vishing Brand-Impersonation Display-Name-Impersonation Freemail-Abuse MITRE: T1566 MITRE: T1566.004 MITRE: T1656 MITRE: T1585.002

One employee mailbox received an email with the subject "Account Service Successfully Verified." Inside was a fabricated McAfee membership overview: a three-year subscription, a reference code, a charge of USD 367.99, and a support telephone number listed twice above a fabricated agent signature. No links. No attachments. No QR code, no redirect chain. On the usual scale of renewal-invoice scams it was unremarkable, right up to the From header.

The display name on the message was the real name of the person who owned the mailbox it was delivered to.

The Sender Identity Was Borrowed From the Recipient

Not a colleague. Not an executive. Not a McAfee billing alias. The name rendered in the inbox belonged to the recipient, so in the message list, the preview pane, and most mobile clients, the mail appeared to have been sent by the person reading it.

That works on a different reflex than ordinary display-name impersonation. Impersonating a vendor asks the recipient to trust someone else. Impersonating the recipient removes trust from the equation, because there is no stranger to evaluate. Self-addressed mail reads as an artifact of one's own activity, a receipt forwarded from another device or a confirmation triggered by something already done, so the billing pretext arrives pre-authorized. Of course there is a subscription. Apparently it was handled.

The mechanic also survives the interface. Clients truncate or omit the sending address in favor of the display name, and some group self-addressed mail into threads the recipient already trusts. None of it requires a spoofed domain, which is what makes it cheap.

The Sending Account Had No History Here

The message came from a consumer Gmail account at mahamudul4539@gmail[.]com. Gmail is a legitimate provider, not attacker infrastructure, and that is the point. There was no lookalike domain to block and no reputation deficit to inherit.

What the account did have was a complete absence of relationship. This was a first-time sender, with no prior correspondence to that recipient or tenant. The received chain adds the detail worth keeping: the SMTP submission into Gmail came from client IP 43[.]152[.]237[.]47, geolocated to Bangkok, Thailand, with no PTR record at all. From there it took the ordinary Gmail outbound path through smtp[.]gmail[.]com into the mailbox. No gateway, no sanitization relay, no unusual hop.

Absent reverse DNS is a soft signal alone. Stacked, it is not. An account asserting a major security brand, submitting from an address with no reverse lookup and no hosting attribution, in an unrelated region, with zero history to the tenant, is a coherent picture of a compromised mailbox or one stood up for the campaign. That picture lives in the received headers, not the authentication results, which is why it gets skipped.

Authentication Was Clean and Told Us Nothing

SPF passed, with the Google outbound IP legitimately permitted to send for gmail[.]com. DKIM passed with a gmail[.]com signing identity. DMARC passed. Composite authentication had no objection, because nothing in the envelope was forged. A real Gmail account really sent this.

That is the ceiling on domain-anchored controls here. Alignment as defined in RFC 7489 answers a narrow question: did a domain authorize this message. Gmail did. The impersonation lived one layer above, in a human-readable string authentication has no opinion about, which MITRE ATT&CK tracks separately as impersonation and CISA phishing guidance warns about directly: authenticated mail still requires content and context review.

See Your Risk: Calculate how many threats your SEG is missing

Nothing to Scan, Only Someone to Call

The entire attack vector was the phone number. That makes this telephone-oriented attack delivery, which MITRE ATT&CK maps as spearphishing voice and defenders shorthand as callback phishing or vishing. The email is only the introduction. The fraud happens once the recipient dials, where a live operator handles objections in real time and the usual destinations are a remote-access session, a refund flow through the victim's own bank portal, or a card capture framed as cancelling the charge.

For an inspection pipeline this is close to a blank page. No URL to detonate, no attachment to hash, no credential page to fingerprint. Every element that could be scanned is inert, and the one that matters is ten digits of plain text. The 2024 Verizon Data Breach Investigations Report puts a human element in 68 percent of breaches, and a payload-free lure reduces the attack surface to that element alone.

What Flagged It Was the Relationship

With no artifact to analyze, the only evaluable material was behavior. Themis, the IRONSCALES Adaptive AI analyst, holds a per-recipient model of who legitimately corresponds with a mailbox and under what identity. It weighed a first-time sender against a phone-first call to action, a consumer mailbox asserting a major security brand, conversational cues typical of voice fraud, and a display name conflicting with the sending address, then labelled the message vishing at 90 percent confidence. Community resolution history on similar incidents rated that verdict highly confident. Detection was automated, one mailbox was affected, and the incident resolved as phishing with no one put on the spot.

That matters more than the confidence figure. When the payload is a conversation, the final control is a person deciding whether to dial, so the human element of the platform belongs in the detection stack rather than bolted on beside it.

What To Take From This Case

Mail that appears to come from the recipient is a testable condition, and every interesting fact here sat in the received chain rather than the authentication summary, so both belong in a rule set instead of an analyst's intuition. Then give people one instruction for phone numbers in unsolicited billing mail: never dial the number in the message, look the vendor up independently, report it. A callback lure only pays if somebody calls.

Indicators of Compromise

TypeIndicatorContext
Emailmahamudul4539@gmail[.]comAttacker-controlled Gmail account, display-named to match the targeted mailbox owner's real name
IP43[.]152[.]237[.]47SMTP submission client IP into Gmail, geolocated to Bangkok, Thailand, no PTR record, likely the operator origin or account access point
Phone1-813-543-3783Callback number presented as McAfee support, listed twice, the sole call to action
Subject"Account Service Successfully Verified"Implies an account action had already completed
ArtifactReference Code 596420Fabricated membership reference giving the invoice the texture of a real one
ArtifactUSD 367.99 charge for a three-year McAfee subscriptionFabricated amount, high enough to alarm and low enough to be plausible
BehaviorFirst-time sender, no history to the tenantRelationship signal, present despite a full authentication pass
BehaviorZero URLs, zero attachments, phone number as the only actionPayload-free structure leaving nothing for a scanning pipeline

MITRE ATT&CK Mapping

TechniqueIDApplication
PhishingT1566Brand-impersonation email delivered to one mailbox
Phishing: Spearphishing VoiceT1566.004Callback structure driving the recipient to a voice channel
ImpersonationT1656McAfee brand impersonation, plus a display name set to the recipient's own name
Establish Accounts: Email AccountsT1585.002Consumer freemail account used as disposable delivery infrastructure

See You Next Time

Authentication tells you a domain sent a message. It does not tell you the name on the front belongs to the sender, even when that name is your own. Check back tomorrow.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 36,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
A Real Zoom Alert, Resent by the Attacker Who Asked for ItZoom really sent this sign-in alert.
A Same-Day Domain, a McAfee Calendar Invite, Two PricesA McAfee renewal scam arrived as a Google Calendar invite from a domain registered the same day.
A Real Datadog Report, a Fake Bill, One Phone NumberA scheduled dashboard report arrived from Datadog's own reporting infrastructure, with real Datadog links and a real Datadog PDF attached.
A Fake McAfee Bill From a Domain the Attacker OwnedA fake $299 McAfee renewal notice passed SPF, DKIM and DMARC without a single forged header.
The Amazon Order That Wanted You to Call, Not ClickA fake Amazon order confirmation for an iPhone the recipient never bought.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.