TL;DR A ServiceNow-branded invoice for $49,465.90 reached the finance mailboxes of a multi-brand residential home-services group inside a fabricated three-message approval thread. Every authentication check passed, there was no attachment, and the only links in the message were Microsoft's own safety-tip help pages. The brand wordmark was drawn as inline SVG vector text, so there was no logo image to fingerprint. The document failed on arithmetic instead: its printed issue date fell 29 days before the vendor domain on its own remittance line was registered. The entire payload was a routing number and a consumer neobank account.
Severity: High Business-Email-Compromise Invoice-Fraud Brand-Impersonation Payment-Diversion MITRE: T1566 MITRE: T1656 MITRE: T1583.001 MITRE: T1584.006 MITRE: T1534

A senior accountant at a multi-brand residential home-services group received an invoice for $49,465.90. It billed for a ServiceNow platform implementation, sat at the bottom of a forwarded three-message approval chain, and asked for payment by ACH only. Every authentication check passed. There was no attachment, no attacker link, and no logo image to fingerprint. The document convicted itself on arithmetic: the issue date printed on its face fell 29 days before the vendor domain on its own remittance line was registered.

The Approval Chain That Was Never Sent

The message was one HTML document dressed as three, and whoever built it left the scaffolding in place: comments in the source labelled the blocks in send order. The oldest block came from a mailbox on the lookalike vendor domain and promised an invoice would follow. The newest, at the top, approved the payment and pointed the reader at banking details printed on the invoice itself.

The middle block is the load-bearing part. Signed as an executive at the recipient's own domain, it apologized for a delay, redirected the thread to the finance mailbox, then closed the only door that mattered: there was no need, it said, to copy him. It does not defeat the one business email compromise control that reliably works, a human confirming a payment instruction with whoever supposedly authorized it. It asks the reader to skip it.

One display name carried three addresses: the From header put it above an unrelated European insurance provider's sending domain, the forged internal signature attached it to the recipient's own apex domain, and our impersonation lookup knew the same name at a third domain entirely, a real business unconnected to any of this.

A Wordmark With Nothing to Hash

Impersonated invoices usually arrive as a PDF or hotlink a stolen logo. This one did neither. There was no attachment, and the wordmark was not an image: it was drawn in the body as inline SVG vector text, with a hand-built vector path for the round glyph, filled in the brand's signature green. That removes a detection surface entirely: no raster asset to hash, no remote fetch to log, no file to detonate. The impersonation exists as vector geometry, which is not content most inspection layers read.

Twenty-Nine Days Before Its Own Vendor Existed

Two attacker domains were registered inside a single twelve-minute window at the same registrar, the Reply-To domain first and the ServiceNow lookalike 12 minutes and 46 seconds later, under identical registrant organization and state fields with the rest redacted for privacy. Both were 3 days and 8 hours old when the message was sent.

Now set that against the document. The invoice printed the same date for issue and for payment, presenting itself as due the day it was raised, with a status pill reading "Awaiting Payment" on a bill that was hours old. More decisively, its printed issue date preceded the registration of its own vendor domain by 29 days. The domain on the remittance line, the domain in the contact address and the domain hosting the fabricated vendor mailbox did not exist for the first 29 days of the period being billed.

Everything else was internally consistent. Four plausible service codes summed to the cent against the subtotal, and the billed-from block reproduced the impersonated vendor's real corporate address. Internal consistency is not evidence of legitimacy. It is evidence of care.

See Your Risk: Calculate how many threats your SEG is missing

Authentication Proved the Wrong Thing

SPF passed. DKIM verified against the sending organization's own selector rather than a shared ESP key. DMARC passed, and Microsoft's composite authentication returned a pass with reason 100, the strongest result it issues. How the sender reached that SendGrid stream is not established, and precision matters: nothing proves account takeover. The message rode out on a real, unrelated organization's authenticated sending stream, which is why every check aligned on that organization's apex domain.

Under RFC 7489, an aligned pass answers a question about the envelope, not the content. It tells you which stream carried the message, and nothing about the three other domains it pointed the reader toward: the Reply-To domain, the remittance domain inside the invoice, and the recipient's own domain forged into the signature. That gap between authenticating a stream and authenticating an intent is where phishing has always lived.

The Entire Payload Was a Routing Number

Only three links existed in the message, and all three were Microsoft's own anti-phishing help pages, pulled in by the first-contact safety tip. All three scanned clean, because they belong to Microsoft. There was no attacker URL anywhere.

The remittance details appeared twice, in a bank transfer panel and a standalone block. Both named the impersonated vendor as payee, both specified ACH only, and both pointed at an account at a US consumer neobank. That is the second free signal: an enterprise software vendor invoicing nearly $50,000 does not collect it into a consumer or prepaid account. The bank is the destination here, not a participant.

The amount is not an accident either. The 2024 Verizon Data Breach Investigations Report puts pretexting, mostly business email compromise, as the leading social engineering type with a median transaction around $50,000, and this invoice was written just under that line. The 2023 FBI IC3 report counted roughly $2.9 billion in reported BEC losses.

What the Recipient Actually Saw

Microsoft delivered it to the inbox at spam confidence 1, filter verdict not spam, with that safety tip as the only user-visible warning. Themis returned 89 percent confidence and tagged the message against a high-value recipient, while its content insight set came back empty. That emptiness is the finding. Nothing in the copy gave a content model anything to object to, so the verdict came from community reputation plus sender analysis catching the display name at a domain other than the one sending it. That is the practical case for Adaptive AI informed by 35,000+ security professionals across 17,000+ organizations.

Timing widened the window: about ten and a half hours passed between ESP submission and tenant arrival, Microsoft re-scanned the message hours after it landed, and a second finance mailbox received a personalized variant.

Controls That Would Have Stopped It Earlier

Read domains as document fields. A domain on a remittance line, in a "questions" contact or as a vendor mailbox deserves the same age check a link destination gets. A domain days old carrying a decades-old vendor's brand is a decision, not a coincidence, and MITRE's phishing coverage treats that acquisition step as part of the attack.

Compare From, Reply-To and remittance domains as a rule rather than a judgment call: three domains for one identity is disqualifying on its own. Treat remittance to a consumer or prepaid banking brand as a hard stop. And when a message tells a recipient not to loop someone in, escalate on that sentence, using a known-good phone number rather than a reply to the thread, which is where CISA's phishing guidance keeps returning.

It reads like vendor email compromise, but nothing about the vendor was compromised. The vendor was simulated.

Indicators of Compromise

TypeIndicatorContext
Domainservice-nowinc[.]comAttacker-registered vendor lookalike; created 29 days after the invoice's printed issue date; appears on the remittance line, the invoice contact line and as the fabricated vendor mailbox domain
Domaindomainlify[.]netReply-To domain; same registrar and identical registrant organization fields, registered 12 minutes 46 seconds before the lookalike
Emaili@domainlify[.]netReply-To address; every reply left the fabricated thread and reached the attacker
Email[masked]@service-nowinc[.]comInvoice "questions" and remittance-advice contact, attacker-owned (local-part withheld)
Email[executive-name]@service-nowinc[.]comFabricated vendor-executive mailbox in the oldest thread block; domain attacker-owned, local-part withheld because it is a real person's name
Invoice referenceINV-6220536262Fabricated invoice number, repeated five times across the document (header, summary panel, payment reference chip, remittance table, footer)
Service codesSN-IMPL-001, SN-AUTO-002, SN-ANLX-003, SN-OPS-004Four fabricated line-item SKUs summing exactly to the $49,465.90 total
Bank routing124303162ACH routing number given for the fraudulent payment, at a US consumer neobank
Bank accountaccount ending 0088Receiving account for the ACH redirect (masked; may belong to a real individual)
Amount$49,465.90Total due, ACH only, marked issued and payable the same day
URLhxxps://u20725423[.]ct[.]sendgrid[.]net/wf/open?upn=u001... (truncated)ESP open-tracking pixel as a 1x1 image at the end of the body, instrumented to record which recipients opened it
BehaviorInline SVG vector wordmarkBrand logo drawn as vector text plus a hand-built glyph path in the brand's green, with no raster asset and no remote image fetch
BehaviorThree-block fabricated threadSingle HTML document imitating a forwarded approval chain, with build comments left in the source labelling each block
BehaviorIssue date preceding vendor-domain registration by 29 daysThe document's internal chronology is impossible against public registration data

MITRE ATT&CK Mapping

TechniqueNameApplication in this case
T1566PhishingUnsolicited finance-themed message to two mailboxes in one finance function, with per-recipient subject personalization
T1656ImpersonationGlobal SaaS vendor impersonated by wordmark, corporate address and service-code structure; an internal executive impersonated in a forged approval block
T1583.001Acquire Infrastructure: DomainsTwo domains registered 12 minutes 46 seconds apart at one registrar under identical privacy-shielded registrant fields, used three days later
T1584.006Compromise Infrastructure: Web ServicesMessage delivered on an unrelated organization's authenticated ESP sending stream, producing aligned SPF, DKIM and DMARC passes on a domain the attacker does not own
T1534Internal SpearphishingThe forged middle block imitates internal mail from an executive at the recipient's own domain, redirecting the thread and discouraging verification

The Document Told On Itself

Nothing here required a sandbox verdict or a file hash: the invoice was disprovable with a registration date and subtraction. It still reached an accountant's inbox because every control in its path answered a narrower question than the one that mattered. Authentication asked which stream sent this. Link scanning asked whether the URLs were malicious. Attachment analysis had nothing to open. None asked whether the vendor being billed from existed when the bill was supposedly written.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
The Security Tool That Delivered the $48,500 Invoice FraudA $48,500 invoice fraud routed through a Votiro email sanitization relay, which paradoxically introduced an SPF softfail.
A PayPal Invoice for Apple, Paid to a Third BrandA $1,040.02 invoice showed a PayPal logo, named Apple as the merchant, and pointed its payment button at a third brand.
The One PayPal Link That Dropped to Plain HTTPA genuine PayPal invoice, forwarded through mangled relay headers to five unrelated companies at once, passed every authentication check.
The Invoice Fraud That Came From a University Mail ServerA regional airport's finance team received a payment request that passed SPF, DKIM, and DMARC cleanly.
The Invoice Was Older Than the Domain It Told You to PayA $19,900 vendor invoice reached the VP of Accounting at an insurance provider with SPF, DKIM and DMARC all passing under an enforced policy.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.