TL;DR A UK IT security distributor received a GOV.UK visual clone announcing a security upgrade to the Sponsorship Management System, the real Home Office portal that visa sponsor licence holders must use. The email body contained zero links. The entire payload was a one-page PDF with no script of any kind, whose single working button pointed to an HTML page in a European object-storage bucket. Its government-style footer held five more link annotations, every one with an empty destination. The inline gateway scored the message clean and delivered it to three mailboxes.
Severity: High Credential Harvesting Brand Impersonation Malicious Attachment MITRE: T1566.001

Five of the six links in this phishing PDF point at nothing at all.

The footer looks exactly like a government notice. Help. Security. Terms. UK Visas and Immigration. Home Office. Each is a real link annotation in the file structure, in a neat row at the bottom of a single A4 page. Open the file's internals and every one of those five has an empty destination. They are decoration. Only the button in the middle of the page goes anywhere.

That is the attack in one detail: a facade built well enough to pass a glance, and hollow underneath.

A pretext aimed at licence holders, not at everyone

The target was a UK distributor of IT security and business-continuity products, selling through managed service providers. The lure was a security upgrade notice for the Sponsorship Management System.

SMS is not an invented brand. It is the genuine Home Office portal that any organisation holding a UK visa sponsor licence must use to issue certificates of sponsorship. Lose access to it and you have a compliance problem with a regulator, not an IT ticket. A generic invoice lure has to survive the recipient's indifference. This one arrives pre-loaded with consequence, which is why the pretext lands.

No prior case in our published teardowns used UK immigration sponsorship as a pretext. First-seen brands are the hard part of this problem. Reported phishing volume is tracked annually in the FBI IC3 2024 annual report. The 2026 Verizon Data Breach Investigations Report puts phishing at 16% of breaches as an initial access vector and the human element at 62%, up from 60%. Those numbers hold because the pretexts rotate faster than the block lists.

The email carries zero links

The message body contains no links whatsoever. The incident's link array is empty.

Everything rides on one attachment, a 62,599-byte file named as sponsor upgrade guidelines. The IRONSCALES platform scored it Malicious, and Themis, the Adaptive AI analyst, returned confidence 90 with an insight naming that attachment specifically. That is a scanner verdict, independent of the narrative the message claimed. No human analyst verdict exists on this record.

The body itself is a careful GOV.UK visual clone: official dark blue as the outer background, a header reading "Sponsorship management system", and a footer carrying Crown copyright, UK Visas and Immigration, and Home Office, United Kingdom.

One real link, buried in a file

Decoding the file returns exactly one URI action. It hangs off a "Complete upgrade" button mid-page, resolving to an HTML page inside a Contabo S3-compatible object-storage bucket in the provider's European region.

Object storage as a payload host is not new, and it is not the point here. The placement is. Putting the only link inside an attachment moves it past the layer where mail filtering does link reputation: there is no link in the message to check. The file is a carrier, nothing more.

The rendered page text is short and pure pressure. A warning that the account may become inaccessible if the task is not completed. Then a deadline: the upgrade link stays active for ten days from receipt, long enough to sound administrative and short enough to be a clock.

What that page served was never captured, so we cannot describe it.

See Your Risk: Calculate how many threats your SEG is missing

What the file does not contain

The fast read on a malicious PDF is that it runs something. It does not. There is no JavaScript, no automatic action dictionary of any kind, no embedded file, no form or form-submission action, no launch action and no rich media. Two byte pairs resemble the start of a Windows executable header, but the accompanying signature bytes are absent, so there is no embedded binary. Nothing in this document executes when you open it.

Which means the Malicious verdict is best explained by the destination the file carries, not by code inside it. A one-page document with no script and one live button is a delivery mechanism, and a good one precisely because static analysis finds so little to object to. MITRE classifies this as T1566.001, spearphishing attachment, and the attachment here does exactly one job.

Authentication told the truth. The gateway ignored it.

The sender is where the facade shows through. The From header displays "Home Office" over an address on a domain with no relationship to the UK government, and the message was injected by Postfix running as root on the attacker's own host, a VPS in an OVH range.

The Reply-To is the more interesting field. It is set to an address on the genuine Home Office domain, not a lookalike. Whether that mailbox is deliverable is not determinable, but the consequence matters: a reply goes to the real Home Office, not to the attacker. The field is credibility, not a channel.

Authentication reported all of this correctly. DKIM was never applied, so there was no signature to evaluate. DMARC failed against the sending domain under a published policy of reject, with an oreject action. Composite authentication returned none. At the origin hop, before a relay rewrote the picture, SPF actually passed for the attacker's own domain at the attacker's own host, which is what SPF is designed to do and why it settles nothing about intent.

Then the inline secure email gateway, or SEG, scored the message clean on both spam and virus checks, Microsoft assigned it a negative spam confidence level, and in May 2026 it was delivered to three mailboxes in the same tenant within the same second, including the generic shared address in the To line. Nothing blocked it.

Indicators

TypeIndicatorContext
Sender domainmail[.]getalertinfo[.]comFrom domain, DMARC fail, no DKIM signature
Sending IP51[.]195[.]101[.]247OVH-range VPS, Postfix injection as root
Attachmentsponsor_upgrade_guidelines.pdf, md5 bbaf9fcb24c94d85273239de7fc0531ePlatform verdict Malicious
URLhxxps://eu2[.]contabostorage[.]com/<32-hex-bucket-id>:cflex/kigo[.]htmlSole live link, on the "Complete upgrade" button
Reply-Tosystemupgrade@homeoffice[.]gov[.]ukGenuine Home Office domain, not attacker-controlled. Do not block.

The defensive read

A first-seen government brand aimed at a licence-holder niche is the case reputation cannot help with. There is no sender history, no prior campaign to match, and no link in the body to score. CISA phishing guidance and the NIST definition of phishing both frame the problem the same way: the deception is social, and the technical artifacts are secondary.

So detection has to reason about shape. An unsigned message from unrelated infrastructure, displaying a government brand, carrying no links in the body and exactly one inside an attachment, with a deadline attached to account access. Every one of those is individually defensible. Together they are not.

That is the work Adaptive AI does that a static rule cannot, and it is why an attachment-borne link needs the same scrutiny as a body link. IRONSCALES platform data across 36,000+ security professionals and 18,000+ organizations puts the baseline at 67.5 phishing emails per 100 mailboxes each month. A single hollow-footer PDF in that volume is not an outlier. It is a Tuesday.

Check the annotations. Real government templates do not ship dead links.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
Insurance Claim PDF Hides JavaScript Behind AcroForm Fields and SendGrid RedirectsA polished insurance claim notification delivers a PDF with interactive AcroForm fields and obfuscated JavaScript auto-execute tokens.
The Whole Page Is the Button: A PDF Click TrapA one-page PDF statement arrived with no visible links and no form controls, just a flat image of a document.
The Health Spending Account Alert That Rode a Benefits Administrator's Own InfrastructureAn Anthem-branded spending account notification routed through a legitimate benefits administrator's redirect infrastructure.
The DOCX That Was Actually a Fake M365 Admin ConsoleAn empty-body domain-renewal email carried one attachment that claimed to be a Word document.
The Vendor Compliance Email Where Every Link Was Real and Every Authentication Check PassedA vendor compliance onboarding email sent through Salesforce infrastructure passed SPF, DKIM, and DMARC with compauth 100.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.