Table of Contents
There was nothing to click and nothing to open. The message that reached a finance mailbox at a heating and furnace equipment manufacturer carried no attachment, no credential page, and no macro-laden spreadsheet. It carried a demand for roughly $4,500, a fabricated history to justify it, and a body of text in which almost every letter was an imposter.
On screen it read as ordinary business English. As bytes it was a mosaic of Greek and Cyrillic characters chosen because they render nearly identically to their Latin counterparts: a Greek omicron standing in for the letter o, a Cyrillic es doing the work of a c. The pretext was a welcome invoice for membership in a fictitious "Executive Advisory VIP Club" attributed to Vistage International, the real executive peer-advisory organization. The balance, it said, should be settled today.
Every Character Was Wearing a Costume
Content filtering rests on a load-bearing assumption: that the words in a message are the words the recipient reads. Homoglyph substitution breaks that at the cheapest possible layer.
A keyword rule hunting for invoice, overdue, or remittance never fired, because those strings were not present. What was present were code point sequences that a human eye resolves into those exact words and a byte comparison does not. No encryption to defeat, no image to run through optical character recognition, no attachment to unpack. The evasion lands before detection gets a chance to be clever.
Mixed-script text is not inherently malicious. Legitimate mail crosses alphabets constantly. What makes this instance an indicator is ratio and placement: a supposedly routine English-language accounts-payable note with substitutions spread through nearly the entire body rather than confined to one name. That is not multilingual business. That is camouflage, and NIST defines phishing around exactly this kind of engineered deception.
An Invoice That Was Never Attached
De-obfuscated, the body asked the reader to "please find attached the outstanding invoice for Business Coaching and Development services, along with the VIP membership" for a named executive at the target company. Nothing was attached. There was no invoice, no statement, no file of any kind.
That gap is the tell, and it is also the point. The attacker needs the recipient to accept that an invoice exists, not to read one. A $1,000 discount was described as already applied to the first month. A membership figure of $5,489.89 was shown reduced to $4,489.89. Two reference numbers were cited as still carrying a balance. Beneath the demand sat a manufactured thread of three forwarded messages, dated a couple of days apart earlier that week, inventing a prior relationship and an original issue date. None of it happened.
The only URLs anywhere in the message were generic Microsoft security-education pages, all clean. URL reputation had nothing to score, and sandboxing had nothing to detonate.
See Your Risk: Calculate how many threats your SEG is missing
The Reply-To Header Was the Whole Attack
Strip away the alphabet games and the fake thread and one piece of attacker-controlled infrastructure remains. The From address was a generic dispatch mailbox at a European university. The Reply-To was an address at an unrelated freemail-style consultant domain.
Almost no mail client shows a recipient the Reply-To header, and hitting reply silently honors it. A finance analyst who wanted to query the balance or ask where to send payment would have written back believing they were corresponding with the sender they could see, and that entire negotiation would have landed with the attacker. Banking details get exchanged in the reply, not in this first message. This one only has to earn one.
Pretexting of this shape is the top social engineering pattern in the 2024 Verizon Data Breach Investigations Report, which puts the median business email compromise transaction near $50,000 and finds a human element in 68 percent of breaches, and the 2023 FBI IC3 Internet Crime Report counts roughly $2.9 billion in reported BEC losses. A four-figure invoice looks modest against that, which is why it clears approval thresholds without a second signature. Divergent reply paths are a behavior business email compromise protection has to model directly, because no authentication check evaluates the header that decides where a reply goes.
Why the Authentication Trail Contradicts Itself
At the origin hop this message was, by every mechanical measure, legitimate. SPF passed for the university's own sending address, DKIM passed under the university's own selector, and DMARC passed with the domain published at a policy of none. The university's gateway even stamped it as found to be clean before it left.
Then the receiving mailbox auto-forwarded it to the finance mailbox of an affiliated healthcare-services organization, and the picture inverted. At the final hop, SPF and DKIM passed for the forwarding tenant's own onmicrosoft[.]com identity, while the DKIM signature covering the original university domain failed with a body hash mismatch and DMARC failed for the visible From domain. The Return-Path had been rewritten by sender rewriting scheme, and the ARC chain validated cleanly end to end.
Read carelessly, that failure looks like a spoofed university domain. It is not. The clean origin hop and the passing ARC chain show a forwarding artifact: the forward altered the message and re-sent it from other infrastructure, which is what broke alignment, and the policy of none meant no enforcement followed anyway. DMARC monitoring surfaces that gap rather than closing it. The record also does not establish whether that dispatch mailbox was compromised or simply a generic address induced to relay, so either way the message rode real institutional infrastructure carrying real signatures.
Nothing blocked it at delivery. A member of the IRONSCALES community reported it, and it surfaced retrospectively through SOC scanback analysis rather than being caught live, with no mitigation action recorded against the affected mailbox. Themis, the IRONSCALES Adaptive AI analyst, scored it as extortion at 90 percent confidence, with sender analysis flagging the mismatch between the visible identity and the reply path. Detection came from a person and from cross-tenant pattern memory across 35,000+ security professionals across 17,000+ organizations, not from anything the message offered a scanner.
Indicators of Compromise
| Type | Indicator | Context |
|---|---|---|
hunterlawrence@consultant[.]com | Attacker-controlled Reply-To where any reply would land | |
| Domain | consultant[.]com | Freemail-style domain hosting the Reply-To |
centraledispatch@[redacted][.]be | Visible From, a generic dispatch mailbox at a European university (third party, redacted) | |
| IP | Withheld | Mail gateway of the spoofed university, legitimate infrastructure, withheld because the netblock identifies the institution, not a block candidate |
| Display name | Fabricated consultant persona (masked) | Signature claimed a firm presented as a member of Vistage International |
| Auth result | Origin: SPF pass, DKIM pass, DMARC pass (p=none) | Valid signature on genuine institutional infrastructure |
| Auth result | Final hop: DKIM body hash fail, DMARC fail, ARC pass | Forwarding artifact, not origin spoofing |
| Subject | Invoice [redacted] Overdue | Reference number masked; a second one appeared in the body |
| Amount | $5,489.89 reduced to $4,489.89 | Fictitious membership invoice, plus a claimed $1,000 discount |
| Encoding | Greek and Cyrillic homoglyphs across the body | Keyword matching defeated at the character level |
| Payload | None (no links, no attachments) | Three benign Microsoft security-education URLs only |
MITRE ATT&CK Mapping
Delivery maps to Phishing (T1566) with no sub-technique, since neither an attachment nor a malicious link is involved. The pretext maps to Impersonation (T1656), covering both the fabricated consultant identity and the borrowed authority of a real advisory brand.
Closing the Gap on Payload-Free Invoice Fraud
Three controls matter here, and none of them is another URL scanner.
Score the header mismatch, not the message text. A Reply-To in a different organization from the From address survives every evasion in this attack. Flag it, surface it to the recipient, and weight it heavily alongside financial-request language. The attacker cannot hide it, because the divergence is the mechanism.
Normalize before you match. Any detection that compares text to a list needs Unicode normalization and a mixed-script check ahead of it, plus a signal when a supposedly English business message is built substantially from non-Latin code points. CISA phishing guidance is clear that layered controls have to assume content-level evasion.
Verify invoices against your own records, out of band. No email should be able to establish that a vendor relationship exists. If accounts payable cannot find the membership, the service, or the prior thread anywhere but in the message asking for money, that is the answer.
The alphabet trick is what makes this one memorable. The reply path is what would have taken the money.
Related attacks
| Attack | What happened |
|---|---|
| SPF PermError Turned a Malformed Domain into an Invoice Fraud Launchpad | An attacker exploited a malformed SPF record that returned PermError instead of pass or fail, paired with a same-day-registered Reply-To domain. |
| Three Domains, One Invoice: The Payment Diversion That Authenticated Itself Through the Wrong Organization | A past due invoice email passed SPF, DKIM, and DMARC while impersonating a contact at a clinical research firm. |
| The Reply-To Was One Letter Off: How a Typosquat Domain Turned a Gmail BEC Into a Payment Diversion | A Gmail-authenticated BEC used a typosquat Reply-To domain and a hidden HTML mailto mismatch to impersonate a steel distributor's credit manager. |
| The PayPal Invoice That Passed Every Check Because PayPal Actually Sent It | A canceled PayPal invoice for $50 arrived with perfect SPF, DKIM, and DMARC authentication because PayPal's own infrastructure sent it. |
| Compromised Manufacturer Domain Delivers Toyota Financial Invoice Lures with Perfect Authentication | A compromised manufacturing company's M365 account sent Toyota Financial invoice lures that passed every authentication check. |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.