TL;DR A healthcare facilities-management team received a forwarded vendor pricing thread from a personal webmail account whose display name mimicked a known external vendor rep. The email carried a clean PDF quote, legitimate links to the real vendor site and ordering portal, and passed every authentication check. Buried among the real links sat one malicious shortlink on a QR-shortener domain, labeled to look like an account convenience feature. It led to a credential-harvesting landing page on a trusted cloud CDN. Nothing broke. Only one link and one impersonated name gave it away.
Severity: High Business-Email-Compromise Vendor-Email-Compromise Credential-Harvesting MITRE: T1566 MITRE: T1566.002

A facilities-management team at a large healthcare system opened a forwarded email that looked exactly like the dozens of vendor quotes they process every week. The subject line carried a bid reference and a purchase order (PO) number. The attachment was a clean PDF quote for a modest amount, a few hundred dollars. The body linked to the vendor's real website and a real ordering portal. Every signal said routine procurement. Only two things were wrong: one link, and one letter in a name.

The Setup: A Forwarded Quote From a Familiar Name

The message arrived as a forwarded thread, the kind that reads like a colleague passing along a supplier's reply. "Fwd:" in the subject, a bid number, a PO reference. The content was a plausible quote conversation, the sort of back-and-forth that happens a hundred times a day inside any procurement workflow.

The sender's display name matched a known external vendor contact the team had worked with. That is the part the human eye locks onto. Most mail clients surface the friendly display name and tuck the actual address out of sight. So the recipient saw a trusted supplier rep, not the underlying account, which was a personal Hotmail address that had nothing to do with the vendor's real domain.

This is vendor email compromise (VEC), a branch of business email compromise that hijacks the trust living inside a supplier relationship. The attacker did not need to breach the vendor. They only needed to look like the vendor for the length of one email.

One Letter, One Login: The Display-Name Lookalike

The impersonation was flagged as a "Similar Display Name" match, and that word "similar" is the whole game. Attackers rarely need a perfect clone. A near-match display name, close enough to pass a glance, riding on a free webmail account, is enough to borrow a real person's authority.

The 2024 Verizon Data Breach Investigations Report puts the human element in 68% of breaches, and the median time for a target to click a phishing link at just 21 seconds. A procurement specialist scanning a familiar-looking quote does not spend 21 seconds auditing the raw From header. They see a name they recognize and move to the next task. The human element is not a weakness to shame; it is the surface every one of these attacks is engineered to exploit.

The Poisoned Link Hiding in Plain Sight

Here is where the craft shows. The email was not a crude lure with a single obvious hook. It was a real-looking quote reply stuffed with legitimate links: the vendor's actual website, a genuine ordering portal, the kind of references a real thread would contain. Everything checked out.

Hidden among those clean links sat exactly one that did not: a shortlink on a QR-shortener domain, hxxps://qrco[.]de/bdnh8B, with display text reading "Save My Info." No QR image was rendered and nothing was scanned. This was a plain clickable hyperlink that simply used a shortener domain to mask its destination. The link text was framed as a harmless account convenience, the kind of "save your details for next time" prompt people click without thinking. It redirected to a contact-card-style landing page hosted on a major cloud content delivery network (CDN), built to harvest credentials.

That single link was the entire attack. One malicious URL in a sea of real ones, wearing the label of a feature nobody questions.

See Your Risk: Calculate how many threats your SEG is missing

Why Authentication Did Not Save Anyone

The uncomfortable part: this email passed everything. SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), DMARC (Domain-based Message Authentication, Reporting and Conformance), and ARC (Authenticated Received Chain) all passed for the hotmail[.]com envelope.

That is not a failure of the protocols. It is exactly what they are designed to do. Authentication confirms that a message genuinely came from the domain it claims and was not tampered with in transit. The email really was sent from a legitimate, authenticated Hotmail account. The protocols validated that fact perfectly. What they cannot do is judge whether the person behind an authenticated webmail account is the vendor rep their display name claims to be.

A legacy secure email gateway (SEG) leans hard on these signals plus reputation and known-bad indicators. A clean PDF, real vendor links, full authentication, and a modest dollar amount produce a green light. The Microsoft Digital Defense Report 2024 makes the same point at scale: identity-based and social-engineering attacks now dominate precisely because they ride legitimate infrastructure that reputation-based filtering trusts by default.

Detecting the Attack Nobody Flagged

This maps cleanly to MITRE ATT&CK Phishing (T1566), specifically Spearphishing Link (T1566.002). The catch is that no single indicator of compromise (IOC) here is damning on its own. Free webmail is normal. Shortener links are normal. Clean PDFs are normal. The signal lives in the combination.

That is where relationship and behavioral analysis earns its keep. IRONSCALES Themis, our Adaptive AI engine, models the organization's real communication graph: who normally emails whom, from which infrastructure, and in what pattern. Against that baseline, a trusted vendor identity suddenly arriving from a personal Hotmail account, carrying one lone shortener link buried in a legitimate thread, stops looking routine and starts looking exactly like what it is. You can see how that context-first approach works across the platform.

Defanged indicators from this case:

Indicators of Compromise

TypeIndicatorContext
URLhxxps://qrco[.]de/bdnh8BMalicious shortlink, display text "Save My Info," redirects to credential-harvesting page
Domainqrco[.]deQR-shortener domain used to mask redirect destination
Sendersmm[...]@hotmail[.]comAuthenticated personal webmail account, display name impersonating a known vendor rep

The Takeaway

Attackers have stopped trying to beat authentication and started living inside it. When the PDF is clean, the links are real, the name is familiar, and every protocol passes, the only thing left to catch is the one detail that does not fit the relationship. Teams that still equate "authenticated" with "safe" will keep waving these through. The defense is context: judging the message against how this vendor, this sender, and this thread normally behave. CISA's guidance on stopping the phishing attack cycle at phase one says the same thing in plainer terms. The email was real. That was the point.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
Remittance Phish Routes Through Nigerian Hosting to Edgeone Credential HarvestA payment remittance lure sent from a Nigerian IP through compromised shared hosting lands in a financial services inbox.
The Vendor Address Hiding in Plain Sight: How a Free Email Service Carried a B2B Impersonation Into a Real ThreadAn attacker embedded a vendor's real domain into the local part of a free webmail address.
SPF Pass, DKIM Pass, DMARC Pass. Still Phishing.A fully authenticated email from a cousin domain passed every gateway check while impersonating a known supplier contact and delivering a fraudulent...
Colleague-Confirmed Fraud: When the Invoice Already Has an Internal Warning AttachedAn invoice with a direct billpay link arrived from an established billing domain relayed via Barracuda.
A Google Redirect, a Monday.com Tracker, and a Fake NDA: Credential Harvesting Through Trusted InfrastructureA DocuSign NDA impersonation routed its primary CTA through a three-hop redirect chain: Google.com to Monday.com tracking service to a Zimbabwean domain.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.