Table of Contents
A facilities-management team at a large healthcare system opened a forwarded email that looked exactly like the dozens of vendor quotes they process every week. The subject line carried a bid reference and a purchase order (PO) number. The attachment was a clean PDF quote for a modest amount, a few hundred dollars. The body linked to the vendor's real website and a real ordering portal. Every signal said routine procurement. Only two things were wrong: one link, and one letter in a name.
The Setup: A Forwarded Quote From a Familiar Name
The message arrived as a forwarded thread, the kind that reads like a colleague passing along a supplier's reply. "Fwd:" in the subject, a bid number, a PO reference. The content was a plausible quote conversation, the sort of back-and-forth that happens a hundred times a day inside any procurement workflow.
The sender's display name matched a known external vendor contact the team had worked with. That is the part the human eye locks onto. Most mail clients surface the friendly display name and tuck the actual address out of sight. So the recipient saw a trusted supplier rep, not the underlying account, which was a personal Hotmail address that had nothing to do with the vendor's real domain.
This is vendor email compromise (VEC), a branch of business email compromise that hijacks the trust living inside a supplier relationship. The attacker did not need to breach the vendor. They only needed to look like the vendor for the length of one email.
One Letter, One Login: The Display-Name Lookalike
The impersonation was flagged as a "Similar Display Name" match, and that word "similar" is the whole game. Attackers rarely need a perfect clone. A near-match display name, close enough to pass a glance, riding on a free webmail account, is enough to borrow a real person's authority.
The 2024 Verizon Data Breach Investigations Report puts the human element in 68% of breaches, and the median time for a target to click a phishing link at just 21 seconds. A procurement specialist scanning a familiar-looking quote does not spend 21 seconds auditing the raw From header. They see a name they recognize and move to the next task. The human element is not a weakness to shame; it is the surface every one of these attacks is engineered to exploit.
The Poisoned Link Hiding in Plain Sight
Here is where the craft shows. The email was not a crude lure with a single obvious hook. It was a real-looking quote reply stuffed with legitimate links: the vendor's actual website, a genuine ordering portal, the kind of references a real thread would contain. Everything checked out.
Hidden among those clean links sat exactly one that did not: a shortlink on a QR-shortener domain, hxxps://qrco[.]de/bdnh8B, with display text reading "Save My Info." No QR image was rendered and nothing was scanned. This was a plain clickable hyperlink that simply used a shortener domain to mask its destination. The link text was framed as a harmless account convenience, the kind of "save your details for next time" prompt people click without thinking. It redirected to a contact-card-style landing page hosted on a major cloud content delivery network (CDN), built to harvest credentials.
That single link was the entire attack. One malicious URL in a sea of real ones, wearing the label of a feature nobody questions.
See Your Risk: Calculate how many threats your SEG is missing
Why Authentication Did Not Save Anyone
The uncomfortable part: this email passed everything. SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), DMARC (Domain-based Message Authentication, Reporting and Conformance), and ARC (Authenticated Received Chain) all passed for the hotmail[.]com envelope.
That is not a failure of the protocols. It is exactly what they are designed to do. Authentication confirms that a message genuinely came from the domain it claims and was not tampered with in transit. The email really was sent from a legitimate, authenticated Hotmail account. The protocols validated that fact perfectly. What they cannot do is judge whether the person behind an authenticated webmail account is the vendor rep their display name claims to be.
A legacy secure email gateway (SEG) leans hard on these signals plus reputation and known-bad indicators. A clean PDF, real vendor links, full authentication, and a modest dollar amount produce a green light. The Microsoft Digital Defense Report 2024 makes the same point at scale: identity-based and social-engineering attacks now dominate precisely because they ride legitimate infrastructure that reputation-based filtering trusts by default.
Detecting the Attack Nobody Flagged
This maps cleanly to MITRE ATT&CK Phishing (T1566), specifically Spearphishing Link (T1566.002). The catch is that no single indicator of compromise (IOC) here is damning on its own. Free webmail is normal. Shortener links are normal. Clean PDFs are normal. The signal lives in the combination.
That is where relationship and behavioral analysis earns its keep. IRONSCALES Themis, our Adaptive AI engine, models the organization's real communication graph: who normally emails whom, from which infrastructure, and in what pattern. Against that baseline, a trusted vendor identity suddenly arriving from a personal Hotmail account, carrying one lone shortener link buried in a legitimate thread, stops looking routine and starts looking exactly like what it is. You can see how that context-first approach works across the platform.
Defanged indicators from this case:
Indicators of Compromise
| Type | Indicator | Context |
|---|---|---|
| URL | hxxps://qrco[.]de/bdnh8B | Malicious shortlink, display text "Save My Info," redirects to credential-harvesting page |
| Domain | qrco[.]de | QR-shortener domain used to mask redirect destination |
| Sender | smm[...]@hotmail[.]com | Authenticated personal webmail account, display name impersonating a known vendor rep |
The Takeaway
Attackers have stopped trying to beat authentication and started living inside it. When the PDF is clean, the links are real, the name is familiar, and every protocol passes, the only thing left to catch is the one detail that does not fit the relationship. Teams that still equate "authenticated" with "safe" will keep waving these through. The defense is context: judging the message against how this vendor, this sender, and this thread normally behave. CISA's guidance on stopping the phishing attack cycle at phase one says the same thing in plainer terms. The email was real. That was the point.
Related attacks
| Attack | What happened |
|---|---|
| Remittance Phish Routes Through Nigerian Hosting to Edgeone Credential Harvest | A payment remittance lure sent from a Nigerian IP through compromised shared hosting lands in a financial services inbox. |
| The Vendor Address Hiding in Plain Sight: How a Free Email Service Carried a B2B Impersonation Into a Real Thread | An attacker embedded a vendor's real domain into the local part of a free webmail address. |
| SPF Pass, DKIM Pass, DMARC Pass. Still Phishing. | A fully authenticated email from a cousin domain passed every gateway check while impersonating a known supplier contact and delivering a fraudulent... |
| Colleague-Confirmed Fraud: When the Invoice Already Has an Internal Warning Attached | An invoice with a direct billpay link arrived from an established billing domain relayed via Barracuda. |
| A Google Redirect, a Monday.com Tracker, and a Fake NDA: Credential Harvesting Through Trusted Infrastructure | A DocuSign NDA impersonation routed its primary CTA through a three-hop redirect chain: Google.com to Monday.com tracking service to a Zimbabwean domain. |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.