Table of Contents
The message had a spotless authentication record. SPF, DKIM, and DMARC all passed. It carried no link and no attachment. And it was still one of the cleaner business email compromise attempts a small firm's inbox saw that quarter, because the only thing the attacker forged was a name.
The display name read like a senior leader at the recipient's own company, the firm's principal. The body claimed an invoice from Vistage Worldwide was more than 60 days overdue, instructed the recipient to process payment immediately, and asked that the payment confirmation be forwarded on once it was done. Vistage is a real executive-coaching and peer-advisory membership organization, which is exactly why its name works as a plausible line item in a professional-services firm's books.
Everything else about the message was a fabrication riding legitimate infrastructure.
A Clean Authentication Record for a Dirty Message
The email was relayed through Amazon Simple Email Service (SES), a mainstream sending platform that thousands of legitimate businesses use every day. Sender Policy Framework (SPF) passed on the SES address. DomainKeys Identified Mail (DKIM) was signed and aligned to both amazonses.com and the account's actual configured sending domain, an unrelated third-party domain with no connection to the recipient, the impersonated executive, or Vistage. Domain-based Message Authentication, Reporting and Conformance (DMARC) passed under a p=NONE policy for that same header From. Microsoft's compound authentication logged compauth=pass reason=100.
That is a full technical pass, and it means precisely nothing about the sender's honesty. Authentication answers one question: did this domain really send this message. It does not answer the question that matters here: is the human named in the display field who they claim to be. SES will faithfully sign for whatever domain an account owner configures, so an attacker who controls a throwaway or abused domain inherits a clean authentication verdict without ever touching the identity they are actually impersonating.
The Display Name Did All the Work
The true From address belonged to that unrelated third-party domain, not to any executive. But most mail clients hide the address and surface the display name, and the display name was a real VIP inside the recipient's own company. When a name a recipient recognizes as leadership appears next to a payment request, the reflex is to comply rather than to expand the header and inspect the address behind it. There was no link to hover, no attachment to detonate, nothing for a signature engine or a sandbox to chew on. The entire attack surface was a string of text and the authority attached to it.
IRONSCALES flagged the message as a confirmed VIP impersonation, with the impersonation signal set true and Themis, the Adaptive AI analyst on the IRONSCALES platform, scoring it at 90 percent confidence. The incident auto-resolved as phishing.
Two Reply-To Escape Hatches
The tell that turns this from a suspicious note into a deliberate operation is the reply path. The message carried two separate Reply-To addresses on two different attacker-registered domains. One was a lookalike of the real Vistage domain, vistage-worldwideinc[.]com, which has no affiliation with the genuine organization at vistage.com. The other, executives-portals-email[.]com, was a second diversion domain themed to sound like an executive mailbox.
Neither routes back to the real leader. Any recipient who hit reply to ask a clarifying question, to confirm the amount, or to flag that the invoice looked unfamiliar would have their message land on infrastructure the attacker controlled. That dual Reply-To pattern is a hallmark of invoice-fraud business email compromise: the sender never needs a link or a malicious file, only a believable pretext and a captured reply channel to walk the victim toward wiring money and then confirming it externally.
See Your Risk: Calculate how many threats your SEG is missing
Mapping to MITRE ATT&CK
The tradecraft maps cleanly onto the MITRE ATT&CK framework. The core deception is T1656 Impersonation, the use of a trusted leader's display name and a known vendor brand to manufacture legitimacy. The payment-confirmation ask, engineered to open a reply thread and extract a wire and its confirmation without any technical payload, aligns to T1598 Phishing for Information.
Indicators of Compromise
| Type | Indicator | Context |
|---|---|---|
| Reply-To domain | vistage-worldwideinc[.]com | Lookalike of the real vistage.com, unaffiliated with the genuine organization; primary reply diversion |
| Reply-To domain | executives-portals-email[.]com | Second attacker-registered reply diversion domain themed as an executive mailbox |
| Reply-To address | admin@executives-portals-email[.]com | Secondary reply alias for the spoofed executive identity |
Detection and What to Watch For
Signature and reputation checks were never going to catch this. The sending platform is legitimate, the authentication is genuine, and there is no payload to scan. Detection has to move to behavior and relationships. The signals that matter are a trusted internal display name paired with an external, unrelated sending domain, a fabricated overdue invoice from a vendor the finance team may or may not actually use, and reply paths that resolve to freshly registered lookalike domains rather than to the person named up top.
This is the ground where behavioral analysis earns its keep, reading the relationship between the claimed identity, the true sending domain, and the reply routing the way a trained analyst would. The 2024 Verizon Data Breach Investigations Report names pretexting, largely business email compromise, as the top social-engineering incident type, with a median BEC transaction near 50,000 dollars and the human element present in 68 percent of breaches. The Microsoft Digital Defense Report 2024 documents the same drift toward abusing trusted services instead of breaking them, and the FBI's 2023 Internet Crime Report has long ranked business email compromise among the costliest categories of cybercrime by reported loss. Across 35,000+ security professionals and 17,000+ organizations, the IRONSCALES community sees this pattern land daily.
The Takeaway
A perfect authentication verdict is not a verdict on trust. When SPF, DKIM, and DMARC all pass, they are vouching for a domain, not for the name a reader sees or the invoice in front of them. The defense is to treat display names as decoration, verify vendor invoices through a known channel rather than by replying to the message that requested payment, and watch the reply path as closely as the From line. Pair that discipline with behavioral detection and you close the exact gap this campaign was built to exploit. See where invoice fraud and business email compromise risk hides in your own mail flow, because the next VIP-branded invoice is already drafted. CISA's guidance on recognizing and stopping phishing early is a solid team reference: https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one
Related attacks
| Attack | What happened |
|---|---|
| Shell International Impersonated in BEC Invoice Fraud: DMARC Failure Exposes the Lookalike Payment Chain | An attacker spoofed Shell International's From header with a debt-collection urgency lure, then pointed payment to two attacker-controlled domains. |
| The Confidential Mode Message That Had Zero Indicators of Compromise | A Gmail Confidential Mode message copied an internal employee's display name, passed SPF/DKIM/DMARC/ARC with every link pointing to Google. |
| The Reply-To Was One Letter Off: How a Typosquat Domain Turned a Gmail BEC Into a Payment Diversion | A Gmail-authenticated BEC used a typosquat Reply-To domain and a hidden HTML mailto mismatch to impersonate a steel distributor's credit manager. |
| The PayPal Invoice That Passed Every Check Because PayPal Actually Sent It | A canceled PayPal invoice for $50 arrived with perfect SPF, DKIM, and DMARC authentication because PayPal's own infrastructure sent it. |
| Past Due Invoice, Future Wire Fraud: How a BEC Campaign Passed Every Authentication Check | A BEC invoice diversion attack impersonated a known vendor contact through SendGrid, passed SPF/DKIM/DMARC. |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.