Table of Contents
One mailbox at a home care and senior in-home care services company received an overdue-invoice notice. The amount it demanded was $4,827,603,074,863, roughly $4.8 trillion, a number larger than the annual output of most national economies, dropped into a five-line email as if it were an ordinary accounts-payable reminder.
The attached invoice, the artifact the message actually wanted the recipient to open, showed a grand total of $229.99.
Neither figure is the story. Both artifacts print the same reference identifier, so they were emitted together by the same tooling, and that tooling filled one of them with a plausible software renewal total and the other with garbage. The message also carried no links at all. Its only call to action was a phone number, and that number never appeared as text.
Two Invoices, Two Amounts, One Reference Number
The body was terse. It opened by introducing a name as calling from the accounting department, cited invoice ORD-JX8WH46R as overdue, gave the absurd balance, told the recipient to pay at a bare unexplained string, printed a reference UUID, and signed off as an entirely different name. Four anchors point to that signature identity: the alias, the sender address, the return path, and a support-location line printed on the invoice image. Two point to the accounting-department identity: the opening sentence, and the attachment's filename.
The attachment was a JPEG styled as an Adobe Acrobat invoice, its billing date matching the send day. It carried its own invoice number, ZMPABX-3092-5416, one line item for an annual Acrobat Pro subscription, and a grand total of $229.99. The trillion-dollar figure appears nowhere on it. Two invoice numbers, two amounts orders of magnitude apart, one shared reference UUID.
That shared identifier rules out the mundane explanation. This is not an operator attaching the wrong file. It is one generation run producing two inconsistent renderings of the same fictional transaction, which means the eye-catching number sits in the throwaway half of the payload while the half designed to be believed stays deliberately boring.
The Kit Left Its Own Merge Field Unfilled
The image confirms the malfunction on its face. Its refund-policy line offers a full refund within 12 hours of purchase by calling support at #TFN1#, an unsubstituted merge token sitting in delivered content, inside the same artifact that otherwise renders a convincing brand invoice layout. The kit filled the phone number into three other places on that page and missed this one.
Two more strings have no explanation available. The body's payment instruction points at a short alphanumeric target with no domain, protocol, or account, and the image prints a login key that corresponds to nothing else in the message. Given the confirmed placeholder bug, both read as further kit artifacts, and nobody can say what either was supposed to become.
For defenders that is usable. A specific unrendered token, a body amount that contradicts the attachment amount, and one reference ID spanning two invoice numbers are fingerprints of one operator's tooling, and they will outlast the sending domain.
The Entire Call to Action Was Rendered as Pixels
The platform's own extraction of message links returned an empty set. Structurally, not narratively, there was nothing to click. Instead the message carried a toll-free number printed three times inside the image: a support line in the header, a hotline block near the bottom, and an inline mention in an auto-renewal cancellation instruction. In the text of the email, that number does not exist.
This is telephone-oriented delivery, which MITRE ATT&CK tracks as spearphishing voice and defenders know as callback phishing or vishing, wrapped in the attachment-based delivery of MITRE ATT&CK. The combination is awkward to inspect. URL reputation and detonation have no input, pattern matching over body text finds no number and no brand name, and a JPEG with no embedded exploit hashes clean. Everything load-bearing is a picture of text, and the NIST definition of phishing turns on deception rather than payload.
The pattern is not a rounding error either. The 2026 Verizon Data Breach Investigations Report publishes a monthly breakdown of attacks blocked by email security gateways, drawing on gateway telemetry from a contributing vendor rather than on Verizon's own measurement, and in that data a median 5 percent of blocked attacks each month are attempts at getting the victim to call back to the attacker. Losses concentrate in fraud that needs a human, not malware: the 2025 FBI IC3 Annual Report puts cyber-enabled fraud at 45 percent of complaints but 85 percent of all reported losses, $17.697 billion of $20.877 billion.
See Your Risk: Calculate how many threats your SEG is missing
Authentication Told Only Half the Story
The sending domain was not registered that morning. It went up roughly a year before the attack through a mainstream registrar with registrant details behind a privacy shield, so heuristics keyed to newly observed domains stayed quiet. The operator had also provisioned it on a mainstream workspace provider, so DKIM passed cleanly under a provider-generated signing identity and the mail arrived over legitimate provider relay infrastructure. The pass proves a tenant controls that domain. It says nothing about who the tenant is.
SPF returned a softfail, because the domain's own record does not authorize the provider address that delivered the mail, and the domain published no DMARC record at all, so the softfail carried no enforcement. Under RFC 9989 that is a domain owner declining to state a preference, and a control that resolves a mixed result by taking the strongest passing signature reads this as ordinary provider mail.
What the Adaptive AI Weighed Instead
With no URL verdict to inherit and no detonation to wait for, the evaluable material was identity and behavior: a first-time sender to the organization, a body that introduces one accounting contact and signs as another, a brand invoice arriving as an image rather than a document, a mixed authentication posture with no policy behind it, and a payment demand nobody had authorized. Themis, the IRONSCALES Adaptive AI analyst, scored the message at 87 percent confidence and labelled it credential theft. The incident auto-resolved as phishing with one mailbox affected.
That label is worth reporting honestly rather than smoothing. There is no credential page in this message and no form to submit. The route to credentials runs through the call, where an operator handles objections live and steers toward remote access, a card capture framed as cancelling the charge, or a refund walked through the victim's own banking portal. That is where credential harvesting happens in a case like this, off the wire and out of the logs.
What To Take From This Case
Three changes pay for themselves. Treat rendered attachment content as message content, which means running optical character recognition over inbound images and scoring what the picture says, not just its hash. Compare amounts across artifacts rather than scoring magnitude in isolation, because the absurd number and the believable number sat in one message and only one was meant to be acted on. And alert on unrendered merge tokens in mail and attachments, since a delivered placeholder is never legitimate.
For the people receiving these, CISA phishing guidance reduces to one instruction that covers the class: never dial a number printed inside an attachment. Look the vendor up independently, then report the message.
Indicators of Compromise
| Type | Indicator | Context |
|---|---|---|
| cmonge_2024.co@sulsel[.]top | Sender From header and envelope return path, presented under a two-word personal alias that matches the body's closing signature | |
| Domain | sulsel[.]top | Attacker-registered sending domain, provisioned as a workspace tenant, registered roughly a year before the attack through a mainstream registrar behind WHOIS privacy, SPF softfail, no DMARC record published |
| Phone | +1 (855) 789-4598 | Sole call to action, rendered only as pixels inside the attached image and repeated in a support line, a hotline block, and an auto-renewal cancellation instruction, never present as text |
| File | JPEG attachment, MD5 d856e66324fcea0acf87a2d765da5613, 72,526 bytes, 958x1356 pixels | Fake Adobe Acrobat invoice image, filename set to the persona named in the body's opening line, scanned clean with no embedded payload |
| Artifact | Invoice number ZMPABX-3092-5416, grand total $229.99 | Identifiers printed on the invoice image, a plausible annual subscription renewal total |
| Artifact | Invoice number ORD-JX8WH46R, amount $4,827,603,074,863 | Body-text invoice, bearing no relationship to the attachment's invoice number or amount |
| Artifact | Reference UUID f3f71b9f-da1b-488a-9466-cd962e365638 | Printed identically in the body and on the invoice image, tying the two mismatched invoices to a single generation run |
| Artifact | #TFN1# | Unsubstituted merge-field placeholder left inside the image's refund-policy text, direct evidence of a malfunctioning kit |
| Artifact | permanent63 | Unexplained payment target given in the body with no domain, protocol, or account, likely a further kit artifact |
| Artifact | Login key 3XPLOCU616QCJ3 | Unexplained token printed on the invoice image, corresponding to nothing else in the message |
| Subject | "Purchase record has been finalized ORD-93/W00N3_I6PC1-71" | Purchase-confirmation pretext whose order reference matches neither invoice number in the message |
| DKIM | sulsel-top.20251104.gappssmtp[.]com, selector 20251104 | Provider-generated signing identity for the attacker's own domain, so the pass is native rather than evidence of a third-party compromise |
| IP | 209[.]85[.]220[.]65 | Legitimate provider relay that delivered the message, not authorized in the sending domain's own SPF record |
| IP | 102[.]133[.]206[.]106 | Originating-IP header value with no reverse DNS on record, unrelated to the relay that delivered the mail |
| Behavior | Zero URLs in the entire message, link extraction returned empty | Structural absence of clickable content, leaving URL reputation and detonation with no input |
MITRE ATT&CK Mapping
| Technique | ID | Application |
|---|---|---|
| Phishing: Spearphishing Attachment | T1566.001 | The entire lure delivered as an image attachment styled as a brand invoice, with the body text reduced to a broken pointer |
| Phishing: Spearphishing Voice | T1566.004 | A callback number printed three times inside the attachment as the message's only actionable instruction |
| Impersonation | T1656 | A major software brand impersonated in a fabricated subscription invoice, with two attacker-crafted staff personas and a fabricated support address |
See You Next Time
A kit that cannot make its own two invoices agree still got a working phone number into an inbox. Polish was never the requirement. Check back tomorrow.
Related attacks
| Attack | What happened |
|---|---|
| A Real Datadog Report, a Fake Bill, One Phone Number | A scheduled dashboard report arrived from Datadog's own reporting infrastructure, with real Datadog links and a real Datadog PDF attached. |
| A Fake McAfee Bill From a Domain the Attacker Owned | A fake $299 McAfee renewal notice passed SPF, DKIM and DMARC without a single forged header. |
| A Real Zoom Alert, Resent by the Attacker Who Asked for It | Zoom really sent this sign-in alert. |
| Real Intuit Invoice, Fake Geek Squad Bill, One Phone Number | A past-due Geek Squad invoice arrived through real Intuit QuickBooks infrastructure. |
| McAfee Renewal Scam Sent Under the Victim's Own Name | A fake McAfee renewal receipt carried no link and no attachment. |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.