TL;DR One mailbox at a home care and senior in-home care services company received an overdue-invoice notice claiming a balance of 4,827,603,074,863 dollars. The attached image, a fake Adobe Acrobat invoice, showed a grand total of 229.99 dollars, with a different invoice number but the same reference ID as the body. The message carried zero links. Its only call to action was a phone number rendered three times as pixels inside that image. The same image left an unfilled merge-field placeholder inside its refund policy, so the kit's quality-control failure is visible in the artifact. Adaptive AI scored it 87 percent.
Severity: High Callback-Phishing Vishing Brand-Impersonation Image-Based-Phishing Invoice-Fraud MITRE: T1566.001 MITRE: T1566.004 MITRE: T1656

One mailbox at a home care and senior in-home care services company received an overdue-invoice notice. The amount it demanded was $4,827,603,074,863, roughly $4.8 trillion, a number larger than the annual output of most national economies, dropped into a five-line email as if it were an ordinary accounts-payable reminder.

The attached invoice, the artifact the message actually wanted the recipient to open, showed a grand total of $229.99.

Neither figure is the story. Both artifacts print the same reference identifier, so they were emitted together by the same tooling, and that tooling filled one of them with a plausible software renewal total and the other with garbage. The message also carried no links at all. Its only call to action was a phone number, and that number never appeared as text.

Two Invoices, Two Amounts, One Reference Number

The body was terse. It opened by introducing a name as calling from the accounting department, cited invoice ORD-JX8WH46R as overdue, gave the absurd balance, told the recipient to pay at a bare unexplained string, printed a reference UUID, and signed off as an entirely different name. Four anchors point to that signature identity: the alias, the sender address, the return path, and a support-location line printed on the invoice image. Two point to the accounting-department identity: the opening sentence, and the attachment's filename.

The attachment was a JPEG styled as an Adobe Acrobat invoice, its billing date matching the send day. It carried its own invoice number, ZMPABX-3092-5416, one line item for an annual Acrobat Pro subscription, and a grand total of $229.99. The trillion-dollar figure appears nowhere on it. Two invoice numbers, two amounts orders of magnitude apart, one shared reference UUID.

That shared identifier rules out the mundane explanation. This is not an operator attaching the wrong file. It is one generation run producing two inconsistent renderings of the same fictional transaction, which means the eye-catching number sits in the throwaway half of the payload while the half designed to be believed stays deliberately boring.

The Kit Left Its Own Merge Field Unfilled

The image confirms the malfunction on its face. Its refund-policy line offers a full refund within 12 hours of purchase by calling support at #TFN1#, an unsubstituted merge token sitting in delivered content, inside the same artifact that otherwise renders a convincing brand invoice layout. The kit filled the phone number into three other places on that page and missed this one.

Two more strings have no explanation available. The body's payment instruction points at a short alphanumeric target with no domain, protocol, or account, and the image prints a login key that corresponds to nothing else in the message. Given the confirmed placeholder bug, both read as further kit artifacts, and nobody can say what either was supposed to become.

For defenders that is usable. A specific unrendered token, a body amount that contradicts the attachment amount, and one reference ID spanning two invoice numbers are fingerprints of one operator's tooling, and they will outlast the sending domain.

The Entire Call to Action Was Rendered as Pixels

The platform's own extraction of message links returned an empty set. Structurally, not narratively, there was nothing to click. Instead the message carried a toll-free number printed three times inside the image: a support line in the header, a hotline block near the bottom, and an inline mention in an auto-renewal cancellation instruction. In the text of the email, that number does not exist.

This is telephone-oriented delivery, which MITRE ATT&CK tracks as spearphishing voice and defenders know as callback phishing or vishing, wrapped in the attachment-based delivery of MITRE ATT&CK. The combination is awkward to inspect. URL reputation and detonation have no input, pattern matching over body text finds no number and no brand name, and a JPEG with no embedded exploit hashes clean. Everything load-bearing is a picture of text, and the NIST definition of phishing turns on deception rather than payload.

The pattern is not a rounding error either. The 2026 Verizon Data Breach Investigations Report publishes a monthly breakdown of attacks blocked by email security gateways, drawing on gateway telemetry from a contributing vendor rather than on Verizon's own measurement, and in that data a median 5 percent of blocked attacks each month are attempts at getting the victim to call back to the attacker. Losses concentrate in fraud that needs a human, not malware: the 2025 FBI IC3 Annual Report puts cyber-enabled fraud at 45 percent of complaints but 85 percent of all reported losses, $17.697 billion of $20.877 billion.

See Your Risk: Calculate how many threats your SEG is missing

Authentication Told Only Half the Story

The sending domain was not registered that morning. It went up roughly a year before the attack through a mainstream registrar with registrant details behind a privacy shield, so heuristics keyed to newly observed domains stayed quiet. The operator had also provisioned it on a mainstream workspace provider, so DKIM passed cleanly under a provider-generated signing identity and the mail arrived over legitimate provider relay infrastructure. The pass proves a tenant controls that domain. It says nothing about who the tenant is.

SPF returned a softfail, because the domain's own record does not authorize the provider address that delivered the mail, and the domain published no DMARC record at all, so the softfail carried no enforcement. Under RFC 9989 that is a domain owner declining to state a preference, and a control that resolves a mixed result by taking the strongest passing signature reads this as ordinary provider mail.

What the Adaptive AI Weighed Instead

With no URL verdict to inherit and no detonation to wait for, the evaluable material was identity and behavior: a first-time sender to the organization, a body that introduces one accounting contact and signs as another, a brand invoice arriving as an image rather than a document, a mixed authentication posture with no policy behind it, and a payment demand nobody had authorized. Themis, the IRONSCALES Adaptive AI analyst, scored the message at 87 percent confidence and labelled it credential theft. The incident auto-resolved as phishing with one mailbox affected.

That label is worth reporting honestly rather than smoothing. There is no credential page in this message and no form to submit. The route to credentials runs through the call, where an operator handles objections live and steers toward remote access, a card capture framed as cancelling the charge, or a refund walked through the victim's own banking portal. That is where credential harvesting happens in a case like this, off the wire and out of the logs.

What To Take From This Case

Three changes pay for themselves. Treat rendered attachment content as message content, which means running optical character recognition over inbound images and scoring what the picture says, not just its hash. Compare amounts across artifacts rather than scoring magnitude in isolation, because the absurd number and the believable number sat in one message and only one was meant to be acted on. And alert on unrendered merge tokens in mail and attachments, since a delivered placeholder is never legitimate.

For the people receiving these, CISA phishing guidance reduces to one instruction that covers the class: never dial a number printed inside an attachment. Look the vendor up independently, then report the message.

Indicators of Compromise

TypeIndicatorContext
Emailcmonge_2024.co@sulsel[.]topSender From header and envelope return path, presented under a two-word personal alias that matches the body's closing signature
Domainsulsel[.]topAttacker-registered sending domain, provisioned as a workspace tenant, registered roughly a year before the attack through a mainstream registrar behind WHOIS privacy, SPF softfail, no DMARC record published
Phone+1 (855) 789-4598Sole call to action, rendered only as pixels inside the attached image and repeated in a support line, a hotline block, and an auto-renewal cancellation instruction, never present as text
FileJPEG attachment, MD5 d856e66324fcea0acf87a2d765da5613, 72,526 bytes, 958x1356 pixelsFake Adobe Acrobat invoice image, filename set to the persona named in the body's opening line, scanned clean with no embedded payload
ArtifactInvoice number ZMPABX-3092-5416, grand total $229.99Identifiers printed on the invoice image, a plausible annual subscription renewal total
ArtifactInvoice number ORD-JX8WH46R, amount $4,827,603,074,863Body-text invoice, bearing no relationship to the attachment's invoice number or amount
ArtifactReference UUID f3f71b9f-da1b-488a-9466-cd962e365638Printed identically in the body and on the invoice image, tying the two mismatched invoices to a single generation run
Artifact#TFN1#Unsubstituted merge-field placeholder left inside the image's refund-policy text, direct evidence of a malfunctioning kit
Artifactpermanent63Unexplained payment target given in the body with no domain, protocol, or account, likely a further kit artifact
ArtifactLogin key 3XPLOCU616QCJ3Unexplained token printed on the invoice image, corresponding to nothing else in the message
Subject"Purchase record has been finalized ORD-93/W00N3_I6PC1-71"Purchase-confirmation pretext whose order reference matches neither invoice number in the message
DKIMsulsel-top.20251104.gappssmtp[.]com, selector 20251104Provider-generated signing identity for the attacker's own domain, so the pass is native rather than evidence of a third-party compromise
IP209[.]85[.]220[.]65Legitimate provider relay that delivered the message, not authorized in the sending domain's own SPF record
IP102[.]133[.]206[.]106Originating-IP header value with no reverse DNS on record, unrelated to the relay that delivered the mail
BehaviorZero URLs in the entire message, link extraction returned emptyStructural absence of clickable content, leaving URL reputation and detonation with no input

MITRE ATT&CK Mapping

TechniqueIDApplication
Phishing: Spearphishing AttachmentT1566.001The entire lure delivered as an image attachment styled as a brand invoice, with the body text reduced to a broken pointer
Phishing: Spearphishing VoiceT1566.004A callback number printed three times inside the attachment as the message's only actionable instruction
ImpersonationT1656A major software brand impersonated in a fabricated subscription invoice, with two attacker-crafted staff personas and a fabricated support address

See You Next Time

A kit that cannot make its own two invoices agree still got a working phone number into an inbox. Polish was never the requirement. Check back tomorrow.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
A Real Datadog Report, a Fake Bill, One Phone NumberA scheduled dashboard report arrived from Datadog's own reporting infrastructure, with real Datadog links and a real Datadog PDF attached.
A Fake McAfee Bill From a Domain the Attacker OwnedA fake $299 McAfee renewal notice passed SPF, DKIM and DMARC without a single forged header.
A Real Zoom Alert, Resent by the Attacker Who Asked for ItZoom really sent this sign-in alert.
Real Intuit Invoice, Fake Geek Squad Bill, One Phone NumberA past-due Geek Squad invoice arrived through real Intuit QuickBooks infrastructure.
McAfee Renewal Scam Sent Under the Victim's Own NameA fake McAfee renewal receipt carried no link and no attachment.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.