TL;DR One HTML body carried two unrelated messages. The visible card named no organization at all and pushed a callback number. Roughly 822 pixels of spacer below it sat a state workforce-agency letter with the agency's real postal address, real social profiles, and an unfilled kit placeholder pointing at a search engine. The display name was a Latin-looking word built from Cyrillic homoglyphs. Authentication passed cleanly on an unrelated 25-year-old domain, and the only payload was a telephone number, so link, file and domain-age controls had nothing to act on.
Severity: High Callback-Phishing Social-Engineering Account-Compromise Brand-Impersonation MITRE: T1566.004 MITRE: T1586.002 MITRE: T1684.001

Earlier this summer, three mailboxes at a digital-asset investment management firm received the same construction inside two and a half hours, each under a different subject line with its own invented ticket number. Nothing about the message failed. SPF passed. DKIM passed. DMARC passed. The sending domain had been registered a quarter of a century ago and was running its own webmail stack. There were no attachments, no QR codes and no credential-harvest URLs, and every link in the body resolved to a real social media profile or to a major search engine, all of which scanned clean.

And yet the message did not agree with itself at any layer.

Four Layers, Four Different Stories

The From display name looked like an ordinary English word, but a codepoint dump showed otherwise: four of its letters were Cyrillic homoglyphs, with an invisible Unicode tag character prepended and a copyright sign bolted on the end. Rendered, it reads as the name of a well-known on-chain crypto analytics provider, exactly the vendor category a digital-asset fund deals with weekly. That provider appears nowhere else in the message: no text, no URL, no branding.

Now the visible body. The card that renders above the fold names no organization whatsoever. Its logo slot is a Content-ID reference to an inline image, cid:SSSSS.png, and the platform record's attachment array is empty, so no such part ever existed and the logo renders broken. The headline announces that the recipient's primary form of contact was recently switched, a callout box shows a partially masked number, (310) *** 1218, and a dark panel offers a customer care line whose only actionable element is a tel: link to +1 (888) 857 9196. The sign-off is generic, and the footer says not to reply.

Then comes the spacer: a single div with a line height of 823 pixels and a height of 822 pixels, sitting between that card and the rest of the document. Be precise here, because it is not concealment: no display rule, no zero-height font, no white-on-white text. The second block is fully readable, simply pushed below the fold, and a recipient who scrolls finds a completely different letter.

That second letter is warm workforce-services outreach signed by a named staffer with the job title of an employment program representative at the California Employment Development Department, the state's benefits and workforce agency. It is not from the agency. The agency is the impersonated party here, and there is no evidence of any compromise on its side. What the operator did copy in is genuine: the agency's real Sacramento post office box, and its authentic Facebook, Instagram and X profiles, which is why all of those links scanned clean. Borrowed trust does not need to be malicious to work.

The kit gave itself away in the same signature. Where the agency's own web address belongs, the "on the web" line still reads hxxp://www[.]google[.]com, an unfilled placeholder nobody populated. And the signature's phone number, 866-217-1218, shares its final four digits with the masked number displayed in the card above it, under a different area code, in a message that otherwise claims no relationship between the two blocks.

The Payload Is a Telephone Number

Strip the incoherence away and the operational design is very clean. There is no attacker-owned domain in this message. No landing page, no attachment, no hash, no redirect chain, no newly registered infrastructure. The entire payload is a phone number, which is what makes this a vishing problem wearing an email envelope. MITRE ATT&CK tracks the pattern as spearphishing voice, T1566.004.

Every control that normally earns its keep had nothing to touch. URL reputation had no URL. Sandboxing had no file. Domain-age heuristics saw a domain older than most of the stack examining it. Lookalike and cousin-domain scoring both need a domain that is trying to resemble something, and this one was not trying at all. The 2026 Verizon Data Breach Investigations Report finds phishing in 16% of breaches as the initial access vector, with newly tracked pretexting at 6% of initial access vectors. The shape of this case is why those numbers stay stubborn: the pretext is the attack, and the pretext is not a file.

See Your Risk: Calculate how many threats your SEG is missing

Authentication Was Never the Question

The submission headers explain how a clean pass happened. The message was submitted as an authenticated user of that Chinese company's own webmail, with the platform recording the authenticated username and an originating IP geolocated to Phoenix, in the United States, well outside the company's own network. From there it relayed out through the company's real mail server and was signed with the domain's own DKIM selector. That mismatch points strongly to credential abuse rather than a forged sender, though the record proves control of the mailbox, not how it was obtained. Either way the domain owner is a bystander here, not the attacker. ATT&CK covers the tradecraft as compromising email accounts, T1586.002, with the display-name trick as impersonation, T1684.001.

One caveat matters on the DMARC result. The pass was recorded under a monitor-only policy, p=none, which means the receiver evaluated alignment and was instructed to take no action on failure. As the current DMARC specification, RFC 9989, makes plain, policy is a request to the receiver, and a pass under p=none is a measurement rather than an enforcement outcome. Reading it as a trust signal is precisely the inversion this message relied on.

What Actually Caught It

Not the sender. The platform's own brand-impersonation detector recorded no impersonation on that display name, a fair result when the Cyrillic characters string-match nothing and the sending domain resembles neither brand in the body.

What produced the verdict was Themis, our Adaptive AI analyst, at confidence 83, and the composition of that score is the whole lesson. Two insight categories contributed: content analysis of the language and structure, and community signal, where similar incidents resolved as phishing across other tenants. The sender-analysis category was empty. The sender genuinely looked fine, so the decision had to come from what the message said and from what 36,000+ security professionals across 18,000+ organizations had already resolved on messages built the same way. All three mailboxes were quarantined automatically within six to seven seconds of receipt, and the incident closed as phishing without an analyst touching it.

What to Do With a Lure That Has No Infrastructure

Treat the callback number as the indicator of record, and feed lure numbers into detection content the way you would feed a domain. Neither number in this message appears among the telephone numbers published on the agency's official contact directory page, a check that takes seconds. Note that ownership of both numbers is unattributed here; absence from a published directory is not proof of who answers.

Two habits do more than any filter. First, treat any inbound claim that a primary contact has changed as a verification event, never an instruction, and confirm it through a channel you already had before the message arrived. CISA's phishing guidance and the NIST definition of phishing both frame the lure as the control point for exactly this reason. Second, stop reading an authentication pass as a verdict on content. It tells you the path was authorized. In this case the path was entirely authorized, and every brand named along it was somebody else's.

Indicators of Compromise

TypeIndicatorContext
Phone+1 (888) 857 9196tel: link in the visible card, presented as a customer care line. The primary callback payload. Ownership unattributed; absent from the 22 numbers on the impersonated agency's published contact directory page.
Phone866-217-1218tel: link in the below-the-fold agency-styled signature. Ownership unattributed and presented only in the lure; absent from that same published directory page. Shares its final four digits with the masked card number.
Phone (masked)(310) *** 1218Lure prop in the card's callout box, not a dialable number. Same trailing digits as the signature number.
IP20[.]168[.]9[.]87Originating IP of the authenticated webmail submission, geolocated to Phoenix, USA, outside the sending company's own network.
URLhxxp://www[.]google[.]comUnfilled kit placeholder in the "on the web" slot of the agency-styled signature. Template artifact, not attacker infrastructure.
File referencecid:SSSSS.pngContent-ID for the card's 160-pixel header logo. No matching part exists in the message, so the logo renders broken. Placeholder-shaped kit artifact.
HTML artifactSpacer div, line-height 823px / height 822pxSeparates two unrelated messages in one body. A whitespace pusher, not CSS concealment.
String9c4ef82c1a207886Mailer-ID header value on a message that never traversed an email service provider. Fingerprint string only.
String693913af3c90612877b3429aa450e5ba85130469Opaque data-tokenized attribute on the body's charset meta tag. Kit fingerprint.
String100f376de38790e3f34a1680953d8a0dPrinted as a message identifier in the card footer, distinct from the real message-id header. Kit fingerprint.
String5f5e7266ab1737dc676f316cePrinted as a reference identifier in the card footer. Kit fingerprint.
Subject patternWe have been trying to reach you. Mail# plus nine digitsThree rotating subject variants across three mailboxes in about 2.5 hours, each with a fabricated ticket number.

MITRE ATT&CK Mapping

TechniqueIDObserved as
Phishing: Spearphishing VoiceT1566.004The only payload in the message is a callback number wired as a tel: link, with no URL, attachment or QR code.
Compromise Accounts: Email AccountsT1586.002Authenticated webmail submission on a long-established third-party domain from an IP outside that company's network.
Social Engineering: ImpersonationT1684.001Cyrillic-homoglyph display name rendering as a crypto analytics vendor, plus a state agency's real address and social profiles reused below the fold.
Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
The Phish Zoom Signed With Its Own DKIM KeyBy every cryptographic measure, this email really was from Zoom: DKIM verified, DMARC passed under a reject policy, sent on Zoom infrastructure.
A Same-Day Domain, a McAfee Calendar Invite, Two PricesA McAfee renewal scam arrived as a Google Calendar invite from a domain registered the same day.
The Fake McAfee Renewal Typed Into a Calendar FieldThe scam copy was typed into a calendar event's description field, so Google's own notifier wrote and delivered it from a real.
The Partner Invite That Used the Wrong Sending DomainA calendar invite appeared to be from an IRONSCALES employee arranging an ANZ distribution call.
A Real Zoom Alert, Resent by the Attacker Who Asked for ItZoom really sent this sign-in alert.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.