On May 26, 2026, Foyl MailGuard quarantined a fraudulent invoice email (THREAT-003) targeting l.park (Procurement Department) at Ficsit Inc. Pioneer Division. The email appeared to originate from Acme Industrial Supplies, a legitimate active supplier of Ficsit, but was sent from a homoglyph domain: acme-industr1al.com — using the numeral "1" in place of the letter "l" in "industrial." The domain had been registered just 2 days prior to the attack and failed all email authentication checks (SPF, DKIM, and DMARC).
The email presented a fraudulent invoice (INV-2026-0847) for $23,847 covering a plausible industrial supply order ("Pioneer Division Equipment Maintenance Q2"). The invoice included altered banking details — routing the payment to the attacker's account rather than the legitimate Acme Industrial bank account on file. The email body directed l.park to process payment within 5 days using the attached invoice PDF.
The email was quarantined automatically by MailGuard on a combination of signals: homoglyph domain detection, fresh domain registration (2 days old), SPF/DKIM/DMARC triple failure, and payment detail change instruction. No financial loss occurred. l.park was unaware of the email. Vendor verification with Acme Industrial confirmed they did not send this invoice and are aware their brand is being spoofed.
acme-industr1al.com specifically to target Ficsit, indicating prior knowledge of Ficsit's active vendor relationships — specifically their use of Acme Industrial Supplies. This represents either an OSINT operation against Ficsit's public procurement disclosures, or reconnaissance gathered from a prior breach of Ficsit procurement communications.| Incident ID | VF-001 |
| Email Threat ID | THREAT-003 |
| Attack Type | Vendor Fraud via Homoglyph Domain / Invoice Fraud |
| Severity | High — Financial fraud attempt; vendor relationship intelligence required |
| Status | Closed — Email blocked; no payment made; vendor notified |
| Fraudulent Sender | billing@acme-industr1al.com (numeral 1 substituted for letter l) |
| Display Name | "Acme Industrial Supplies" (legitimate vendor name) |
| Legitimate Vendor Domain | acme-industrial.com |
| Fraudulent Domain | acme-industr1al.com |
| Domain Registered | May 24, 2026 — 2 days before attack |
| Registrar | GoDaddy — privacy protected registrant |
| Target | l.park@ficsit-pioneer.corp (Procurement Coordinator) |
| Invoice ID | INV-2026-0847 |
| Invoice Description | Pioneer Division Equipment Maintenance Q2 |
| Invoice Amount | $23,847 USD |
| Payment Due Date | 5 business days from date of invoice |
| Email Authentication | SPF FAIL, DKIM FAIL, DMARC FAIL (all three failed) |
| Email Disposition | QUARANTINE — not delivered to inbox |
| Detection Date | May 26, 2026 · 09:18 UTC |
| Financial Loss | $0 — payment never initiated |
| Vendor Notified | Yes — Acme Industrial confirmed domain is not theirs |
billing@acme-industr1al.com, display: "Acme Industrial Supplies". To: l.park@ficsit-pioneer.corp. Subject: "Invoice INV-2026-0847 — Pioneer Division Equipment Maintenance Q2". Attachment: INV-2026-0847.pdf (fraudulent invoice, 287 KB). SPF FAIL, DKIM FAIL, DMARC FAIL. Domain age: 2 days. MailGuard homoglyph detection flags acme-industr1al.com vs acme-industrial.com. Email quarantined. No inbox delivery.
A homoglyph attack (also called a lookalike domain or typosquat) exploits visual similarity between characters to register a domain that appears identical to a legitimate domain when read quickly. In this case, the numeral "1" (one) was substituted for the letter "l" (lowercase L) in "industrial" — a substitution that is virtually invisible in many fonts at normal reading sizes.
| Property | Legitimate Domain | Fraudulent Domain |
|---|---|---|
| Domain | acme-industrial.com | acme-industr1al.com (numeral 1) |
| Visual appearance | acme-industrial.com | acme-industr1al.com (near-identical in most fonts) |
| Registered | Long-established | May 24, 2026 — 2 days before attack |
| Registrar | Established corporate registrar | GoDaddy — privacy protected |
| MX records | Properly configured | Configured for sending only (no website) |
| SPF record | v=spf1 include:_spf.acme-industrial.com ~all | None — SPF FAIL |
| DKIM | Properly signed | Not configured — DKIM FAIL |
| DMARC | p=reject | None — DMARC FAIL |
The attacker chose this specific homoglyph technique because: (1) the substituted character is commonly confused in sans-serif fonts popular in email clients, (2) the domain was plausible enough to pass a quick human review, and (3) registering a homoglyph of an existing domain is easy and cheap. The domain had no website content, confirming it was registered solely for email-based fraud.
All three email authentication mechanisms failed for THREAT-003:
| Check | Result | Reason |
|---|---|---|
| SPF | FAIL | No SPF record published for acme-industr1al.com. Sending IP had no authorization. |
| DKIM | FAIL | No DKIM signing configured on acme-industr1al.com. Email unsigned. |
| DMARC | FAIL | No DMARC record on acme-industr1al.com. Even if SPF/DKIM had passed, they would not align with the claimed sender domain. Legitimate domain (acme-industrial.com) DMARC policy is p=reject. |
The fraudulent invoice (INV-2026-0847, PDF attachment) was crafted to mimic Acme Industrial Supplies' invoice format, including their logo and standard invoice layout. Key fraud indicators present in the invoice:
| Field | Fraudulent Invoice | Fraud Indicator |
|---|---|---|
| Invoice Number | INV-2026-0847 | Sequential number in a plausible format — but not in Acme's actual invoice numbering system |
| Description | "Pioneer Division Equipment Maintenance Q2" | Plausible service description; Ficsit does have maintenance contracts |
| Amount | $23,847.00 | Non-round number chosen to appear realistic rather than suspicious |
| Bank Details | Altered bank name, account, and routing numbers | Key fraud element — payment would route to attacker's account |
| Contact | billing@acme-industr1al.com / +1-555-0192 (fake) | Fraudulent contact details to intercept any verification calls |
| Sender domain in body | acme-industr1al.com throughout | Consistent fraudulent domain but visually nearly identical to legitimate |
| Payment terms | "Due within 5 business days" | Tight deadline creates urgency and discourages extended verification |
MailGuard flagged THREAT-003 via a combination of rules:
| Signal | Value | Source |
|---|---|---|
| Homoglyph domain detection | acme-industr1al.com matches vendor acme-industrial.com (Levenshtein distance 1, numeral/letter substitution) | MailGuard homoglyph engine |
| Domain age | 2 days — below 30-day threshold for known-vendor bypass | WHOIS lookup |
| SPF FAIL | No SPF record on sending domain | Email authentication |
| DKIM FAIL | Email unsigned | Email authentication |
| DMARC FAIL | No DMARC on sending domain; legitimate vendor has p=reject | Email authentication |
| Invoice + banking detail change | Email body instructs payment to new banking details different from vendor file | Content analysis |
| Vendor not in recent comms | No recent email from acme-industr1al.com (new domain) | Communication history |
| Tactic | Technique | ID | Observed Behavior |
|---|---|---|---|
| Reconnaissance | Gather Victim Identity Info | T1589 | Identified Ficsit's active vendor relationships (Acme Industrial) and procurement contact (l.park) via OSINT |
| Resource Dev. | Acquire Infrastructure: Domains | T1583.001 | Registered acme-industr1al.com (homoglyph of acme-industrial.com) via GoDaddy 2 days pre-attack |
| Initial Access | Phishing: Spearphishing Attachment | T1566.001 | Fraudulent invoice PDF delivered as spearphishing attachment to procurement contact |
| Social Engineering | Impersonation | T1656 | Vendor identity impersonated via homoglyph domain and display name matching legitimate vendor |
| Impact | Financial Theft | T1657 | $23,847 invoice fraud targeting altered banking details — payment would have gone to attacker account |
| Type | Value | Confidence | Description |
|---|---|---|---|
| Domain | acme-industr1al.com | Confirmed | Homoglyph fraudulent domain. Registered 2026-05-24 via GoDaddy. Configured for email only. Blocked at NGFW and email gateway. |
| billing@acme-industr1al.com | Confirmed | Fraudulent sending address. Blocked at email gateway. | |
| Invoice | INV-2026-0847 | Confirmed | Fraudulent invoice — $23,847 for "Pioneer Division Equipment Maintenance Q2." Confirmed by Acme Industrial as not issued by them. |
| Bank Account | Attacker bank account — details on file with Finance | Confirmed | Fraudulent banking details included in invoice PDF. Do not process payment to these details. Under investigation. |
| Display Name | Acme Industrial Supplies | Confirmed | Fraudulent display name used when sending from homoglyph domain. Add rule: Acme Industrial Supplies display name from non-acme-industrial.com domains should be blocked. |
| Time | Action | By | Status |
|---|---|---|---|
| 09:18 UTC | Email THREAT-003 quarantined — not delivered to l.park inbox | MailGuard (automated) | Completed |
| 09:18 UTC | Security analyst notified; VF-001 opened | MailGuard (automated) | Completed |
| 09:25 UTC | Homoglyph confirmed (acme-industr1al.com vs acme-industrial.com); WHOIS retrieved | Security analyst | Completed |
| 09:35 UTC | Acme Industrial contacted via on-file phone number — invoice confirmed fraudulent; vendor warned | Security analyst | Completed |
| 09:45 UTC | acme-industr1al.com blocked at NGFW and email gateway | Security analyst | Completed |
| 09:45 UTC | Domain submitted to threat intelligence; l.park confirmed unaware of email | Security analyst | Completed |
| 09:45 UTC | Procurement team briefed on homoglyph vendor fraud; do not process invoices from non-registered domains | Security analyst | Completed |
| 10:00 UTC | ICANN / GoDaddy abuse report filed for acme-industr1al.com | Security analyst | Completed |
| 10:00 UTC | VF-001 closed — no financial loss, all containment complete | Security analyst | Completed |
| Pending | Audit all registered vendor domains in approved vendor list for homoglyph exposure | Security / Procurement | Not Started |
| Pending | Implement vendor domain allowlist at email gateway | Security | Not Started |
VF-001 was a vendor impersonation invoice fraud blocked before any financial impact. The attack succeeded in reaching MailGuard — it was stopped by automated detection, not by process controls. If MailGuard had not detected it, the email may have reached l.park's inbox and been processed as a legitimate invoice, particularly given the plausible format and timing (Q2 maintenance invoices are expected in this period).
--- HEADERS ---
From: "Acme Industrial Supplies" <billing@acme-industr1al.com>
To: l.park@ficsit-pioneer.corp
Subject: Invoice INV-2026-0847 -- Pioneer Division Equipment Maintenance Q2
Date: Mon, 26 May 2026 09:17:53 +0000
Message-ID: <INVOICE-2026-0847@acme-industr1al.com>
Content-Type: multipart/mixed; boundary="boundary_inv_0847"
X-Mailer: PHPMailer 6.8.0
--- AUTHENTICATION ---
Authentication-Results: mx.ficsit-pioneer.corp;
spf=fail (no SPF record found for acme-industr1al.com)
dkim=fail (no DKIM signature)
dmarc=fail (no DMARC policy for acme-industr1al.com;
legitimate domain acme-industrial.com policy=reject)
--- MAILGUARD ANALYSIS ---
Vendor-fraud confidence: HIGH
Homoglyph match: acme-industr1al.com ≈ acme-industrial.com [Levenshtein=1, numeral/letter sub]
Domain age: 2 days (registered 2026-05-24)
Invoice content: payment instructions present
Banking detail change: DETECTED (differs from vendor file on record)
SPF: FAIL | DKIM: FAIL | DMARC: FAIL
Action: QUARANTINE incident=VF-001
--- BODY ---
Dear l.park,
Please find attached invoice INV-2026-0847 for Pioneer Division Equipment
Maintenance services delivered in Q2 2026.
Invoice #: INV-2026-0847
Date: May 25, 2026
Amount Due: $23,847.00 USD
Due Date: June 2, 2026 (5 business days)
Please process payment to our updated banking details (please note our
banking information has recently changed):
Bank: Pioneer Commerce Bank
Account: [REDACTED FOR REPORT — on file with Finance]
Routing: [REDACTED FOR REPORT — on file with Finance]
Payee: Acme Industrial Supplies
If you have any questions, please contact us at:
billing@acme-industr1al.com or +1-555-0192
Thank you for your continued business.
Best regards,
Robert Haines
Accounts Receivable
Acme Industrial Supplies
billing@acme-industr1al.com
The following comparison illustrates how the homoglyph substitution is nearly invisible in common email client fonts. Security awareness training should include this type of comparison.
Legitimate vendor domain: acme-industrial.com Position 14: l ← lowercase letter "L" Fraudulent domain (this incident): acme-industr1al.com Position 14: 1 ← numeral "one" In common sans-serif fonts (Arial, Helvetica, Calibri, etc.): "l" and "1" appear nearly identical. Visual appearance in most email clients: acme-industrial.com ← legitimate acme-industr1al.com ← FRAUDULENT (visually indistinguishable without zoom) Additional homoglyphs that should be monitored (not yet observed): acme-industria1.com (numeral 1 for final l) acme-industrla1.com (transposition + numeral) acme-1ndustrial.com (numeral 1 for capital I)