# Phishing Investigation — "Past Due - AMU54618 - AMYSH Solutions" - **Date (UTC):** 2026-07-15 - **Tenant:** cascadestucson.com (`207fa277-e9d8-4eb7-ada1-1064d2221498`) - **Reported by:** Chris Knight (via Mike/Howard) - **Investigated with:** ComputerGuru Security Investigator (Graph read + EXO read), read-only ## The message | Field | Value | |---|---| | From | Dax Howard `` | | Reply-To | `dax.howard@steqm.com` (mismatch — classic BEC indicator) | | To | `accounting@cascadestucson.com` (only recipient in tenant) | | Subject | Past Due - AMU54618 - AMYSH Solutions | | Delivered | 2026-07-14 17:32 UTC (10:32 AM AZ) | | Internet-Message-Id | `` | | Attachment | `W9_AMYSH_Solutions54618.pdf` (84 KB) | Two delivery attempts ~10s apart: 1. **17:30:23 UTC — Quarantined** as **High Confidence Phish** (never released). 2. **17:30:34 UTC — Delivered** to the Inbox (second copy evaded the filter). ## Attachment analysis The PDF is a filled **IRS W-9** for "AMYSH Solutions", EIN 92-4058031, 75 E Santa Clara St, San Jose CA 95113, signed 04/11/2026. **No URLs, no QR code, no active content.** This is a vendor-impersonation / BEC setup: get the target to onboard a fake vendor and pay a fraudulent invoice. The email body claims to forward an invoice from "Skylar Green, Billing Coordinator, AMYSH Solutions". ## Who opened it (MailItemsAccessed audit, delivered copy) Mailbox delegates with FullAccess: ashley.jensen, lauren.hasselman, zachary.nelson, Chris.Knight. | Time (UTC) | User | Client | |---|---|---| | 2026-07-14 17:32:06 | ashley.jensen@cascadestucson.com | Outlook Android | | 2026-07-14 17:33:30 | Chris.Knight@cascadestucson.com | Outlook desktop | | 2026-07-14 18:16:43 | ashley.jensen@cascadestucson.com | Outlook Android | | 2026-07-14 18:54:59 | Chris.Knight@cascadestucson.com | Outlook desktop | ## Did anyone respond / act on it? - **No outbound mail** from the tenant to `info@syufway.com` or the reply-to `dax.howard@steqm.com` (message trace 07-13 → 07-15). Nobody replied. - No link/click risk — the PDF contains no links. - Risk is limited to *future action*: paying the fake invoice or emailing the reply-to address. ## Verdict Confirmed phishing (vendor-fraud/BEC lure). Defender already classified the first copy as High Confidence Phish. Opened by Ashley Jensen and Chris Knight; no reply, no click, no payment action observed. **No compromise indicated.** ## Remediation performed (2026-07-15, approved by Howard) 1. [OK] Delivered copy moved to Deleted Items in the accounting mailbox (recoverable if ever needed for evidence). 2. [OK] `syufway.com` and `steqm.com` added to the Tenant Allow/Block List (Sender block, no expiration) — future mail from either domain is blocked. 3. Quarantined copy left in quarantine (High Confidence Phish, not released). ## Remaining advice for client - Do not pay invoice AMU54618 or contact the sender. - Any real vendor banking/W-9 changes get phone verification on a known-good number.