Files
claudetools/clients/cascades-tucson/reports/2026-07-15-phish-investigation-amu54618.md
Howard Enos 71aa0da646 sync: auto-sync from HOWARD-HOME at 2026-07-15 11:39:11
Author: Howard Enos
Machine: HOWARD-HOME
Timestamp: 2026-07-15 11:39:11
2026-07-15 11:39:45 -07:00

3.0 KiB

Phishing Investigation — "Past Due - AMU54618 - AMYSH Solutions"

  • Date (UTC): 2026-07-15
  • Tenant: cascadestucson.com (207fa277-e9d8-4eb7-ada1-1064d2221498)
  • Reported by: Chris Knight (via Mike/Howard)
  • Investigated with: ComputerGuru Security Investigator (Graph read + EXO read), read-only

The message

Field Value
From Dax Howard <info@syufway.com>
Reply-To dax.howard@steqm.com (mismatch — classic BEC indicator)
To accounting@cascadestucson.com (only recipient in tenant)
Subject Past Due - AMU54618 - AMYSH Solutions
Delivered 2026-07-14 17:32 UTC (10:32 AM AZ)
Internet-Message-Id <NSCCVAyTgUFD3cMIwaf4nl5G1cSc5xC4W4Cr1Rrk0c@localhost>
Attachment W9_AMYSH_Solutions54618.pdf (84 KB)

Two delivery attempts ~10s apart:

  1. 17:30:23 UTC — Quarantined as High Confidence Phish (never released).
  2. 17:30:34 UTC — Delivered to the Inbox (second copy evaded the filter).

Attachment analysis

The PDF is a filled IRS W-9 for "AMYSH Solutions", EIN 92-4058031, 75 E Santa Clara St, San Jose CA 95113, signed 04/11/2026. No URLs, no QR code, no active content. This is a vendor-impersonation / BEC setup: get the target to onboard a fake vendor and pay a fraudulent invoice. The email body claims to forward an invoice from "Skylar Green, Billing Coordinator, AMYSH Solutions".

Who opened it (MailItemsAccessed audit, delivered copy)

Mailbox delegates with FullAccess: ashley.jensen, lauren.hasselman, zachary.nelson, Chris.Knight.

Time (UTC) User Client
2026-07-14 17:32:06 ashley.jensen@cascadestucson.com Outlook Android
2026-07-14 17:33:30 Chris.Knight@cascadestucson.com Outlook desktop
2026-07-14 18:16:43 ashley.jensen@cascadestucson.com Outlook Android
2026-07-14 18:54:59 Chris.Knight@cascadestucson.com Outlook desktop

Did anyone respond / act on it?

  • No outbound mail from the tenant to info@syufway.com or the reply-to dax.howard@steqm.com (message trace 07-13 → 07-15). Nobody replied.
  • No link/click risk — the PDF contains no links.
  • Risk is limited to future action: paying the fake invoice or emailing the reply-to address.

Verdict

Confirmed phishing (vendor-fraud/BEC lure). Defender already classified the first copy as High Confidence Phish. Opened by Ashley Jensen and Chris Knight; no reply, no click, no payment action observed. No compromise indicated.

Remediation performed (2026-07-15, approved by Howard)

  1. [OK] Delivered copy moved to Deleted Items in the accounting mailbox (recoverable if ever needed for evidence).
  2. [OK] syufway.com and steqm.com added to the Tenant Allow/Block List (Sender block, no expiration) — future mail from either domain is blocked.
  3. Quarantined copy left in quarantine (High Confidence Phish, not released).

Remaining advice for client

  • Do not pay invoice AMU54618 or contact the sender.
  • Any real vendor banking/W-9 changes get phone verification on a known-good number.