3.0 KiB
3.0 KiB
Phishing Investigation — "Past Due - AMU54618 - AMYSH Solutions"
- Date (UTC): 2026-07-15
- Tenant: cascadestucson.com (
207fa277-e9d8-4eb7-ada1-1064d2221498) - Reported by: Chris Knight (via Mike/Howard)
- Investigated with: ComputerGuru Security Investigator (Graph read + EXO read), read-only
The message
| Field | Value |
|---|---|
| From | Dax Howard <info@syufway.com> |
| Reply-To | dax.howard@steqm.com (mismatch — classic BEC indicator) |
| To | accounting@cascadestucson.com (only recipient in tenant) |
| Subject | Past Due - AMU54618 - AMYSH Solutions |
| Delivered | 2026-07-14 17:32 UTC (10:32 AM AZ) |
| Internet-Message-Id | <NSCCVAyTgUFD3cMIwaf4nl5G1cSc5xC4W4Cr1Rrk0c@localhost> |
| Attachment | W9_AMYSH_Solutions54618.pdf (84 KB) |
Two delivery attempts ~10s apart:
- 17:30:23 UTC — Quarantined as High Confidence Phish (never released).
- 17:30:34 UTC — Delivered to the Inbox (second copy evaded the filter).
Attachment analysis
The PDF is a filled IRS W-9 for "AMYSH Solutions", EIN 92-4058031, 75 E Santa Clara St, San Jose CA 95113, signed 04/11/2026. No URLs, no QR code, no active content. This is a vendor-impersonation / BEC setup: get the target to onboard a fake vendor and pay a fraudulent invoice. The email body claims to forward an invoice from "Skylar Green, Billing Coordinator, AMYSH Solutions".
Who opened it (MailItemsAccessed audit, delivered copy)
Mailbox delegates with FullAccess: ashley.jensen, lauren.hasselman, zachary.nelson, Chris.Knight.
| Time (UTC) | User | Client |
|---|---|---|
| 2026-07-14 17:32:06 | ashley.jensen@cascadestucson.com | Outlook Android |
| 2026-07-14 17:33:30 | Chris.Knight@cascadestucson.com | Outlook desktop |
| 2026-07-14 18:16:43 | ashley.jensen@cascadestucson.com | Outlook Android |
| 2026-07-14 18:54:59 | Chris.Knight@cascadestucson.com | Outlook desktop |
Did anyone respond / act on it?
- No outbound mail from the tenant to
info@syufway.comor the reply-todax.howard@steqm.com(message trace 07-13 → 07-15). Nobody replied. - No link/click risk — the PDF contains no links.
- Risk is limited to future action: paying the fake invoice or emailing the reply-to address.
Verdict
Confirmed phishing (vendor-fraud/BEC lure). Defender already classified the first copy as High Confidence Phish. Opened by Ashley Jensen and Chris Knight; no reply, no click, no payment action observed. No compromise indicated.
Remediation performed (2026-07-15, approved by Howard)
- [OK] Delivered copy moved to Deleted Items in the accounting mailbox (recoverable if ever needed for evidence).
- [OK]
syufway.comandsteqm.comadded to the Tenant Allow/Block List (Sender block, no expiration) — future mail from either domain is blocked. - Quarantined copy left in quarantine (High Confidence Phish, not released).
Remaining advice for client
- Do not pay invoice AMU54618 or contact the sender.
- Any real vendor banking/W-9 changes get phone verification on a known-good number.