Case Study Feature Image - 2026 Invoice Fraud Email Compromise at Clean Energy Manufacturer - Field of solar panels with wind turbines in the distance
Unmasking an Invoice Fraud Email Compromise at Clean Energy Manufacturer
See how Quisitive security experts found and stopped a hijacked mailbox running targeted invoice fraud through a look-alike domain at a major clean energy manufacturer.
Quisitive Spyglass Security Management Program Logo

In this case study:

Industry: Manufacturing

 

Products and Services:

Spyglass Managed Security Services

 

Location: USA

Executive Summary

The manufacturer contacted Quisitive after its team saw what appeared to be a large-scale email-spoofing problem: thousands of messages using the company's own domains seemed to be arriving from outside its network. At the same time, finance staff had reported a suspicious change to a live customer invoice thread. Leadership needed to know whether they were facing a mass spoofing campaign, an account compromise, or both.

 

Quisitive's investigation cut through the noise and separated two very different issues. The perceived "mass spoofing" was largely a false positive: a simple IP-based heuristic was flagging the company's own legitimate mail from remote staff and sanctioned relays. Microsoft Defender's authoritative message-authentication verdict showed that 100% of inbound mail claiming the company's domains actually passed authentication. Meaning, there was no mass spoofing campaign.

 

The real threat was far more targeted. A single finance mailbox had been compromised after a credential-phishing email, with the sign-in evidence pointing to session-token theft that bypassed the mailbox's existing multi-factor authentication. The attacker inserted a fraudulent "revised invoice" into a genuine customer thread, hid the customer's replies with an inbox rule, and worked through an attacker-controlled look-alike domain: a near-identical typosquat of the company's real domain - to impersonate an accounts-receivable contact.

 

Because the fraudulent invoice was delivered to the customer from a domain outside the company's tenant, it was invisible to the company's own logs. That made the top priority an out-of-band call to the customer: the FBI's Internet Crime Complaint Center logged $3.05 billion in reported business email compromise losses in 2025 across 24,768 complaints - roughly $123,000 per reported incident [1] - and redirected funds are frequently unrecoverable once a wire clears.

 

Quisitive contained the incident - rolling credentials and sessions, removing the malicious rule, and blocking the look-alike domain - and delivered a prioritized roadmap built on controls the company already owned.

The Numbers at a Glance

100%

Of inbound mail claiming the company's domains passed authentication. The "mass spoofing" was a false positive.

One

Compromised finance mailbox driving all of the targeted invoice fraud

126,551

Messages were analyzed across a 10-day window to separate real mail from noise.

The Challenge

The company's IT team was staring at a confusing picture.

 

A message-trace review appeared to show tens of thousands of emails using the company's own domains arriving from external, non-Microsoft IP addresses - the classic signature of "Direct Send" domain spoofing. On its face, it looked like the organization was being impersonated to its customers and partners at scale.

 

But the volume did not add up, and a separate, quieter signal was more alarming: finance had noticed something wrong with a real customer invoice thread. Three questions needed answers quickly, because each pointed to a different response - and the wrong assumption could waste critical time:

  • Was this a genuine mass spoofing campaign, or was legitimate business mail being misread as an attack?
  • Had one or more mailboxes - especially in finance - actually been compromised?
  • Was money already at risk, and were customers or suppliers being defrauded in the company's name?

The stakes were financial and reputational. As a manufacturer with distributed operations, the company had many legitimate senders using its domains from outside Microsoft's network, which made naive spoofing detection unreliable. Quisitive needed to establish ground truth fast, without disrupting the mail flow that the business runs on.

Quisitive's Approach

Quisitive ran the engagement in disciplined phases, prioritizing evidence that could be proven deterministically over assumptions - and pivoting hard the moment the data revealed a genuine compromise.

1. Separate the noise from the signal

Quisitive analyzed ten days of message-trace data and, crucially, compared the naive IP-based heuristic against Microsoft Defender's authoritative composite-authentication verdict (SPF, DKIM, and DMARC combined).

 

The heuristic flagged roughly 19,000 owned-domain messages from non-Microsoft IPs; the authoritative verdict showed every one of the inbound owned-domain messages actually passed authentication.

 

The "mass spoofing" was the company's own remote staff and sanctioned relays - a false positive, proven from the tenant's own records.

2. Follow the real anomaly into a compromise investigation

With the spoofing noise cleared, Quisitive focused on the finance signal.

 

Correlating mailbox activity with identity sign-in logs, Quisitive reconstructed a clean account-takeover timeline: a phishing lure, failed sign-in attempts, and then a successful sign-in from an anonymizing VPN in which multi-factor authentication was satisfied. This was a pattern more consistent with stolen session tokens than with a guessed password.

3. Map the fraud, the tradecraft, and the blast radius

Quisitive profiled the attacker's activity inside the mailbox: the hidden inbox rule, the injected "revised invoice," and the self-deletion of the sent message.

 

Quisitive then swept the rest of the accounts receivable and accounts payable functions to confirm whether any other customer or supplier relationships had been hijacked.

What Quisitive Found

The "spoofing flood" was largely a false positive

The single most important early finding was what was NOT happening. There was no mass Direct Send spoofing campaign. The alarming volume was inflated by legitimate senders - remote finance staff, an on-site business-application relay, and a sanctioned learning-management platform - all using the company's domains from non-Microsoft IPs.

 

Proving this from the authoritative authentication verdict let the team stop chasing a phantom and concentrate resources on the genuine threat.

A single finance mailbox was compromised

One accounts-receivable mailbox was taken over after the user received a credential-phishing email. The attacker's successful sign-in came from an anonymizing VPN with multi-factor authentication already satisfied, a pattern consistent with session-token theft rather than a simple password compromise. The attacker then operated from the mailbox over several days via Outlook on the web.

Targeted invoice fraud through a look-alike domain

Inside the mailbox, the attacker ran a precise, low-noise fraud. They created a hidden inbox rule that automatically marked the target customer's replies as read and moved them out of sight, injected a fraudulent "revised invoice" into a genuine customer thread, and impersonated an accounts-receivable contact using a typosquat domain nearly identical to the company's own. Because the fraud was routed through that external look-alike domain, any altered banking details sent onward to the customer never appeared in the company's own telemetry - only the customer could confirm what they received.

Contained scope, with clear follow-up

A tenant-wide sweep of the finance function confirmed the fraud was contained to a single customer thread - no other invoice conversation had been hijacked. Two supplier bank-detail changes were reviewed and assessed legitimate, though flagged for routine out-of-band verification before payment. The realism of the attack made a small number of high-priority, phone-based confirmations the essential next step.

The Solutions and Results

Quisitive gave the company a clear, evidence-backed separation of noise from real risk, contained the active compromise, and delivered a prioritized plan that closes the exact path the attacker used. The immediate actions:

  1. Call the affected customer out-of-band on a known-good number - because the fraud left the tenant, a direct call was the only control that could stop a redirected wire before it cleared.
  2. Contain the compromised identity - revoke all sessions and tokens, reset credentials, re-register multi-factor authentication, and remove the hidden inbox rule.
  3. Block the look-alike domain at the tenant level so it can no longer be used to impersonate the company.

For durable protection, Quisitive's highest-leverage recommendation cost the company nothing new: nine Conditional Access policies already existed in the tenant but were running in report-only mode. Enforcing them - together with phishing-resistant MFA and token protection for finance and admins - directly defeats the token-replay technique used in this incident. Microsoft's 2025 Digital Defense Report quantifies the gap that step closes: phishing-resistant MFA blocks more than 99% of identity-based attacks, while token theft and adversary-in-the-middle techniques make up under 3% of identity compromise attempts - the narrow slice that conventional MFA does not stop, and precisely where this incident landed [3].

 

Quisitive also recommended rejecting unauthenticated Direct Send, progressing DMARC to a reject policy with DKIM on all sending domains, enabling Defender impersonation protection for finance and executive users, and - most cost-effective of all - a mandatory out-of-band verification step before any bank-detail or invoice change is actioned. That control is the cheapest defense available against the most common fraud attempt organizations face: the Association for Financial Professionals' 2026 Payments Fraud and Control Survey found 74% of organizations were affected by business email compromise in 2025 - a marked increase over the prior two years [2].

What Quisitive Found

The company came to Quisitive believing it faced a mass spoofing campaign. It left with proof that the "campaign" was largely its own legitimate mail, a reconstructed fraud timeline it would not have found on its own, a contained incident, and a roadmap built almost entirely on controls it already owned, all delivered without disrupting the mail flow the business depends on.

Sources

[1] Federal Bureau of Investigation, Internet Crime Complaint Center. 2025 Internet Crime Report, April 2026. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf

 

[2] Association for Financial Professionals. 2026 AFP Payments Fraud and Control Survey Report, underwritten by Truist, April 14, 2026. https://www.financialprofessionals.org/training-resources/resources/survey-research-economic-data/details/payments-fraud

 

[3] Microsoft. Microsoft Digital Defense Report 2025, October 2025. https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2025