11/17/2025
Scammers are getting smarter. One of my clients received this email this morning — and on the surface, everything looked legitimate. The company name and website are real, the message passed every security check, and nothing in the email itself raised any flags.
The problem shows up when you click the “resolve transaction” link. It redirects to a spoofed site that tries to make you download a “PDF” file… which is actually a piece of malware disguised as a PDF (notice the .pdf.msi). This is exactly how attackers slip past normal defenses and trick people into installing malicious software.