INTERNAL DOCUMENT - EVIDENCE

Phishing Email Analysis

This is the email that was sent to multiple TechNova staff members on November 15, 2024, at approximately 9:00 AM.

⚠️ Key Indicators of Phishing:

  • From address domain: tecknova.com (missing 'h' - should be technova.com)
  • Link destination: backups-secure.net (not CloudSafe's domain)
  • Urgency tactics: "URGENT" and "expires in 24 hours"
  • Grammar issues: "require your immediate attention"
  • Generic greeting: "Dear Valued Customer" instead of personalized

Technical Analysis

Header Value Analysis
Return-Path bounce@mail-service-83.net Suspicious - doesn't match sender
SPF softfail Failed SPF check
DKIM none No DKIM signature
Reply-To no-reply@backups-secure.net Different domain

Victim Impact

Sarah Mitchell (Accounts Clerk) clicked the link and entered her credentials on the fake site at approximately 9:12 AM.

The attacker then used her credentials to:

  1. Log into the TechNova file server
  2. Navigate to the Invoices directory
  3. Download 23 customer invoice PDFs
  4. Modify the invoices with different bank account details
  5. Send the modified invoices to customers

← Back to Helpdesk Log | View Invoice Comparison →