Last year, we published a blog about financial fraud attacks using YOPmail. What made those attacks most interesting wasn’t the fraud, it was that the attackers used YOPmail, an anonymous email service that doesn’t require user authentication. This meant we were able to get into the attacker’s account to see what they’ve been up to, no password required.
Recently, we found a different kind of attack that gave us similar insights into the history of the adversary. In this case, we found attacks featuring a recycled W-9 that offered up PDF revision histories of different financial fraud scams.
Attack email
Here’s an example email from one of the attacks:

There’s a lot of redaction, but here’s the flow the bottom to the top:
- Fabricated pre-invoice notification: The first message in this fully fabricated email thread is from the CPO/COO of ServiceNow. It sets up the premise that the target company has recently implemented a ServiceNow analytics solution and that an invoice will be sent soon. Major indicators of malicious intent are: 1) the message was sent from an executive, 2) the sender’s email address is the
service-nowinc[.]comlookalike domain. - Impersonated confirmation and routing: The second message is from an impersonated employee at the target company. They are confirming that the invoice is expected and tell ServiceNow to send it to the target of the attack.
- Fabricated “missing invoice” email: The third message loses the plot a bit and features “late payment” verbiage. This is a standard tactic in driving urgency, though the lack of timestamps in the fabricated thread means the target needs to assume there was a gap between messages two and three. Just like with message one, this is an impersonated ServiceNow employee with a
service-nowinc[.]comemail. - Impersonated approval email from target company: The final message is a fake approval from the impersonated employee in message two that has been sent to the target of the attack. While the Display Name is a real employee, the message is sent from
info@nuf.co[.]jpwith the Reply-To addressi@domainlify[.]net.
Indicators of AI
While investigating the attack, we determined with relative certainty that the thread was generated with AI. Within the HTML, we observed comments between each message of the fake thread. These appear to be remnants of an LLM prompt:
Attachments
The fabricated thread contains two attachments. The first is a fake invoice that impersonates the billing vendor (ServiceNow) and aligns with the information in the attack email. It features a suspicious GO2BANK account account and asks for questions to be sent to the attacker controlled email gomez@service-nowinc[.]com:

The other attachment is a fake W-9 for the impersonated billing vendor. This is being used simply to increase believability, not as a payload:

Everything on this W-9 is publicly available information, making it easy for an attacker to create this form.
PDF attack history
While the W-9 was not a payload for the target, it did offer up interesting insights. PDFs contain a version history that can be sniffed out a few ways. In the case of this attack, we found that the W-9 was originally created for a “SCALED SOLUTIONS USA, LLC,” indicating that it had been used for a prior attack.
Using the versions within, we created an animated history of the PDF where you can see it start blank, get filled with Scaled Solutions information, and then get edited for the ServiceNow impersonation:

What makes this even more interesting is that during our investigation, we uncovered multiple other attacks using the same base “Scaled Solutions” PDF. In these similar attacks, we saw the same tactics (thread fabrication, financial urgency, fake invoice), but the W-9s were from a variety of impersonated vendors.
When we went through the revision histories of each of those W-9s, we found the same blank, scanned W-9 as the base revision, as well as the same “Scaled Solutions” information in the next set of revisions. This type of information can prove useful for detection engineers, threat intelligence analysts, threat researchers, and SOC teams performing investigations into threat actors.
Dig deeper at GrrCON
If you’re interested in learning how we investigated these attacks and analyzed their version histories, come to my “VIPs and Fake IDs: Investigating PDF Revisions” talk at GrrCON 2026 on Thurs., Sept. 24 at 4:30 p.m. ET.
Detection signals
Sublime's AI-powered detection engine detected this attack. Some of the top detection signals were:
- Fabricated approval chain: Attack centers around an artificially (likely AI) constructed email thread that creates false legitimacy for a fraudulent payment.
- Lookalike domain: Attack uses
service-nowinc[.]comto impersonate legitimate vendorservicenow[.]com. - Impersonation with domain mismatch: The fabricated thread references a real executive at the target company, but the final message is sent from
info@nuf.co[.]jpwith the employee name as the Display Name. The Reply-To features the same Display Name and the email addressi@domainlify[.]net. - Suspicious bank: GO2BANK is not used by major enterprises.
- Urgency: Attack uses late payment notice to create time pressure.
ASA, Sublime’s Autonomous Security Analyst, flagged this email as malicious. Here is ASA’s analysis summary from the first example:

So long and thanks for all the crumbs
History-filled PDFs aside, thread hijacking and fabrication is an increasingly popular tactic in modern, tailored attacks. In the case of thread hijacking, a threat actor will compromise an inbox, find an existing thread, and then use it to deliver a realistic attack. In the case of the above attack, we saw a fabricated thread that was potentially built using a real email from a different attack as the template. This tactic can prove difficult for legacy email security solutions to detect, making a strong case for AI-powered detection from Sublime.
If you enjoyed this Attack Spotlight, be sure to check our blog every week for new blogs, subscribe to our RSS feed, or sign up for our monthly newsletter. Our newsletter covers the latest blogs, detections, product updates, and more.
Read more Attack Spotlights:
Get the latest
Sublime releases, detections, blogs, events, and more directly to your inbox.






.avif)