Family Sentinel
Scam Watch · August 27, 2026 · 4 min read

A purchase order email that passes every security check — and how to verify it in 60 seconds

A new attack campaign is sending fake vendor quotes and invoice requests to small organizations through mail servers that have been quietly taken over — so every technical security check passes. The only reliable defense is the simplest one: ask the person who would have made the request.

Business email compromise — scams that impersonate vendors, suppliers, or colleagues to trick organizations into paying fraudulent invoices or opening malicious files — cost American organizations more than $3 billion in 2025 alone, according to the FBI's Internet Crime Complaint Center. The average loss per complaint was over $122,000. Churches, nonprofits, and small community organizations are not too small to be targets; they are often preferred because they have fewer safeguards than a corporation.

This month, cybersecurity researchers at Breakglass Intelligence and several other firms documented a specific campaign that is worth knowing about — not because the technical details are unusual, but because it is engineered to defeat the warning signs that most people have learned to watch for.

What is arriving in inboxes right now

The emails arrive with subject lines that blend into the everyday correspondence of any organization that handles purchasing: "RFQ — please review and confirm," "Revised pricing for your upcoming order," or "Attached: quote for requested supplies." They appear to come from a supplier or vendor — often one your organization might plausibly do business with.

The attachment is an image file, typically a PNG. There is nothing in the body of the email that looks suspicious: no unusual links, no urgent request for wire transfer, no misspelled words. The email reads like a normal piece of business correspondence.

Inside the image, hidden using a technique called steganography, is a malicious program. Steganography — the practice of concealing information inside an ordinary-looking file — allows attackers to hide executable code inside what appears to be a photograph or product picture. When a staff member opens the attachment, that hidden program runs silently in the background.

What the program is after

The malicious program's goal is credential theft — collecting account access information from the computer it runs on. It gathers:

All of this is sent silently to the attacker. There is no ransom message, no visible sign that anything has happened. The staff member goes back to work, and the attacker now has the keys to accounts that may include your organization's financial systems, email, and donor records.

Why the usual warning signs are missing

Email security has gotten good at catching malicious messages because harmful emails usually carry something that can be flagged: a link to an unfamiliar website, an attachment type that raises alerts, or a sender whose domain does not match who they claim to be.

This campaign avoids all of those tells. Attackers are routing the emails through real mail servers belonging to legitimate businesses that have been quietly compromised. Because the message travels through a real server:

The only reliable signal that something is wrong exists outside the email entirely: no one at your organization actually requested this quote.

The one check that defeats this attack: Before anyone on your team opens an attachment on a vendor invoice or purchase order — especially an image file — someone should ask the person who would have made the request: "Did we reach out to this vendor?" If the answer is no, do not open the attachment. This step cannot be automated, which is exactly why it works.

What to do — the 60-second protocol

  1. Before opening any attachment, confirm the request internally. Find the office manager, bookkeeper, facilities coordinator, or pastor who would have initiated a vendor conversation and ask: "Did we contact this company?" Take sixty seconds before clicking anything. If no one recognizes the request, delete the email without opening it.
  2. Do not reply to the email to verify. If the sender's mail account has been taken over, the attacker may be monitoring replies. Call the vendor directly using a phone number from your own records — a number you look up yourself, not a number printed in the email.
  3. Treat image attachments with the same care as programs. A legitimate vendor quote nearly always arrives as a PDF, a spreadsheet, or a Word document — not a PNG or JPEG. An image file attached to a purchase order or invoice is worth pausing over, even if everything else looks normal.
  4. Make sure every team member knows this protocol — not just the person who usually handles purchasing. The regular office manager may be out on any given day. One brief team conversation about this before it happens is more valuable than any software filter after the fact.
  5. If someone already opened a suspicious attachment, act quickly. Change passwords on every financial account, email account, and donor management or membership system immediately — starting with anything connected to money. Notify your bank that there may have been a credential theft. Do not wait to see whether anything goes wrong.
  6. Report it. Forward suspicious emails to the FBI's Internet Crime Complaint Center at ic3.gov. You can also send them to security@familysentinel.org for a free second opinion — no charge, no obligation.

Related reading

We watch the email that starts this attack.

The protocol above stops this campaign — but it requires someone to run it every time a vendor email arrives. Family Sentinel monitors your organization's inbox around the clock for exactly the behavioral patterns these attacks carry: procurement-themed messages with image attachments, sender addresses that pass authentication but have no history with your domain, and the email signatures that name-brand credential-theft campaigns leave behind. We flag them before anyone on your team has to make a judgment call. No software to install, no passwords to share — and a real Security Architect is behind every alert we send.

Book a free 20-minute checkup →

Want the next threat before it reaches you?

Scam Watch goes out regularly — the newest scams and how to spot them, in plain English. Free.

Written by the Family Sentinel security desk — a working Security Architect and the team who watch organizational inboxes for a living. Sources: FBI Internet Crime Complaint Center (IC3) 2025 Annual Report (BEC losses and per-complaint averages); Breakglass Intelligence, "PhantomStealer v3.5.0 Resurfaces: RFQ-Themed Spear Phishing Targets Procurement Staff via Compromised Chilean SMTP Relay," August 2026; Group-IB Phantom Stealer analysis; ThreatseEye.io, "Phantom Stealer: PNG Steganography & PowerShell Injection," August 2026. Questions about a suspicious email your organization received? Forward it to security@familysentinel.org or call (940) 281-6672 — no charge, no strings.