S
Stitex
Security

The “Complaint” Phishing Attack on Business Email

A staple of business phishing: an email with the subject “Complaint” or “Claim”, a short businesslike message and a single button — “Download document”. The click redirects to a fake mail login page, the password is harvested, and attackers move into your mailbox. Here is how to recognise it, what never to do, and how it can be blocked automatically.

July 20, 20269 min readStitex Technologies

What the attack looks like

The classic scenario: a message arrives at a corporate mailbox. The sender address looks plausible — a domain resembling a real contractor or supplier. The subject is bare: “Complaint.”, sometimes with the full stop included. The body is two or three sentences with no detail, and a large button reading Download document or a link promising the full version.

There is no actual attachment. Instead there is a link to a short, unfamiliar domain, usually registered days or weeks earlier. Clicking it produces one or two redirects and lands on a page visually indistinguishable from a real mail login. The form is waiting for the username and password of that same corporate mailbox.

What happens after the password is entered
Within minutes the attacker is inside the mailbox: reading contracts, downloading documents, adding a forwarding rule that copies all incoming mail to themselves, and sending fake invoices to your counterparties in your name. Recovering from that takes days, and often money.

Five signals that this is phishing

One signal is grounds for suspicion. Three or more and it is phishing with near certainty.

#SignalHow to check
1Reply-To differs from From, and points at a free mail providerOpen the message headers. If From is a company domain and Reply-To is a free mailbox, that is phishing. Legitimate companies do not redirect replies to free mail.
2A short, urgent business subject with no specifics“Complaint”, “Claim”, “Urgent”, “Notice of debt” — one or two words, with no contract number, date or name. A genuine complaint is always specific.
3No attachment despite promising a documentThe message has a “download the claim” button but the attachment list is empty. A real document is attached as a file, not as a button to an external service.
4The same link repeated three or more timesButton, inline link and signature all point to one URL. Hover over the link without clicking — the status bar shows the real address.
5The link domain is unrelated to the sender domainThe mail claims to come from a supplier’s domain while the link goes to a short unfamiliar one. Legitimate companies link to their own site.

What never to do

  • Do not click “Download” buttons in messages like this. A genuine file would be an attachment.
  • Do not hit Reply — if Reply-To has been redirected to free mail, your response goes to the attacker along with the thread and your signature block.
  • Do not enter credentials on a login page you reached from an email link. Open the mail service yourself, from a bookmark.
  • Do not forward it internally as a question — that is how a second person clicks it.

Why two-factor authentication matters here

This attack ends at a harvested password. With a second factor in place, the harvested password is not enough to get in — which is why email is the first account that should have it. The reasoning is in why two-factor authentication is not optional, and the wider account-hygiene checklist in the server security audit checklist.

Frequently asked questions

What makes this scheme so effective against businesses?

It exploits a professional reflex. A message titled “Complaint” or “Claim” from what looks like a contractor gets opened and acted on quickly, because ignoring a complaint feels riskier than clicking a link. The urgency does the work that a technical exploit would otherwise have to.

What should we do if someone already entered their password?

Change that password immediately, and every account where it was reused. Then check the mailbox for forwarding rules the attacker may have added, review sent items, and warn your counterparties that invoices may have gone out in your name.

Can this be blocked automatically?

Largely, yes. The pattern is consistent enough that a filter can score the combination of signals — mismatched reply address, a bare urgent subject, no attachment despite promising a document, a link domain unrelated to the sender — and hold the message before it reaches the inbox.

Business email without the phishing

Our mail service with an AI moderation layer recognises this scheme by its combination of signals and holds the message before it reaches the inbox.