A document-invite lure reached a chief executive on September 4, and pasted into the same HTML body, below the lure, was a verbatim copy of the web console of the phishing service that sent it. The panel read like a SaaS billing page: an Enterprise plan marked active with 23 days remaining, a lifetime counter of 138,291 emails, three add-on meters all at zero, a tab strip from Send and Leads through SMTP Config and Proxy, and an empty-state line reading no saved campaigns.
Then the working state: 4,043 leads loaded, one relay, 25 sends in parallel at zero delay, and a fifty-line delivery log of 250 response codes. The arithmetic proves it was live, not filler. Twenty-five sends across 26 seconds is 0.96 per second, displayed as 1.0, and the leads still queued at that rate produce the printed estimate of 69 minutes 18 seconds; the next batch recomputes to about 78 minutes and prints 78 minutes 12 seconds. Static text cannot carry estimates that integrate their own timestamps. The log named fifty real mailboxes at forty-nine uninvolved companies and we are publishing none of them. Two corrections worth making. This was not an authentication failure: the message passed SPF at the true inbound edge, DKIM was not evaluated there, the sending domain publishes no DMARC policy, and the failure pair visible downstream was manufactured by the receiving side's own gateway-to-relay topology. And nothing here was attacker-registered: the relay host dates to 2011, the sending domain belongs to a real insurance brand whose provider account was abused, and the landing page sits on a compromised legitimate website owned by a private individual. The receiving gateway fired three rules and totalled 0.50 against a kill threshold of 3.0, and the only one that scored anything was a non-standard-port URI, present solely because the operator pasted his own log. The defensive read is cheap. Kit banners, a lead-loader line, a repeating delivery log and a licence meter are ordinary body strings, easy to match and easy to score heavily, and this leak class is structural because kits invite the operator to paste custom HTML.
(Link to full teardown in comments)