HUS Ltd Order Confirmation Email Scam: Dangerous Excel Attachment Exposed

A purchase order arrives with a company signature and an Excel attachment. For someone handling suppliers or sales, it looks like another task awaiting review.

The HUS Ltd order-confirmation email deserves a closer look before that spreadsheet becomes part of your working day, especially if the order is unexpected.

Illustrative HUS Ltd impersonation email with an unexpected purchase order spreadsheet attachment

Overview

A real steel company is being impersonated

This malicious order-confirmation campaign uses the name of HUS Ltd to persuade recipients to open an Excel attachment presented as business paperwork.

The genuine HUS Ltd website identifies a steel manufacturing and trading company based in Plovdiv, Bulgaria.

That legitimate business presence does not authenticate the email. A company signature, employee name, and public address can be copied into an unrelated message.

The warning concerns the impersonation and attached file. It is not evidence that the real company’s employees sent malware or that its website was compromised.

The purchase order leads toward a spreadsheet security boundary

The reported subject references PO0425. Its attachment is named Order NO. PO00435, HUS Ltd.xls, and the message discusses order confirmation and purchase conditions.

The reported workbook presents little useful content while encouraging the recipient to leave Protected View. That makes the requested security change particularly important.

  • An unfamiliar order creates a business reason to open the attachment.
  • A copied company identity supplies apparent legitimacy.
  • The spreadsheet format feels normal for commercial records.
  • An editing prompt shifts attention from verification to making the file work.

The payload is unknown, and the buttons matter

The available campaign report does not identify the final malware payload. We have not executed the attachment, so claims about a specific infection would be unsupported.

Also, Enable Editing and Enable Content are not interchangeable. Leaving Protected View does not automatically enable active content in Office.

The lead illustration uses fictional sender details and represents the attachment lure. It is not the original workbook, and it contains no executable content.

Why This Looks Like Ordinary Supplier Correspondence

Purchase orders are repetitive by design. They contain reference numbers, short instructions, attachments, and signatures that recipients often process quickly.

A busy employee may judge the message by whether it resembles that workflow rather than whether the underlying order can be verified.

Detailed signatures add another distraction. A street address, job title, and company website create an impression of completeness without authenticating the sender.

Looking up the company may confirm that it exists. That answers a narrower question than whether this particular file came from it.

The difference matters for anyone investigating suspicious supplier messages. Finding a real business does not resolve the provenance of an unsolicited attachment.

Start with your own commercial records: did someone request this order, expect these conditions, or ask this contact to send a spreadsheet?

If the answer is uncertain, the next step is verification, not changing Office settings until the file displays something useful.

How the HUS Ltd Order Confirmation Email Scam Works

Step 1: The message supplies a ready-made business context

Instead of asking you to install unfamiliar software outright, the email presents a document that appears relevant to an ordinary commercial transaction.

Order references make the message feel specific. Yet a reference is only meaningful when it matches a record held by your organization or verified counterparty.

Do not assume a colleague must have arranged it simply because the company name sounds plausible. Ask the person responsible for the relevant purchase or sale.

If no one recognizes the transaction, preserve the notice for reporting. You do not need to open its attachment to justify that decision.

Step 2: The signature lends the file someone else’s credibility

A business signature encourages readers to picture an accountable professional behind the email. That can make a technical warning seem like an inconvenience rather than useful protection.

However, public contact information is easy to reuse. It cannot establish which account sent the message or whether the attached file was authorized.

Even a familiar conversation should be checked if its request changes unexpectedly. Compromised correspondence and copied signatures are different possibilities requiring evidence, not assumptions.

For this case, the available evidence supports impersonation. It does not identify the method used to obtain the signature or prove a breach at HUS.

Step 3: The attachment moves the interaction into Excel

The recipient is encouraged to treat the workbook as the place where the real transaction details will become clear.

This can reverse the safe order of checks. Instead of confirming the transaction before opening the file, you open the file to discover the transaction.

Excel workbooks can contain more than visible cells. Their risk depends on content, application behavior, security controls, and what the user authorizes.

The .xls extension identifies an older Excel format; it is not a certificate of safety. Renaming a file or seeing a spreadsheet icon changes nothing.

Do not upload private business attachments to a public analysis service without permission. Your security team may have a controlled way to inspect them.

Step 4: A viewing problem becomes a request to reduce protection

When expected content does not appear, readers naturally look for a way to fix the display. A prominent editing control can seem like the next sensible step.

Protected View is a safety boundary, not an error message that a document sender is entitled to override.

If an unsolicited order requires you to trust content before explaining itself, stop. The lack of useful visible information is not a reason to grant additional permissions.

Do not follow instructions to disable protections globally, add an unknown trusted location, or run an unrelated command to reveal commercial paperwork.

A legitimate counterpart can confirm the order and provide an approved alternative through your normal business process.

Step 5: Further execution depends on the file and environment

Some malicious Office documents rely on active content or vulnerable application behavior. Not every attachment executes merely because it is downloaded or viewed.

Microsoft distinguishes leaving Protected View from enabling active content. Current Office defenses may also block internet-origin macros, depending on the product and configuration.

That is why a response needs exact details: which file opened, which warnings appeared, and which controls you selected.

There is no identified payload to name in this campaign’s available record. Do not assume ransomware, a password stealer, or remote access without further evidence.

Nevertheless, unexpected execution or permission changes warrant assessment. Lack of a confirmed malware name is not a reason to continue experimenting with the workbook.

Enable Editing Is Not the Same as Enable Content

Leaving Protected View changes how Office treats the document

Protected View restricts how an untrusted document is handled. Selecting Enable Editing takes the document out of that protective viewing mode.

That action is meaningful, but it should not be described as universally equivalent to running macros. The distinction affects both prevention and incident reporting.

Microsoft’s trusted-document documentation states that active content is not automatically enabled when a user exits Protected View.

If you remember clicking only Enable Editing, tell support exactly that. Do not change your account of events to match an alarming explanation you read online.

Active-content prompts and blocked macros are separate decisions

A workbook may present additional warnings about content that Office has disabled. Those warnings deserve their own assessment, not automatic approval.

Microsoft also documents how internet-origin macros are blocked in supported Office configurations.

Do not search for a bypass to satisfy an unknown sender. A security control preventing the file from working may be doing exactly what it should.

Your organization’s settings can differ from another person’s computer. Advice based on a different Office version may not explain what happened on yours.

A blank workbook is not a diagnosis

An empty-looking sheet does not prove infection, nor does it prove the attachment is harmless. It only describes what the application displayed.

Similarly, an application crash does not identify a particular malware family. Security assessment needs the file and relevant system evidence.

The safe practical decision is to stop handling an unexpected workbook and let an authorized person investigate it without lowering protections.

What to Do If You Opened the Attachment

  1. Stop interacting with the workbook. Do not reopen it, approve more prompts, or try suggested display fixes from the sender.

    Write down what you remember seeing and clicking. Include whether the file stayed in Protected View or whether you enabled editing, content, or another permission.

  2. Notify workplace IT if this is a business device. Provide the message and attachment using the approved incident-reporting process.

    Avoid forwarding the file to coworkers for an informal second opinion. That could expose more people while adding little reliable evidence.

    If you suspect active compromise, stop sensitive work and follow your organization’s isolation procedure. Let responders decide how to preserve logs and system state.

  3. Preserve the original message safely. Headers, arrival time, attachment name, and the recipient account can help investigators connect related deliveries.

    Do not post the workbook publicly or send confidential business material to an unknown scanning service. Ask the security team how to transfer it.

  4. Have a personal device checked if risky content ran. Use trusted security software and install operating-system and Office updates through their normal channels.

    Malwarebytes can assist with detecting malicious or unwanted software. No single scan can establish every action a file may have taken before detection.

    Seek qualified help if warnings persist, unfamiliar programs appear, or you cannot explain recent account activity. Avoid cleanup tools offered by the suspicious email.

  5. Secure accounts if there is evidence of exposure. Use a clean device when malware execution is suspected, especially for email and financial services.

    Replace compromised credentials and examine suspicious account activity with the provider or administrator. Merely receiving the attachment does not mean every password must have been stolen.

  6. Review browser changes only if the incident included browsing. Remove unexpected extensions or notification permissions granted during any related visit.

    AdGuard may help with malicious advertising exposure on the web. It is not a tool for neutralizing an Excel workbook or restoring a compromised machine.

  7. Confirm the commercial situation independently. Ask the genuine business contact whether an actual order or delivery needs attention.

    Use an existing vendor record or the company’s independently opened website. Do not accuse the named employee based only on a copied signature.

  8. Close the incident with a clear internal record. Record the assessment, affected systems, cleanup, and any account changes your responders directed.

    If the file was blocked before execution, document that outcome too. Accurate reporting helps avoid both unnecessary alarm and missed follow-up work.

A Safer Purchase-Order Workflow

Purchasing and sales teams need to exchange documents. A useful defense should make unexpected orders easier to verify, not make ordinary work impossible.

Maintain a trusted vendor directory separately from incoming messages. That gives employees a contact route the suspicious sender did not supply.

Assign someone to keep that directory current when staff or suppliers change. An outdated contact list can send employees back to unverified email signatures.

Require unfamiliar order references to be matched with an internal owner. A busy shared inbox should not turn uncertainty into permission to open every attachment.

When a sender asks for a different file-handling process, confirm the change outside the email thread. This is especially important for security-setting exceptions.

Agree on approved document formats and transfer channels where practical. A transaction can often continue without asking staff to enable unknown active content.

Keep software supported and updated, but do not treat updates as permission to trust arbitrary attachments. Technical defenses and business verification address different risks.

Encourage fast reporting of mistakes. Someone who clicked a warning should be able to explain it immediately without first trying to fix the situation alone.

The strongest lesson from this lure is about workflow: the desire to finish an ordinary task should not determine whether an unfamiliar file receives trust.

Frequently Asked Questions

Is HUS Ltd a fake company?

No. Its official site describes a real steel business. This warning concerns a malicious message using its identity, not the legitimacy of the company itself.

Is the attachment a confirmed ransomware installer?

The available record does not identify its final payload. Calling it a specific ransomware family would go beyond the evidence.

Does clicking Enable Editing automatically run macros?

No. Office distinguishes leaving Protected View from enabling active content. Report the exact prompts you approved so the incident can be assessed correctly.

What if I downloaded the spreadsheet but never opened it?

Do not open it now. Report and handle the file through your security process; downloading alone does not establish that its content executed.

Can I trust the message because the address is real?

A real address can be copied. Verify the particular order and sender through established business records rather than treating signature details as authentication.

Should I request another copy from the same sender?

First confirm the transaction through an independently verified contact. Asking the unverified sender for another file may simply restart the same exposure.

The Bottom Line

The HUS Ltd order-confirmation scam hides a risky attachment inside an ordinary supplier workflow. A real company name cannot make an unexpected workbook trustworthy.

Verify the transaction before handling the file, keep Office protections intact, and report any interaction accurately. Unknown payload details should prompt careful assessment, not invented certainty.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

USPS Change of Address Scam: Fake Moving Sites Charge More and Collect Data

Next

Adobe PDF Document Completed Email Scam: Fake Review Notification Exposed