ExxonMobil RFQ Email Scam Exposed: Fake Quotation Attachment Investigated

A request for quotation can look like a valuable new lead. Suppliers are trained to respond quickly when a large prospective customer appears.

This RFQ uses detailed purchasing language, but the attachment’s real file type tells a very different story.

Fake ExxonMobil request for quotation email with an HTML attachment

Overview

The procurement opportunity presented

The Confirmation of Request for Quotation email impersonates ExxonMobil. One observed subject used the reference “RFQ-62924-0187#923194” alongside the recipient.

The message was signed by “Celia Chow, Procurement Manager.” It asked for minimum order quantities, pricing, lead times, customization availability, and packaging details.

That vocabulary makes the request feel tailored to manufacturers and wholesalers. It resembles the information a genuine purchasing team might need before choosing a supplier.

The attachment is not what the email promises

The body refers to an attached RFQ PDF. The actual filename ends in “.xls.html,” a double extension that identifies an HTML webpage.

Opening the file in a browser displays a fake webmail login. It asks the supplier to verify an email address and provide the account password.

The form can submit entered credentials to criminals. ExxonMobil and Google are not involved in the fraudulent message or login page.

The clearest warning signs

  • A major company supposedly sends an unsolicited high-value purchasing opportunity.
  • The sender domain does not match the claimed organization.
  • The email describes a PDF while the attachment ends in HTML.
  • A local quotation file asks for the recipient’s email password.
  • The request lacks a verified buyer relationship or procurement portal record.
  • Detailed purchasing terms create credibility without proving the buyer’s identity.

An HTML attachment can open directly from the Downloads folder. Its local address does not prevent scripts or forms from communicating with an external server.

Simply viewing the page is not the same as submitting credentials. The main confirmed theft occurs when the user enters and sends the password.

Suppliers should verify the buyer through independently located corporate contacts. A promising contract is not worth bypassing ordinary customer-onboarding controls.

Local HTML request for quotation attachment displaying a fake email login

How the ExxonMobil RFQ Email Scam Works

Step 1: Criminals approach a supplier with a prestigious buyer name

A recognizable energy company suggests purchasing power, repeat business, and a valuable account. That prospect can override the caution applied to ordinary spam.

The message targets people accustomed to receiving inquiries from unknown customers. For sales teams, unfamiliarity alone is not unusual, which gives attackers room.

Public catalogs and business directories reveal what a company sells. Scammers can send broadly relevant RFQs without understanding the supplier deeply.

The real company’s name, address, and employee titles can be copied from public sources. Accurate public details do not authenticate the sender.

Step 2: Procurement language makes the inquiry feel operational

The email asks for MOQ, unit price, lead time, OEM or ODM options, and packaging. These are practical details rather than vague promises.

Specific terminology lowers suspicion because it sounds like an experienced buyer. Yet every requested field can be copied into a reusable template.

The reference number adds another layer of apparent process. Attackers can invent an RFQ number without any matching record inside the company they impersonate.

A legitimate procurement contact should be verifiable through the company’s supplier portal or established switchboard. The email’s detail cannot replace that check.

Step 3: The attachment uses a misleading double extension

The body calls the file a PDF, but the attachment ends in “.xls.html.” That final HTML extension determines its actual behavior.

Placing “xls” before “html” encourages the recipient to see a spreadsheet. Some mail interfaces truncate long names or emphasize the first familiar extension.

HTML attachments are webpages saved as files. They can contain forms, scripts, copied logos, and links, then open inside the default browser.

They are not inherently malicious. Their use becomes suspicious when an unexpected sender mislabels them and embeds a login form unrelated to the document.

Step 4: The local page imitates webmail authentication

Once opened, the attachment displays “Verify Email Address” and asks for the recipient’s password before revealing the quotation.

The browser address may begin with “file:///” because the page is stored locally. That does not mean the form is offline or trustworthy.

HTML can send form data to a remote endpoint when the user clicks a button. The collection address may be hidden in the page’s code.

A genuine buyer does not need a supplier’s mailbox password to share requirements. Authentication should occur through the supplier’s own identity provider or a known portal.

Step 5: The form captures business email credentials

Entered addresses and passwords can be transmitted to the phishing operator. A fake loading screen or error may appear afterward.

The page might ask twice, claiming the first password was wrong. That tactic can collect alternate passwords or increase confidence in a repeated entry.

If multi-factor authentication is enabled, the attacker may immediately trigger a login. The victim could receive a prompt while expecting the RFQ to open.

Never approve an unexpected prompt. Contact IT if one appears after interacting with a suspicious attachment, even when the password seemed rejected.

Step 6: A supplier mailbox reveals commercial relationships

Sales and finance accounts hold quotations, customer contacts, invoice values, bank instructions, delivery schedules, and internal approval messages.

An intruder can use those records to craft believable follow-ups. They may impersonate the supplier toward customers or impersonate customers toward the supplier.

Mailbox rules can forward incoming messages and hide security notices. Attackers may remain quiet while learning which conversations offer the greatest financial opportunity.

Compromise also damages reputation. Customers receiving fraudulent payment requests from a familiar supplier account may blame the supplier for resulting losses.

Step 7: The fake RFQ can lead to invoice diversion

After observing real transactions, criminals may send revised bank details or replacement invoices. They often choose a moment when payment is already expected.

A message sent inside an authentic thread inherits its history and participants. That makes a fraudulent change appear connected to the legitimate order.

Payment diversion is a plausible next stage of business email compromise. It was not established as the outcome of every RFQ message in this campaign.

Finance teams should verbally verify new beneficiary details using a known number. Email confirmation alone cannot safely authorize a bank-account change.

Why Suppliers Are Attractive Targets

Unknown inquiries are part of normal sales work

Consumer phishing looks suspicious when the sender is unfamiliar. Sales teams, however, expect first contact from companies they have never served.

Scammers exploit that openness. The possibility of winning business encourages recipients to open attachments before the buyer passes formal verification.

One mailbox connects many organizations

A supplier’s account communicates with customers, logistics providers, banks, and colleagues. Compromising it creates trusted paths into several businesses.

The attacker can study tone, signatures, payment cycles, and common attachments. Later messages can closely resemble the victim’s ordinary correspondence.

Commercial urgency can bypass security

Large opportunities may receive executive attention. Employees can fear that cautious delays will cost the company a valuable contract.

Good buyers respect verification. Refusal to confirm identity through official channels is a warning, not a reason to relax controls.

How to Validate an Unexpected RFQ

Confirm the buyer through official channels

Locate the company’s supplier or procurement information independently. Search the official website manually instead of using any link in the message.

Call the published switchboard and ask whether the named employee and RFQ reference are genuine. Do not use the telephone number in the email signature.

Inspect the complete filename

Enable visible file extensions and read the final suffix. A promised PDF should actually end in “.pdf,” not “.html” or an executable type.

Send suspicious files to the security team. Do not rename them, enable content, or enter credentials to discover what they contain.

Use a clean onboarding process

New customers should provide legal identity, billing details, credit information, and authorized contacts through documented procedures.

Separate sales enthusiasm from account approval. No single unsolicited email should create both the opportunity and the proof that it is real.

What a Genuine Corporate RFQ Usually Provides

A traceable procurement identity

Real corporate buyers normally use approved domains, supplier portals, tender platforms, or existing purchasing contacts. Their identity can be confirmed outside the message.

A reference number should lead to a record that an authorized procurement team recognizes. Random digits in a subject line provide no such traceability.

Commercial requirements without credential collection

A genuine RFQ may request pricing, capacity, certifications, and delivery terms. It does not require the supplier to reveal an email password.

Secure portals authenticate users through their own accounts or a documented single-sign-on flow. They do not hide webmail forms inside local attachments.

Clear delivery and contracting expectations

Legitimate buyers can explain the contracting entity, billing process, delivery location, inspection requirements, and payment terms before requesting valuable goods.

Fraudulent inquiries often postpone those details. They keep attention on pricing until trust is established, then introduce unusual shipping or credit requests.

How an HTML Attachment Can Look Like a Document

An HTML file uses the same language as a webpage. It can reproduce a sign-in card, company colors, buttons, and instructions inside the browser.

Because the file came from email, users may assume its content was scanned or approved. Mail scanning cannot guarantee that every interactive form is honest.

The form’s submission address can differ from everything visible on screen. Security analysts can inspect that code without sending credentials to the operator.

For ordinary recipients, the safe rule is simpler: no quotation attachment should ask for the password to an unrelated mailbox.

Mailbox security investigation showing suspicious supplier messages

Company, Address, and Fulfillment Checks

Verify the exact legal entity

Large corporate groups contain many similarly named entities. Confirm which entity is buying, where it is registered, and which procurement process it uses.

The email’s “ExxonMobil LTD” label does not establish a legal relationship. ExxonMobil was impersonated and is not responsible for the campaign.

Treat copied addresses as unproven

Scammers can paste a real headquarters address beneath a fake sender domain. Address accuracy proves only that the information was publicly available.

Compare registration records, tax details, delivery locations, and correspondence domains. Inconsistencies should pause quotation work until the buyer confirms them.

Call an independently published number

Use the company’s official switchboard or established supplier contact. Ask to be transferred to procurement and verify the named person and reference.

Never let the suspicious message define the entire verification channel. A criminal can control the email address, signature, telephone number, and reply.

Verify delivery and payment expectations

Fraudulent buyers may later request samples, credit terms, or shipments to unrelated freight forwarders. Confirm every location and responsible entity before dispatch.

Do not confuse a fulfillment warehouse with a corporate office. Understand who owns the goods, who accepts delivery, and who is legally obligated to pay.

What to Do if You Have Fallen Victim to This Scam

  1. Preserve the RFQ evidence. Close the local page without another submission, then retain the original email and attachment for your security team.
  2. Change the mailbox password. Use a clean device and the official account portal. Choose a unique password that is not used elsewhere.
  3. Revoke sessions and review multi-factor methods. Remove unfamiliar devices, tokens, recovery addresses, telephone numbers, and application passwords.
  4. Inspect mailbox rules and delegates. Delete unauthorized forwarding, hiding rules, connected applications, and delegated access. Review sent and deleted folders.
  5. Notify management, finance, and IT. They should search for the campaign, review affected conversations, and warn customers about possible impersonation.
  6. Audit recent payment changes. Call known customers and suppliers to verify beneficiary updates, revised invoices, and unusual requests made from the account.
  7. Change reused credentials. Prioritize banking, customer portals, cloud storage, payroll, and administrator accounts that shared the exposed password.
  8. Scan the computer. The confirmed lure targets credentials, but run Microsoft Defender and Malwarebytes to check for additional downloads or scripts.
  9. Add layered web filtering. AdGuard can block some malicious destinations and advertisements, but staff must still verify unexpected business opportunities.
  10. Report attempted fraud quickly. Contact banks immediately if funds moved, then file reports with law enforcement and relevant cybercrime authorities.

Frequently Asked Questions

Was this RFQ really sent by ExxonMobil?

No. The investigated message impersonated ExxonMobil. The sender and attachment were part of a credential-phishing campaign.

Why does the attachment end in .xls.html?

The final “.html” means it is a webpage file. Adding “xls” earlier in the name helps it resemble a quotation spreadsheet.

Can a local HTML file steal information?

Yes. It can display a form and send entered data to a remote server. A “file:///” address does not guarantee offline behavior.

Am I compromised if I opened it but entered nothing?

The confirmed credential risk is much lower. Close it, report it, scan the device, and investigate any download, prompt, or unusual browser behavior.

Should I reply and ask the buyer to verify themselves?

No. Contact the company through an independently sourced switchboard or supplier portal. Replying keeps verification inside a channel the attacker may control.

Could the scam lead to financial theft?

Yes. A stolen business mailbox can support invoice diversion and fraudulent bank changes, although that outcome was not confirmed for every recipient.

The Bottom Line

The fake ExxonMobil RFQ uses realistic procurement language to deliver an HTML credential form disguised as a quotation document.

Read complete filenames, verify new buyers independently, and never provide an email password to open an attachment. If credentials were entered, secure the mailbox and notify business partners quickly.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

O2 Discount Call Scam: How Fake 40% Offers Can Hijack Your Mobile Account

Next

Free File Converter Scam Can Install Hidden Malware