{"id":409253,"date":"2026-09-03T19:01:03","date_gmt":"2026-09-03T19:01:03","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=409253"},"modified":"2026-09-03T19:01:03","modified_gmt":"2026-09-03T19:01:03","slug":"exxonmobil-rfq-email-scam-quotation-attachment","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/exxonmobil-rfq-email-scam-quotation-attachment\/","title":{"rendered":"ExxonMobil RFQ Email Scam Exposed: Fake Quotation Attachment Investigated"},"content":{"rendered":"<p>A request for quotation can look like a valuable new lead. Suppliers are trained to respond quickly when a large prospective customer appears.<\/p><div id=\"mwtad1776301763\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>This RFQ uses detailed purchasing language, but the attachment\u2019s real file type tells a very different story.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Fake ExxonMobil request for quotation email with an HTML attachment\" title=\"\" class=\"lazyload\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/exxonmobil-rfq-email.png\"><\/figure>\n<div id=\"mwtad2591779014\" class=\"gas_fallback-ad_309746-ad_406044-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The procurement opportunity presented<\/h3>\n<p>The Confirmation of Request for Quotation email impersonates ExxonMobil. One observed subject used the reference \u201cRFQ-62924-0187#923194\u201d alongside the recipient.<\/p><div id=\"mwtad2608040206\" class=\"gas_fallback-ad_381396-ad_406044-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The message was signed by \u201cCelia Chow, Procurement Manager.\u201d It asked for minimum order quantities, pricing, lead times, customization availability, and packaging details.<\/p>\n<p>That vocabulary makes the request feel tailored to manufacturers and wholesalers. It resembles the information a genuine purchasing team might need before choosing a supplier.<\/p>\n<h3>The attachment is not what the email promises<\/h3>\n<p>The body refers to an attached RFQ PDF. The actual filename ends in \u201c.xls.html,\u201d a double extension that identifies an HTML webpage.<\/p><div id=\"mwtad2449787387\" class=\"gas_fallback-ad_309686-ad_406044-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Opening the file in a browser displays a fake webmail login. It asks the supplier to verify an email address and provide the account password.<\/p>\n<p>The form can submit entered credentials to criminals. ExxonMobil and Google are not involved in the fraudulent message or login page.<\/p>\n<h3>The clearest warning signs<\/h3>\n<ul>\n<li>A major company supposedly sends an unsolicited high-value purchasing opportunity.<\/li>\n<li>The sender domain does not match the claimed organization.<\/li>\n<li>The email describes a PDF while the attachment ends in HTML.<\/li>\n<li>A local quotation file asks for the recipient\u2019s email password.<\/li>\n<li>The request lacks a verified buyer relationship or procurement portal record.<\/li>\n<li>Detailed purchasing terms create credibility without proving the buyer\u2019s identity.<\/li>\n<\/ul>\n<p>An HTML attachment can open directly from the Downloads folder. Its local address does not prevent scripts or forms from communicating with an external server.<\/p><div id=\"mwtad472855892\" class=\"gas_fallback-ad_381401-ad_406044-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Simply viewing the page is not the same as submitting credentials. The main confirmed theft occurs when the user enters and sends the password.<\/p>\n<p>Suppliers should verify the buyer through independently located corporate contacts. A promising contract is not worth bypassing ordinary customer-onboarding controls.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Local HTML request for quotation attachment displaying a fake email login\" title=\"\" class=\"lazyload\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/exxonmobil-rfq-login.png\"><\/figure>\n<div id=\"mwtad3006992913\" class=\"gas_fallback-ad_309747-ad_406044-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the ExxonMobil RFQ Email Scam Works<\/h2>\n<h3>Step 1: Criminals approach a supplier with a prestigious buyer name<\/h3>\n<div id=\"mwtad4081392496\" class=\"gas_fallback-ad_381404-ad_406044-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>A recognizable energy company suggests purchasing power, repeat business, and a valuable account. That prospect can override the caution applied to ordinary spam.<\/p>\n<p>The message targets people accustomed to receiving inquiries from unknown customers. For sales teams, unfamiliarity alone is not unusual, which gives attackers room.<\/p>\n<p>Public catalogs and business directories reveal what a company sells. Scammers can send broadly relevant RFQs without understanding the supplier deeply.<\/p>\n<div id=\"mwtad630190388\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>The real company\u2019s name, address, and employee titles can be copied from public sources. Accurate public details do not authenticate the sender.<\/p>\n<h3>Step 2: Procurement language makes the inquiry feel operational<\/h3>\n<p>The email asks for MOQ, unit price, lead time, OEM or ODM options, and packaging. These are practical details rather than vague promises.<\/p>\n<p>Specific terminology lowers suspicion because it sounds like an experienced buyer. Yet every requested field can be copied into a reusable template.<\/p>\n<div id=\"mwtad4204493932\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>The reference number adds another layer of apparent process. Attackers can invent an RFQ number without any matching record inside the company they impersonate.<\/p>\n<p>A legitimate procurement contact should be verifiable through the company\u2019s supplier portal or established switchboard. The email\u2019s detail cannot replace that check.<\/p>\n<h3>Step 3: The attachment uses a misleading double extension<\/h3>\n<p>The body calls the file a PDF, but the attachment ends in \u201c.xls.html.\u201d That final HTML extension determines its actual behavior.<\/p>\n<p>Placing \u201cxls\u201d before \u201chtml\u201d encourages the recipient to see a spreadsheet. Some mail interfaces truncate long names or emphasize the first familiar extension.<\/p>\n<p>HTML attachments are webpages saved as files. They can contain forms, scripts, copied logos, and links, then open inside the default browser.<\/p>\n<p>They are not inherently malicious. Their use becomes suspicious when an unexpected sender mislabels them and embeds a login form unrelated to the document.<\/p>\n<h3>Step 4: The local page imitates webmail authentication<\/h3>\n<p>Once opened, the attachment displays \u201cVerify Email Address\u201d and asks for the recipient\u2019s password before revealing the quotation.<\/p>\n<p>The browser address may begin with \u201cfile:\/\/\/\u201d because the page is stored locally. That does not mean the form is offline or trustworthy.<\/p>\n<p>HTML can send form data to a remote endpoint when the user clicks a button. The collection address may be hidden in the page\u2019s code.<\/p>\n<p>A genuine buyer does not need a supplier\u2019s mailbox password to share requirements. Authentication should occur through the supplier\u2019s own identity provider or a known portal.<\/p>\n<h3>Step 5: The form captures business email credentials<\/h3>\n<p>Entered addresses and passwords can be transmitted to the phishing operator. A fake loading screen or error may appear afterward.<\/p>\n<p>The page might ask twice, claiming the first password was wrong. That tactic can collect alternate passwords or increase confidence in a repeated entry.<\/p>\n<p>If multi-factor authentication is enabled, the attacker may immediately trigger a login. The victim could receive a prompt while expecting the RFQ to open.<\/p>\n<p>Never approve an unexpected prompt. Contact IT if one appears after interacting with a suspicious attachment, even when the password seemed rejected.<\/p>\n<h3>Step 6: A supplier mailbox reveals commercial relationships<\/h3>\n<p>Sales and finance accounts hold quotations, customer contacts, invoice values, bank instructions, delivery schedules, and internal approval messages.<\/p>\n<p>An intruder can use those records to craft believable follow-ups. They may impersonate the supplier toward customers or impersonate customers toward the supplier.<\/p>\n<p>Mailbox rules can forward incoming messages and hide security notices. Attackers may remain quiet while learning which conversations offer the greatest financial opportunity.<\/p>\n<p>Compromise also damages reputation. Customers receiving fraudulent payment requests from a familiar supplier account may blame the supplier for resulting losses.<\/p>\n<h3>Step 7: The fake RFQ can lead to invoice diversion<\/h3>\n<p>After observing real transactions, criminals may send revised bank details or replacement invoices. They often choose a moment when payment is already expected.<\/p>\n<p>A message sent inside an authentic thread inherits its history and participants. That makes a fraudulent change appear connected to the legitimate order.<\/p>\n<p>Payment diversion is a plausible next stage of business email compromise. It was not established as the outcome of every RFQ message in this campaign.<\/p>\n<p>Finance teams should verbally verify new beneficiary details using a known number. Email confirmation alone cannot safely authorize a bank-account change.<\/p>\n<div id=\"mwtad815146440\" class=\"gas_fallback-ad_309748-ad_406044-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why Suppliers Are Attractive Targets<\/h2>\n<h3>Unknown inquiries are part of normal sales work<\/h3>\n<p>Consumer phishing looks suspicious when the sender is unfamiliar. Sales teams, however, expect first contact from companies they have never served.<\/p>\n<p>Scammers exploit that openness. The possibility of winning business encourages recipients to open attachments before the buyer passes formal verification.<\/p>\n<h3>One mailbox connects many organizations<\/h3>\n<p>A supplier\u2019s account communicates with customers, logistics providers, banks, and colleagues. Compromising it creates trusted paths into several businesses.<\/p>\n<p>The attacker can study tone, signatures, payment cycles, and common attachments. Later messages can closely resemble the victim\u2019s ordinary correspondence.<\/p>\n<h3>Commercial urgency can bypass security<\/h3>\n<p>Large opportunities may receive executive attention. Employees can fear that cautious delays will cost the company a valuable contract.<\/p>\n<p>Good buyers respect verification. Refusal to confirm identity through official channels is a warning, not a reason to relax controls.<\/p>\n<div id=\"mwtad3058744529\" class=\"gas_fallback-ad_318930-ad_406044-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How to Validate an Unexpected RFQ<\/h2>\n<h3>Confirm the buyer through official channels<\/h3>\n<p>Locate the company\u2019s supplier or procurement information independently. Search the official website manually instead of using any link in the message.<\/p>\n<p>Call the published switchboard and ask whether the named employee and RFQ reference are genuine. Do not use the telephone number in the email signature.<\/p>\n<h3>Inspect the complete filename<\/h3>\n<p>Enable visible file extensions and read the final suffix. A promised PDF should actually end in \u201c.pdf,\u201d not \u201c.html\u201d or an executable type.<\/p>\n<p>Send suspicious files to the security team. Do not rename them, enable content, or enter credentials to discover what they contain.<\/p>\n<h3>Use a clean onboarding process<\/h3>\n<p>New customers should provide legal identity, billing details, credit information, and authorized contacts through documented procedures.<\/p>\n<p>Separate sales enthusiasm from account approval. No single unsolicited email should create both the opportunity and the proof that it is real.<\/p>\n<div id=\"mwtad2321183620\" class=\"gas_fallback-ad_381388-ad_406044-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What a Genuine Corporate RFQ Usually Provides<\/h2>\n<h3>A traceable procurement identity<\/h3>\n<p>Real corporate buyers normally use approved domains, supplier portals, tender platforms, or existing purchasing contacts. Their identity can be confirmed outside the message.<\/p>\n<p>A reference number should lead to a record that an authorized procurement team recognizes. Random digits in a subject line provide no such traceability.<\/p>\n<h3>Commercial requirements without credential collection<\/h3>\n<p>A genuine RFQ may request pricing, capacity, certifications, and delivery terms. It does not require the supplier to reveal an email password.<\/p>\n<p>Secure portals authenticate users through their own accounts or a documented single-sign-on flow. They do not hide webmail forms inside local attachments.<\/p>\n<h3>Clear delivery and contracting expectations<\/h3>\n<p>Legitimate buyers can explain the contracting entity, billing process, delivery location, inspection requirements, and payment terms before requesting valuable goods.<\/p>\n<p>Fraudulent inquiries often postpone those details. They keep attention on pricing until trust is established, then introduce unusual shipping or credit requests.<\/p>\n<div id=\"mwtad468864265\" class=\"gas_fallback-ad_381392-ad_406044-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How an HTML Attachment Can Look Like a Document<\/h2>\n<p>An HTML file uses the same language as a webpage. It can reproduce a sign-in card, company colors, buttons, and instructions inside the browser.<\/p>\n<p>Because the file came from email, users may assume its content was scanned or approved. Mail scanning cannot guarantee that every interactive form is honest.<\/p>\n<p>The form\u2019s submission address can differ from everything visible on screen. Security analysts can inspect that code without sending credentials to the operator.<\/p>\n<p>For ordinary recipients, the safe rule is simpler: no quotation attachment should ask for the password to an unrelated mailbox.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Mailbox security investigation showing suspicious supplier messages\" title=\"\" class=\"lazyload\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/exxonmobil-rfq-activity.png\"><\/figure>\n<div id=\"mwtad1153113732\" class=\"gas_fallback-ad_381392-ad_406044-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Company, Address, and Fulfillment Checks<\/h2>\n<h3>Verify the exact legal entity<\/h3>\n<p>Large corporate groups contain many similarly named entities. Confirm which entity is buying, where it is registered, and which procurement process it uses.<\/p>\n<p>The email\u2019s \u201cExxonMobil LTD\u201d label does not establish a legal relationship. ExxonMobil was impersonated and is not responsible for the campaign.<\/p>\n<h3>Treat copied addresses as unproven<\/h3>\n<p>Scammers can paste a real headquarters address beneath a fake sender domain. Address accuracy proves only that the information was publicly available.<\/p>\n<p>Compare registration records, tax details, delivery locations, and correspondence domains. Inconsistencies should pause quotation work until the buyer confirms them.<\/p>\n<h3>Call an independently published number<\/h3>\n<p>Use the company\u2019s official switchboard or established supplier contact. Ask to be transferred to procurement and verify the named person and reference.<\/p>\n<p>Never let the suspicious message define the entire verification channel. A criminal can control the email address, signature, telephone number, and reply.<\/p>\n<h3>Verify delivery and payment expectations<\/h3>\n<p>Fraudulent buyers may later request samples, credit terms, or shipments to unrelated freight forwarders. Confirm every location and responsible entity before dispatch.<\/p>\n<p>Do not confuse a fulfillment warehouse with a corporate office. Understand who owns the goods, who accepts delivery, and who is legally obligated to pay.<\/p>\n<h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>Preserve the RFQ evidence.<\/strong> Close the local page without another submission, then retain the original email and attachment for your security team.<\/li>\n<li><strong>Change the mailbox password.<\/strong> Use a clean device and the official account portal. Choose a unique password that is not used elsewhere.<\/li>\n<li><strong>Revoke sessions and review multi-factor methods.<\/strong> Remove unfamiliar devices, tokens, recovery addresses, telephone numbers, and application passwords.<\/li>\n<li><strong>Inspect mailbox rules and delegates.<\/strong> Delete unauthorized forwarding, hiding rules, connected applications, and delegated access. Review sent and deleted folders.<\/li>\n<li><strong>Notify management, finance, and IT.<\/strong> They should search for the campaign, review affected conversations, and warn customers about possible impersonation.<\/li>\n<li><strong>Audit recent payment changes.<\/strong> Call known customers and suppliers to verify beneficiary updates, revised invoices, and unusual requests made from the account.<\/li>\n<li><strong>Change reused credentials.<\/strong> Prioritize banking, customer portals, cloud storage, payroll, and administrator accounts that shared the exposed password.<\/li>\n<li><strong>Scan the computer.<\/strong> The confirmed lure targets credentials, but run Microsoft Defender and Malwarebytes to check for additional downloads or scripts.<\/li>\n<li><strong>Add layered web filtering.<\/strong> AdGuard can block some malicious destinations and advertisements, but staff must still verify unexpected business opportunities.<\/li>\n<li><strong>Report attempted fraud quickly.<\/strong> Contact banks immediately if funds moved, then file reports with law enforcement and relevant cybercrime authorities.<\/li>\n<\/ol>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Was this RFQ really sent by ExxonMobil?<\/h3>\n<p>No. The investigated message impersonated ExxonMobil. The sender and attachment were part of a credential-phishing campaign.<\/p>\n<h3>Why does the attachment end in .xls.html?<\/h3>\n<p>The final \u201c.html\u201d means it is a webpage file. Adding \u201cxls\u201d earlier in the name helps it resemble a quotation spreadsheet.<\/p>\n<h3>Can a local HTML file steal information?<\/h3>\n<p>Yes. It can display a form and send entered data to a remote server. A \u201cfile:\/\/\/\u201d address does not guarantee offline behavior.<\/p>\n<h3>Am I compromised if I opened it but entered nothing?<\/h3>\n<p>The confirmed credential risk is much lower. Close it, report it, scan the device, and investigate any download, prompt, or unusual browser behavior.<\/p>\n<h3>Should I reply and ask the buyer to verify themselves?<\/h3>\n<p>No. Contact the company through an independently sourced switchboard or supplier portal. Replying keeps verification inside a channel the attacker may control.<\/p>\n<h3>Could the scam lead to financial theft?<\/h3>\n<p>Yes. A stolen business mailbox can support invoice diversion and fraudulent bank changes, although that outcome was not confirmed for every recipient.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The fake ExxonMobil RFQ uses realistic procurement language to deliver an HTML credential form disguised as a quotation document.<\/p>\n<p>Read complete filenames, verify new buyers independently, and never provide an email password to open an attachment. If credentials were entered, secure the mailbox and notify business partners quickly.<\/p>\n<div id=\"mwtad1318339588\" class=\"gas_fallback-ad_176819-ad_406044-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A request for quotation can look like a valuable new lead. Suppliers are trained to respond quickly when a large prospective customer appears. This RFQ uses detailed purchasing language, but the attachment\u2019s real file type &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"ExxonMobil RFQ Email Scam Exposed: Fake Quotation Attachment Investigated\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/exxonmobil-rfq-email-scam-quotation-attachment\/#more-409253\" aria-label=\"Read more about ExxonMobil RFQ Email Scam Exposed: Fake Quotation Attachment Investigated\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":409254,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-409253","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/409253","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=409253"}],"version-history":[{"count":2,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/409253\/revisions"}],"predecessor-version":[{"id":409432,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/409253\/revisions\/409432"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/409254"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=409253"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=409253"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=409253"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}