DOJO
MAKE ATTACHMENT VERIFICATION ORDINARY.
Practicing familiar-sender scenarios can help a family treat unexpected documents as something to confirm, even within a trusted relationship.
HARDTARGET™PRIVATE INQUIRYHARDTARGET INTEL / CASE FILE
CASE FILE #007 · TRUST
A familiar name.
Tomorrow’s meeting.
An unexpected attachment.

An illustrative HARDTARGET scenario, not a documented client or victim case. The sequence and consequences are representative educational details.
01 / THE SETUP
A woman receives an email appearing to come from her investment advisor. It asks her to review an investment-update PDF before their meeting the next morning.
The familiar name, routine meeting and invitation for her insights make the document feel like part of an established relationship. Reviewing it seems considerate and practical.
In this illustrative reconstruction, she opens the unexpected attachment before confirming it with her advisor. The advisor later says the document did not come from the firm. The file requires assessment; its actual effect is not presumed.

02 / THE SEQUENCE
ILLUSTRATIVE ATTACK PROGRESSIONAPPROACH
CONTEXT
REQUEST
ACTION
CHECK
03 / HOW IT WORKED
The attacker places an unexpected file inside a familiar advisory routine. The recipient’s willingness to prepare for a meeting gives the attachment a reason to be opened before its origin is tested.
The approach uses an advisory relationship and plausible meeting context.
The sender appears to be someone already entrusted with important affairs.
A reasonable preparation request encourages opening the file.
Attachment engagement is illustrated. Opening the file is not presented as proof of malware, device compromise or a documented loss.
04 / THE HUMAN TRIGGER

An established advisor earns a place in a family’s decision-making. A request to prepare for a meeting can feel like another small expression of that relationship.
The attack borrows both trust and professional authority. The file seems less uncertain because the person supposedly sending it is familiar.
Checking an unexpected attachment does not undermine the relationship. It protects the channel through which that relationship works.
05 / THE AI EFFECT
AI could help an impersonator tailor an advisory email to the language of the recipient’s financial relationship.
AI is a possible amplifier here, not established involvement in a documented incident.
DEPENDING ON THE INFORMATION AVAILABLE
A well-written request can feel considerate.
Its origin still needs to be established.
Further context: FBI / Generative AI and financial fraud
06 / SIGNALS
The document was not anticipated through the usual advisory exchange.
The recognizable name is carrying more weight than the actual sender details.
The attachment or file-sharing location differs from established practice.
A meeting deadline discourages a simple check.
The advisor’s normal process does not require this step.
The advisor has not confirmed the file through a known channel.
One unfamiliar detail may mean nothing.
Several together create a pattern.
07 / THE INTERCEPT
Relevant disciplines create opportunities to reduce exposure, recognize the request or introduce an independent check.
MAKE ATTACHMENT VERIFICATION ORDINARY.
Practicing familiar-sender scenarios can help a family treat unexpected documents as something to confirm, even within a trusted relationship.
STRENGTHEN THE ENVIRONMENT RECEIVING THE FILE.
Device, software and account protections can reduce some risks associated with deceptive files without guaranteeing that an attachment is safe.
UNDERSTAND WHICH RELATIONSHIPS ARE VISIBLE.
Reviewing exposed advisory connections can help identify the context an outsider could borrow.
Confirm an unexpected attachment with your advisor through a channel you already use before opening it. A familiar name is not independent verification.
EXPLORE THE DIGITAL BUNKER™FROM INTELLIGENCE TO PROTECTION
Recognizing the pattern creates an opportunity to interrupt it.
RISE ABOVE.