Agent Foskett Case File • Email Security • Social Engineering • Microsoft Defender XDR • KQL

The $3.2 Billion Investor Who Also Had 800 KG of Gold

Some investigations begin with a suspicious sign-in.

Others begin with PowerShell.

This one began with someone wondering why I hadn't replied to his USD $3.2 billion investment opportunity.

Apparently he'd emailed me three times.

Sorry. Been busy. 😂

Agent Foskett investigating a suspicious 3.2 billion dollar investment and 800 kilogram gold email scam
Big Numbers Don't Equal Credibility

The promise was enormous. The investigation was much simpler: check the sender, check the domain, check the company and follow the evidence.

✓ Different company and email domain
✓ Request to move to WhatsApp
✓ KYC and identity-verification language

The offer was difficult to ignore

According to the email, there was USD $3.2 billion available for investment in suitable projects. But that wasn't all. The sender also wanted to know whether I knew anyone interested in buying 800 kg of 24-carat gold bars.

Of course.

Because when you're moving billions of dollars internationally, the obvious strategy is to cold-email a technology company and ask: “While I've got you... know anyone who wants 800 kilos of gold?” 😂
USD $3.2 billionAn extraordinary unsolicited investment opportunity arriving by email.
800 kg of goldA second extraordinary proposition added to an already extraordinary message.
Three emailsThe sender appeared particularly keen to receive a response.

Agent Foskett noticed a few clues

The supposed CFO was representing one company, but the message came from a completely different domain. Then came the request for a WhatsApp video call, followed by references to KYC, due diligence and identity verification. And my favourite part? The sender wanted me to confirm whether I was “still managing this email account.”

Nice try. 😂
Identity mismatchThe claimed business identity and the sending domain did not line up cleanly.
Move the conversationThe sender wanted the discussion shifted away from email and onto WhatsApp.
Identity collectionKYC and verification language can create a plausible reason to request sensitive personal or business information.

The billions were interesting. The domain was more interesting.

A SOC analyst does not need to decide whether the promise sounds believable before beginning the investigation. In Microsoft Defender XDR Advanced Hunting, start with the observable evidence. Replace the example domain below with the actual sender domain from the message and establish where else it appears.
investigate-sender-domain.kql
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
  8. 8
  9. 9
  10. 10
  11. 11
  12. 12
  13. 13
let SuspiciousDomain = "suspicious-domain.example";
EmailEvents
| where Timestamp > ago(30d)
| where SenderFromDomain =~ SuspiciousDomain
| project Timestamp,
          SenderFromAddress,
          RecipientEmailAddress,
          Subject,
          DeliveryAction,
          ThreatTypes,
          DetectionMethods
| order by Timestamp desc

Was I the only person they contacted?

One suspicious email is useful evidence. A pattern is better. Summarise activity from the sender domain to see how many messages and recipients are associated with it. In a business environment, this can quickly show whether the message was an isolated approach or part of a broader campaign.
sender-domain-pattern.kql
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
  8. 8
  9. 9
  10. 10
  11. 11
  12. 12
let SuspiciousDomain = "suspicious-domain.example";
EmailEvents
| where Timestamp > ago(30d)
| where SenderFromDomain =~ SuspiciousDomain
| summarize Emails=count(),
            Recipients=dcount(RecipientEmailAddress),
            FirstSeen=min(Timestamp),
            LastSeen=max(Timestamp)
    by SenderFromAddress, SenderFromDomain
| order by Emails desc

Check the URLs before following them

If the messages contained links, pivot from the email into EmailUrlInfo. The goal is not to click the link to see what happens. It is to inspect the URL evidence associated with messages from the suspicious domain and identify infrastructure that may deserve further investigation.
sender-domain-urls.kql
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
  8. 8
  9. 9
  10. 10
  11. 11
  12. 12
  13. 13
let SuspiciousDomain = "suspicious-domain.example";
EmailEvents
| where Timestamp > ago(30d)
| where SenderFromDomain =~ SuspiciousDomain
| project NetworkMessageId, Timestamp, SenderFromAddress, Subject
| join kind=inner (
    EmailUrlInfo
    | project NetworkMessageId, Url, UrlDomain
) on NetworkMessageId
| project Timestamp, SenderFromAddress, Subject, Url, UrlDomain
| order by Timestamp desc

Hunt for similar investment approaches

If the exact sender is only one clue, broaden the hunt carefully. Subject keywords can help surface potentially related messages for analyst review, but they are not proof of malicious activity. Legitimate business email can contain the same words, so treat the results as leads rather than detections.
investment-email-hunt.kql
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
  8. 8
  9. 9
  10. 10
  11. 11
  12. 12
EmailEvents
| where Timestamp > ago(30d)
| where Subject has_any (
    "investment",
    "gold",
    "funding",
    "business proposal"
)
| project Timestamp, SenderFromAddress, SenderFromDomain,
          RecipientEmailAddress, Subject, DeliveryAction
| order by Timestamp desc

What Agent Foskett checked

SenderWho actually sent the message, and does that identity match the person being claimed?
DomainDoes the sending domain belong to the organisation named in the email?
CompanyCan the claimed role, organisation and business relationship be independently verified?
Other recipientsDid the same sender or domain contact other people in the environment?
URLsWere links included, and what infrastructure appears behind them?
Platform shiftWhy does the sender want the conversation moved to WhatsApp or another channel?

What the evidence can and cannot prove

Suspicious wording, mismatched domains and an unusual request can justify investigation, but one clue alone does not prove fraud. KQL can establish what Microsoft 365 observed: sender addresses, domains, recipients, delivery actions, URLs and patterns across messages. Verification of the claimed person and company should be performed independently using trusted contact information rather than details supplied in the suspicious message.
Telemetry can showHow the message appeared in the environment and whether related infrastructure or recipients exist.
Independent checks can showWhether the claimed organisation and individual can be verified through trusted sources.
Do not assumeLarge numbers, formal language and KYC terminology do not establish credibility.

The lesson

Big numbers don't equal credibility.

Don't investigate the promise.

Investigate the person making it.

Check the sender. Check the domain. Check the company. Question the urgency. And don't move the conversation elsewhere just because they ask.

And if someone with $3.2 billion and 800 kg of gold is desperately chasing you because you haven't answered their emails...

you might want to investigate that too. 😂
Investigation principle: Follow the evidence before you follow the opportunity.
$3.2 billion. 800 kg of gold. One unsolicited email.
The bigger the promise, the more important it becomes to verify the evidence behind it.
Continue the Investigation

Final thought

The most useful clue in this case was never the amount of money.

It was the mismatch between the story being told and the evidence sitting behind the message.

A polished title can be typed. A huge number can be typed. “KYC” can be typed. Even 800 kilograms of gold can be typed. 😂

The evidence still has to stand up.

Follow the evidence. Build the timeline.

The Logs Already Knew! 🔎
Develop IT.. Protect IT.. GEMXIT.
GEMXIT PTY LTD | GEMXIT UK LTD
Talk to GEMXIT

The $3.2 Billion Investor Who Also Had 800 KG of Gold

This Agent Foskett case file investigates an unsolicited investment email claiming USD $3.2 billion in available funds and 800 kg of 24-carat gold, with red flags including a mismatched sender domain, WhatsApp migration and KYC language.

Microsoft Defender XDR Email Investigation With KQL

Use EmailEvents and EmailUrlInfo in Advanced Hunting to investigate sender domains, recipients, message patterns and URLs associated with suspicious email activity.

Email Scam And Social Engineering Investigation

Large financial claims do not establish credibility. Verify the sender, domain and company independently, investigate related Microsoft 365 telemetry and treat requests to move communication or provide identity information with caution.