Skip to main content

Scam: Inquiry About Product Supply to Italy / CATALOG REQUEST | Handpake Manufacturing Company Ltd.

Β· 6 min read
Jagdish Kumawat
Jagdish Kumawat
Founder @ Dewiride

We are interested in purchasing your company's products and would like to know if you can supply them to Italy. A fake buyer inquiry marked "TOP URGENT".

Complete Email​

from: Handpake Manufacturing Company Ltd. HR@neatwl.icu
to: info@jd-bots.com
reply-to: sales2@cnhandpak.com
date: 07/20/2026 8:36 AM
subject: Inquiry About Product Supply to Italy / CATALOG REQUEST

Email Body​

TOP URGENT

Dear Sir/Madam,

Greetings!

We are interested in purchasing your company’s products and would like to know if you can supply them to Italy.

We would appreciate your early response and look forward to hearing from you soon.

Thank you.

Best regards,

Handpake Manufacturing Company Ltd.

Address: Tiancheng Industrial Zone, Yueqing City,
Zhejiang Province, China
No: 86 577 27813218
Email: sales2@cnhandpak.com
https://www.cnhandpack.com

Attacking email screenshot


Red Flags​

This is a fake buyer inquiry β€” one of the most common opening moves against small exporters, manufacturers, and service companies. The message is deliberately empty of detail because its only job is to get a reply.

1. Three Different Domains in One Email​

  • Sender: HR@neatwl.icu
  • Reply-to: sales2@cnhandpak.com
  • Website in signature: www.cnhandpack.com

A genuine company sends, receives, and publishes from the same domain. Here all three differ β€” and the reply-to domain (cnhandpak) is missing the letter "c" present in the website (cnhandpack). That one-character gap is the classic signature of a lookalike domain registered to intercept correspondence intended for a real business.

2. A Throwaway Sending Domain​

  • .icu TLD: This is a cheap, bulk-registered top-level domain heavily associated with spam and short-lived scam infrastructure. No established manufacturer in Zhejiang sends commercial mail from a .icu address.
  • neatwl Is Meaningless: The sending domain bears no relationship whatsoever to "Handpake," "Handpack," or anything in the signature.

3. The Wrong Department Entirely​

  • HR@: Human Resources does not source products or request catalogs. Procurement inquiries come from purchasing, sourcing, or sales departments. The mailbox was simply whatever the sender had available.

4. The Company Name Is Misspelled​

  • The email signs off as "Handpake" while linking to "cnhandpack.com". A real business does not misspell its own name in its own signature block. This strongly suggests someone is loosely impersonating an existing Yueqing manufacturer rather than writing from it.

5. Manufactured Urgency With Nothing to Be Urgent About​

  • "TOP URGENT" in bold red: Applied to a message that asks no specific question, names no product, states no quantity, and sets no deadline. Urgency here is pure theatre, designed to trigger a fast reply before you think it through.

6. Completely Generic Content​

  • No Product Named: "your company's products" β€” the sender does not know or care what you sell. This identical email is being blasted to thousands of addresses scraped from the web.
  • No Quantities, Specs, or Terms: A real purchase inquiry includes part numbers, volumes, target pricing, Incoterms, or delivery timelines.
  • "Dear Sir/Madam": No name, no company reference, no evidence they have ever seen your website.
  • Italy Is Arbitrary: A Chinese manufacturer claiming to buy your goods for delivery to Italy is an odd trade flow, chosen because it sounds plausibly international.

7. Broken Template Artifact in the Subject​

  • The subject begins with ## β€” leftover markup from a mail-merge or template system that failed to render. Legitimate business correspondence does not ship with visible template debris, and it confirms this was machine-generated at volume.

How This Scam Works​

The first email is a filter. Replying marks you as a live, responsive, business-owning target, and the follow-up takes one of several routes:

  1. Advance-Fee Variant: A large order is agreed, then you are asked to pay a "registration fee," "export licence," "notary charge," or "sample shipping cost" before the purchase order is released. The order never exists.
  2. Fake Purchase Order / Goods Theft: A convincing PO arrives with generous terms. Goods are shipped on credit against a forged bank guarantee or a bad cheque, and the shipment disappears.
  3. Credential Phishing: The promised "catalog request" or "specification sheet" arrives as a link or attachment leading to a fake login page, or carrying malware.
  4. Business Email Compromise Setup: Correspondence is established through the lookalike domain, so that later β€” once real invoices are in play β€” banking details can be swapped without anyone noticing the missing letter.
  5. Fee-for-Introduction: You are told you must be "certified," "listed," or "verified" with a paid third party before the deal can proceed.

Conclusion and Recommendations​

This is not a sales lead. It is a mass-mailed probe using a disposable .icu domain and a lookalike reply-to address, dressed up with a real-looking Chinese factory address and a false sense of urgency.

Immediate Actions:​

  • Do Not Reply: Even a polite "we don't supply that" confirms a monitored, human-attended mailbox and invites escalation.
  • Do Not Send a Catalog or Price List: Your product data, pricing, and letterhead are exactly what is needed to build convincing fake documents in your name.
  • Do Not Open Attachments or Follow Links: Treat any "specification" or "order" file from this thread as hostile.
  • Report as Spam or Phishing: Flag it so your provider learns the pattern.
  • Warn Sales and Accounts: These land on info@, sales@, and enquiries@ inboxes where an eager salesperson may reply before anyone checks the headers.

Verification Steps:​

  • Compare Every Domain: Line up the From, Reply-To, and signature domains character by character. Any mismatch ends the conversation.
  • Contact the Real Company Independently: If the named manufacturer genuinely interests you, find their contact details yourself through a search engine or trade directory β€” never by replying or using the numbers in the email.
  • Check Domain Age: A WHOIS lookup showing a domain registered weeks ago is decisive for a company claiming years of operation.
  • Search the Exact Wording: Paste a full sentence into a search engine. Templates like this appear verbatim across scam-reporting forums.

Additional Protection Tips​

  • Treat Unsolicited Buyers Like Unsolicited Sellers: An inbound "we want to buy from you" deserves the same scrutiny as "we want to sell to you" β€” arguably more, because flattery lowers defences.
  • Insist on Specifics Before Engaging: Genuine buyers can name the product, quantity, destination port, and payment terms in their first message.
  • Never Ship on Unsecured Credit to a New Overseas Contact: Use a letter of credit or verified advance payment for first orders.
  • Lock Down Banking Change Requests: Require a phone callback to a previously known number before altering any payment details β€” the single most effective defence against the lookalike-domain endgame.
  • Train the Front Desk: The people monitoring generic inboxes are the real perimeter. They should know that "TOP URGENT" with no specifics is a warning sign, not a priority flag.

Remember: Real buyers describe what they want to buy. A message that cannot name a single product, quantity, or specification is not interested in your goods β€” it is interested in your reply.


Share this post