An email landed with a subject line about a seizure of assets — my bank accounts, my property, ordered under German tax law. I didn't open it. I decrypted it by hand instead: three layers of obfuscation, a fake login page built pixel-perfect from the real tax office's own logo, and my own email address hardcoded inside it, with a campaign number attached, like I was one row in a spreadsheet.
That part isn't what stuck with me. What stuck with me is what happened after, on both sides. My own helpdesk auto-replied to the phisher with a legally binding GDPR commitment, because it checks whether an email arrived, not whether it's real. And when I went to report the attack, the "official" reporting channel was a maze built to satisfy an audit, not to help anyone standing outside it trying to get in.
This episode is about the mechanism underneath both failures: systems built to react to the shape of a thing instead of checking its substance — and why I found the exact same shortcut sitting inside my own business, built by me, years ago.
Iconoclast Insights is André Daus — Strategic Opposition, uncomfortable questions, no comfortable answers.