I've tried searching a few terms but can't really answer my question.
We have a system which sends out invoices and we have had a couple of instances with one individual where the PDF attachment has somehow been altered between us sending it and the recipient opening it. The PDF normally contains a 'pay now' link but this has been deleted and replaced with spurious bank account details. This individual was sent two emails with different PDF attachments on the same day but at different times, and both have been altered in the same way.
At this stage I am just looking for possible ways this might have been done so we can investigate further. Emails are sent by Amazon SES and the customer has a bigpond.net.au email address. We are using DKIM signatures on sent emails.
I'm trying to get hold of the header from the email that was sent. I only have a forwarded copy of it.
Would appreciate any suggestions so that we can gather some more information about it.