Business email compromise does not look like the ransomware note or the flashing alert most people picture when they hear “cyberattack.” It looks like an ordinary, well-timed email. This illustrative scenario shows how a supplier mailbox and a plausible invoice can create a payment-redirection risk.
01The setup: a compromised supplier, not the target
In this scenario, the attacker may not need to breach the finance team's own systems. A supplier mailbox could have been compromised through phishing, then monitored for real invoice threads, payment cycles, and amounts. The risk is quiet because the relationship is familiar.
02The move: a near-perfect forgery, perfectly timed
During a genuine invoice cycle, the attacker could send a follow-up from the compromised supplier mailbox with one change: updated bank details for a $40,000 payment, framed as a routine account switch. A familiar address and a deadline can make a changed detail look ordinary unless the process requires independent verification.
03The gaps that let it get this far
- No dedicated email security layer — default mailbox filtering does not flag a message from a legitimate, previously-trusted sender.
- No out-of-band verification process for bank-detail changes — the request was never checked against anything outside the email thread itself.
- No log visibility into the mail rule the attacker's access had planted, which was quietly forwarding a copy of relevant threads.
04What stopped it
The control sequence to verify is straightforward: anomaly detection creates a pause, and a callback to a known, independently sourced supplier number confirms or rejects the bank-detail change. The decision and evidence should be recorded before payment release.
05The four controls, in order of cost
- A mandatory callback-verification policy for any bank-detail change — the lowest-cost control on this list.
- Dedicated email security with anomaly detection layered over default mailbox filtering.
- Log monitoring (SIEM) with visibility into mailbox rules and forwarding behaviour, not just inbound spam.
- Staff training on business-email-compromise red flags, refreshed on a schedule rather than run once at onboarding.
Invoice fraud often exploits trust in a relationship you cannot fully control. Independent callback verification is a practical control because it tests the change outside the suspect email thread. Treat this page as an educational scenario and verify the process against your own payment workflow.
Where this leaves you
Knowing the risk is not the same as knowing your own exposure.
The Cyber Readiness Assessment gives you a written, prioritised answer in ten business days — enquire for scope and terms.