How ProArch SOC Stopped a Spoofed Domain BEC Attack Targeting Vendor Payments
How ProArch SOC Detected the Spoofed Domain BEC Incident
Our security team identified and responded to a Business Email Compromise (BEC) incident in which one of our client’s domains was spoofed to target external customers and vendors.
The attacker impersonated a legitimate employee and sent emails claiming that banking details had changed, embedding a fabricated prior message to make the request appear as a continuation of a real conversation.
Follow-up emails mimicked replies within the same thread and included a PDF attachment containing fraudulent bank account information, designed to redirect vendor payments to attacker-controlled accounts.
The SOC identified and contained the activity quickly, blocking the spoofed domain and removing the malicious emails before further damage occurred.
Who Is at Risk from Vendor Payment BEC Attacks
This incident is relevant to SOC teams, CISOs, IT admins managing email security, and finance or accounts payable teams — particularly at organizations that regularly exchange payment or banking information with vendors and customers via email.
How the Spoofed Domain BEC Attack Worked
The attacker used a look-alike domain to impersonate a legitimate employee at the client organization, targeting external customers and vendors directly.
Attack Vector: Look-Alike Domain Impersonation
- Spoofed/look-alike domain impersonating the client organization, used to email external customers and vendors.
- Initial email falsely claimed the customer’s banking details had changed, introducing an attacker-controlled bank account.
Social Engineering Techniques Used to Redirect Payments
- Email thread hijacking — a fabricated message dated in the past was inserted into the email body, claiming the “old bank account” would be closed, to create a false sense of continuity and urgency.
- Follow-up emails were crafted to mimic replies within the same ongoing thread, reinforcing legitimacy.
- A PDF attachment was sent containing fraudulent bank account details; sandbox analysis confirmed it was designed to deceive recipients into updating payment information and falsely represented itself as originating from the legitimate organization.
Key Pattern: Fraud Without Malware or Exploits
- The attack relied entirely on domain spoofing and social engineering rather than malware or exploits, limiting the effectiveness of traditional file- or URL-based detection controls.
Why Spoofed Domain BEC Attacks Matter
Financial Fraud — Vendors or customers could unknowingly redirect payments to attacker-controlled bank accounts.
Reputational Damage — Abuse of the client’s domain to defraud external parties can damage trust with customers and vendors.
Trust Erosion — Impersonation attempts like this undermine confidence in legitimate communications from the organization going forward.
Downstream Liability — Vendors or customers who fall victim may hold the impersonated organization responsible, creating relationship strain or potential liability exposure.
How ProArch SOC Responded to Prevent Vendor Payment Fraud
Immediate SOC Actions: Blocking, Deleting, and Alerting
- Block the spoofed/look-alike domain across email gateways and DNS filtering (already actioned by SOC).
- Hard delete identified malicious emails from all affected mailboxes (already actioned by SOC).
- Distribute an advisory to all known vendors and customers warning them of the impersonation (already actioned by SOC).
- Report the phishing domain to the relevant hosting provider/registrar for takedown.
Short-Term Controls: Strengthen Email and Payment Verification
- Tighten SPF, DKIM, and DMARC enforcement to reduce the success rate of domain spoofing.
- Establish an out-of-band verification process for any request to change banking or payment details.
- Train finance and accounts payable staff to recognize thread-hijacking and urgency-based social engineering tactics.
Long-Term Prevention: Monitor Domains and Formalize Payment Policies
- Deploy brand/domain monitoring to proactively detect newly registered look-alike domains.
- Formalize a vendor payment verification policy requiring dual approval for any banking detail changes.
- Run periodic phishing simulations focused on BEC and vendor payment fraud scenarios.
How ProArch SOC Continued Monitoring After the BEC Attempt
We continue to monitor for additional look-alike domains impersonating the client, further phishing attempts referencing this incident, and any indication that the fraudulent bank account details surface in other campaigns.
Strengthen Your Defenses with ProArch MDR
BEC attacks often move faster than traditional security teams can respond. ProArch’s Managed Detection and Response (MDR) service helps organizations detect suspicious activity, contain threats quickly, and reduce the risk of financial fraud before it escalates.
