Our security team identified and responded to a Business Email Compromise (BEC) incident in which one of our client’s domains was spoofed to target external customers and vendors.
The attacker impersonated a legitimate employee and sent emails claiming that banking details had changed, embedding a fabricated prior message to make the request appear as a continuation of a real conversation.
Follow-up emails mimicked replies within the same thread and included a PDF attachment containing fraudulent bank account information, designed to redirect vendor payments to attacker-controlled accounts.
The SOC identified and contained the activity quickly, blocking the spoofed domain and removing the malicious emails before further damage occurred.
This incident is relevant to SOC teams, CISOs, IT admins managing email security, and finance or accounts payable teams — particularly at organizations that regularly exchange payment or banking information with vendors and customers via email.
The attacker used a look-alike domain to impersonate a legitimate employee at the client organization, targeting external customers and vendors directly.
Attack Vector: Look-Alike Domain Impersonation
Social Engineering Techniques Used to Redirect Payments
Key Pattern: Fraud Without Malware or Exploits
Financial Fraud — Vendors or customers could unknowingly redirect payments to attacker-controlled bank accounts.
Reputational Damage — Abuse of the client’s domain to defraud external parties can damage trust with customers and vendors.
Trust Erosion — Impersonation attempts like this undermine confidence in legitimate communications from the organization going forward.
Downstream Liability — Vendors or customers who fall victim may hold the impersonated organization responsible, creating relationship strain or potential liability exposure.
Immediate SOC Actions: Blocking, Deleting, and Alerting
Short-Term Controls: Strengthen Email and Payment Verification
Long-Term Prevention: Monitor Domains and Formalize Payment Policies
We continue to monitor for additional look-alike domains impersonating the client, further phishing attempts referencing this incident, and any indication that the fraudulent bank account details surface in other campaigns.
BEC attacks often move faster than traditional security teams can respond. ProArch’s Managed Detection and Response (MDR) service helps organizations detect suspicious activity, contain threats quickly, and reduce the risk of financial fraud before it escalates.