This is an anonymized account of a business email compromise attempt against a professional services client — details altered to protect the client, but the mechanics are accurate and representative of how this attack type typically plays out.
How it started
The client’s accounts payable team received an email that appeared to come from a known vendor, referencing a real, existing invoice and requesting that future payment be sent to a "updated" bank account due to a supposed banking change. The email used the vendor’s actual logo and closely mimicked their usual tone — it wasn’t a crude, obviously fake attempt.
What caught it
The accounts payable lead had a standing habit — not a formal policy at the time, just personal practice — of confirming any banking-detail change by phone, using a number pulled from prior invoices rather than any number provided in the email itself. The phone call reached the real vendor, who had sent no such request. That one habit is what stopped the transfer.
What the investigation found
The vendor’s email account had been compromised through a phishing email weeks earlier, and the attacker had been monitoring the mailbox, watching for exactly this kind of invoice conversation before inserting themselves into it — a more patient version of the attack than a random blind attempt. We found this out after the client looped in the vendor, whose own security team confirmed the intrusion.
What changed afterward
The client formalized what had been an informal habit into policy: any banking-detail change requires phone verification using a number from an independent source, not the email itself. We also implemented DMARC enforcement and deployed additional email security controls to reduce the chance of a similar compromise reaching their own mailboxes. The near-miss became the reason the control finally got written down, instead of depending on one person’s good habit.