The version of a business email compromise that people picture involves technical sophistication, and the version that actually happens involves a password somebody chose in 2016 and used in three places. What follows is a composite assembled from the ordinary shape of these incidents rather than any single case, and its value is precisely that nothing in it is clever. Every step is something an unremarkable attacker does with unremarkable tools, which is why the defenses against it are also unremarkable and are almost never in place.
Week One, When Somebody Simply Signs In
A ten person contracting firm uses a hosted email service. The office manager’s address and a password appear in a compiled list of credentials leaked from an unrelated online retailer several years earlier, and that same password protects the work mailbox because it was easy to remember and nobody ever suggested otherwise. Somebody signs in from another country on a Tuesday evening. Nothing breaks, nothing is deleted, and no alert reaches anybody, because from the service’s point of view the correct password was entered. For several days nothing happens except reading, while the intruder learns who the customers are, which supplier is owed money, and what the office manager sounds like in writing. A quiet forwarding rule keeps selected messages out of sight, so the mailbox looks entirely normal to its owner.
Week Two, When the Groundwork Is Laid
The preparation is administrative rather than technical. A domain is registered that differs from the firm’s by one character, close enough that nobody reading quickly would notice. The forwarding rule keeps a conversation with a regular supplier out of the office manager’s inbox, so the attacker can answer it while the real recipient sees nothing. Timing is chosen deliberately, and the week the owner is away at a trade show is the obvious candidate. What makes this work is that everything the attacker sends is consistent with everything already in the mailbox. The invoice looks like previous invoices because it was built from one. The tone matches because it was copied. The amount is plausible because the attacker has read a year of them. Nobody is being asked to do anything unusual, which is the entire design, and it is why suspicion is not a reliable defense.
Week Three, When the Payment Clears
An email arrives from what appears to be the supplier, attaching an updated invoice and mentioning that banking details have changed following a change of provider. It arrives in an existing thread, it is signed by the usual name, and it asks for nothing except payment of a sum already owed. The bookkeeper updates the payee record and releases the transfer, which is exactly what the process was designed to have her do.
The gap between the payment and the discovery is generally weeks, because the real supplier does not chase an invoice until it is properly overdue and the firm believes it has already been paid. By the time anybody compares notes, the funds have moved through two accounts and the practical prospects of recovery are poor. The bank is not at fault, the payment was authorized by the customer, and the loss sits with the firm.
The Four Points Where It Would Have Stopped
The first is the reused password, and a unique one would have ended the sequence before it began. The second is the absence of a second factor on email, which would have made a correct password insufficient. The third is the forwarding rule, which most services allow an administrator to alert on or prohibit outright, and which is the single most reliable indicator that a mailbox has been entered. The fourth is the payment process, and it is the one entirely within the firm’s control regardless of anything technical. A rule that any change to banking details is verified by telephone on a number already held, never on a number supplied in the message requesting the change, would have stopped this at the last possible moment. It costs one phone call per change, and changes of that kind are rare enough that the burden is negligible.
What the Firm Changed in a Single Afternoon
Afterward the firm did four things in an afternoon. Second factor authentication on every mailbox. A password manager so that unique passwords were practical rather than aspirational. Administrator alerting on new forwarding rules. And a written payment rule requiring verbal verification of any change to payee details, signed by everybody who can release a payment. It also asked its insurance broker what its policy actually covered, which is a conversation better had before than after, since fraudulent transfer of funds is frequently excluded from general policies and sits in a separate crime or cyber endorsement.
None of the four changes is sophisticated and none of them cost much, which is the point of telling the story this way. The firms that lose money to this are not the ones facing an unusually capable adversary; they are the ones where an old password, an unmonitored rule, and a payment process built on trust all happened to line up in the same fortnight. The defenses are boring, they are cheap, and they are only ever installed by somebody who has understood how ordinary the attack actually is.