Toolkit by Bot&Partners / films / Phishing and spoofed addresses

Phishing and spoofed addresses

One of the costliest frauds starts with an ordinary email from a familiar supplier. The film shows how an account number gets swapped and which check stops it.

Film · practicum “Security”
Keep scrolling

    As text

    The same as the films: every shot and its text. You can copy the text and give it to your own assistant along with your question.

    Phishing and spoofed addresses

    1. The supplier and the buyer's accountant have been emailing each other for years. The invoice arrives in an email, and the payment goes to the IBAN written on the invoice. Nobody checks each email on its own, because there are many of them and they all look alike. The fraud known as invoice redirection relies on this habit.

    2. It starts with the supplier. He gets a phishing email and types his password into a fake login page, and from then on an outsider has access to his mailbox. For a few weeks the outsider only reads the mail. He sets up a rule that forwards him copies of the emails and waits for the next invoice.

    3. When a payment falls due, the buyer gets an email: our bank details have changed, please pay today. The fraudster sends it from the same mailbox or from a domain with one letter changed. The style, the signature and the references to earlier emails are genuine, because he has read them. The attachment is an ordinary invoice in which only the IBAN differs.

    4. The accountant pays the invoice, because there is no reason to doubt it. The money lands in the fraudster's account, and the supplier never receives it. This comes out a few days later, when the supplier asks about the payment. By then the fraudster has usually moved the money on, and every hour lowers the chance of stopping it.

    5. Mail services and security teams filter out such emails all the time: spam filters, sender checks, monitoring. But an email from a real, compromised mailbox gets past the filter. So the most reliable defense is simple: call the person who is asking. A change of bank details is confirmed with the supplier by phone, using a number from the contract or older documents, not from the email. After that, a second person approves the change.

    6. Some signs give such an email away. New bank details together with a demand to pay urgently. A request to tell no one or to communicate only by email. A domain with one letter changed, and a reply address that does not match the sender's. And a request to bypass the usual approval process.

    7. If the payment has already gone, the first hours count. Call your bank, report the fraudulent payment and ask them to stop it or to contact the receiving bank with a request to freeze and return the funds. Next, a report to the cyber police. Keep the emails together with their headers: they show where an email really came from. The supplier, for their part, changes the password and checks the forwarding rules in the mailbox.

    Next