• Home
  • About Us
  • Courses
  • Membership
    • Registration
  • Events
  • Blog
  • Contact
  • Home
  • About Us
  • Courses
  • Membership
    • Registration
  • Events
  • Blog
  • Contact
RegisterLogin

Blog

  • Home
  • Blog
  • Blog

Business email compromise – the silent corporate killer

  • Posted by Mr Strategy
  • Date March 5, 2025
  • Comments 0 comment

In January 2023, we received a phone call from the CEO of a well-known logistics company. His voice carried the weight of urgency and frustration.

“Mr. Strategy, I think we’ve been scammed, but I can’t understand how. We wired about seventy-one thousand United States dollars to what we believed was our supplier’s account, only to find out it never reached them. The finance team insists they followed the right process, but the supplier says they never changed their banking details. I need answers. Fast.”

It was a classic case of Business Email Compromise (BEC), but as we would soon uncover, the attackers had executed their scheme with surgical precision.

The fraudster’s playbook  you it all happened

By the time we stepped into the company’s headquarters, panic was evident. The finance director, the IT manager, and the CEO were all waiting. They needed an explanation.

Here’s what we found out:

Initial compromise

After analysis of their systems, we found out that the company’s finance officer, Subject 1, had unknowingly clicked on a phishing email a few weeks earlier. The email, disguised as a routine Microsoft 365 security update, asked her to verify her credentials. The attackers, operating as Subject 2, captured her email login details in real time and immediately accessed her inbox.

Email monitoring and reconnaissance

The criminals did not act immediately. Instead, they watched. Sophisticated cybercriminals are very patient people. They take their time. For three weeks, they studied email conversations between the finance team and key suppliers. They identified the payment patterns, the tone of the emails, and the key players in financial transactions. They examined the approval limits, and emmergency instances when finance is allowed to process the payment quickly.

The deception begins

Once the attackers had a full picture, they acted. They created a lookalike email domain, changing just one letter in the supplier’s email address—something barely noticeable to the human eye. Using this fraudulent email address, Subject 2 posed as the supplier’s accounts manager, informing the company of a “recent banking update” due to an “ongoing audit.”

Social engineering at its best

To further authenticate their claim, the fraudsters compromised the supplier’s actual email account and forwarded previous legitimate invoices. They even used the supplier’s real email signature, adding credibility to the deception.

Execution of the fraud

With all the pieces in place, Subject 1 received a final email instructing payment to the “new” bank account. The finance team, trusting the familiar conversation thread, wired $71,240 without hesitation.

The aftermath

Two days later, the real supplier followed up for payment, completely unaware of the fraud. By then, the money had already been withdrawn from an offshore account.

What went wrong? The investigations

Once we pieced together the fraud, the next step was to determine how the company let this happen.

  1. Weak email security. The finance officer’s email was compromised because the company did not enforce multi-factor authentication (MFA) on their accounts.
  2. Lack of financial verification protocols. The finance department had no internal process for verifying bank detail changes. A simple phone call to the supplier’s known contact number would have stopped the fraud.
  3. Poor cyber awareness. Employees were last trained two years ago to identify phishing emails, making them easy prey for attackers.

Lessons learned

  1. Enforce email security. Implement multi-factor authentication (MFA) for all corporate email accounts.
  2. Tighten financial processes. No banking details should ever be changed based on email instructions alone. Always verify via phone calls to known contacts.
  3. Train employees. Conduct phishing awareness training and test employees regularly with simulated attacks.

The cost of negligence

  • Share:
Mr Strategy

Previous post

How Omundo stole money using ATM cards that were not his
March 5, 2025

Next post

Cybercrime is a constant business: Three business areas to watch out for!
March 11, 2025

You may also like

861b386f2b82ad3755f755a260fa98ce
The loan file that looked compliant
July 22, 2026
3ada66f904c1341a8997499b1391c6a8
Mobile money is not informal money
July 22, 2026
f5d992dc1d077909c365d6f8e24cf93a
The honest employee who became expensive
July 8, 2026

Leave A Reply Cancel reply

Your email address will not be published. Required fields are marked *

Are you human? Please solve:Captcha


Popular Courses

Internal Audit Core

Internal Audit Core

$1,120
Certified Fraud Forensic Professional

Certified Fraud Forensic Professional

$1,120
Certified Cyber Security Manager

Certified Cyber Security Manager

$1,120

At IFIS, we live by our motto. Every course, certification, and training session emphasizes practical, hands-on skills that empower you to solve real-world challenges from day one. Learn by doing. Be empowered to transform your career and life.

Facebook X-twitter Youtube Instagram

Quick Links

  • Home
  • About Us
  • Courses
  • Membership
    • Registration
  • Events
  • Blog
  • Contact
  • Home
  • About Us
  • Courses
  • Membership
    • Registration
  • Events
  • Blog
  • Contact

Contact Us

  • info@forensicsinstitute.org
  • +256 783373637
  • +256 782 610333
  • Strategy Place, Trinity Building, Block 216, Plot 2475, Kayondo Road, off Ntinda–Kiwatule Road, Kalinabiri, Ntinda, P.O. Box. 40292, Kampala.
  • Privacy Policy
  • Terms & Conditions

© 2026 – Forensic Institue. All rights reserved.

Login with your site account

Or login with:

Google
Are you human? Please solve:Captcha


Lost your password?

Not a member yet? Register now

Register a new account

Or login with:

Google
Are you human? Please solve:Captcha


Are you a member? Login now