A controller received what appeared to be a routine request from a long-standing construction vendor: future payments needed to go to a new bank account. The sender’s name, signature, invoice format, and timing all looked right. This email compromise case study examines why the request was nearly approved, how the risk was contained before funds moved, and what business leaders can learn from the close call.
The organization was a growing professional services firm with approximately 90 employees, a lean finance team, and an internal IT manager responsible for daily support. Like many midsize businesses, it had Microsoft 365, multi-factor authentication, endpoint protection, and a documented approval process for wire transfers. On paper, it had reasonable safeguards.
The incident exposed a harder truth: security tools can block many threats, but they cannot compensate for a process that trusts email as proof of identity.
Email Compromise Case Study: What Happened
The attack began several weeks before the payment request. A criminal obtained credentials for an accounts payable employee through a convincing phishing page that imitated the company’s Microsoft 365 sign-in screen. The employee had multi-factor authentication enabled, but the attacker used an adversary-in-the-middle phishing kit that captured the session token after the user approved the login prompt.
That detail matters. Multi-factor authentication remains essential, but not every form of MFA provides the same resistance to modern phishing. A stolen session token can allow an attacker to access a mailbox without repeatedly triggering an approval request.
Once inside, the attacker did not immediately send messages. Instead, they monitored conversations between the finance team and several vendors. They learned who approved payments, how invoices were formatted, which suppliers were paid regularly, and the language employees used in internal emails.
After identifying a vendor with a large upcoming payment, the attacker created a mailbox rule that moved replies from the real vendor into an obscure folder. They then used the compromised employee’s account to continue an existing email thread. The request stated that the vendor had changed banks and included new account details for an upcoming $180,000 payment.
The controller noticed one small inconsistency. The vendor’s contact had signed prior messages with a full name and title, while this message used only an abbreviated first name. It was not enough to prove fraud, but it was enough to pause the payment.
Rather than reply to the email, the controller called a phone number already listed in the company’s vendor records. The actual vendor confirmed that no banking change had been requested. The finance team stopped the payment, alerted IT, and preserved the suspicious messages for investigation.
Why the Scam Was So Convincing
Business email compromise succeeds because it uses legitimate business activity as camouflage. The attacker did not send a poorly written message from an unfamiliar address. They inserted themselves into a real vendor relationship, used a real employee mailbox, and timed the request around an expected payment.
The finance team also faced operational pressure. The payment deadline was approaching, the vendor was important to ongoing projects, and the request did not initially look unusual. These conditions are common in organizations that are growing quickly or operating with limited administrative capacity. Employees are trying to keep work moving, not conduct a forensic review of every message.
This is why awareness training alone has limits. Training can help employees recognize suspicious links, unexpected attachments, and unusual requests. It is less reliable when a fraudulent email comes from a trusted internal account and matches an active conversation.
The strongest defense is a combination of trained employees, technical visibility, and financial procedures designed to assume that email can be compromised.
The Response That Contained the Damage
After confirming the fraud attempt, IT treated the event as a potential account takeover rather than simply deleting a suspicious email. That distinction drove the right response.
The compromised account was immediately disabled, active sessions were revoked, and the password was reset. IT reviewed sign-in activity for unfamiliar locations, devices, and authentication methods. Mailbox rules, delegated access, forwarding settings, and recently sent messages were examined to determine whether the attacker had established persistence or contacted other vendors.
The team also searched the environment for the attacker’s indicators, including similar sender addresses, payment-change language, and rules that redirected vendor communications. Finance notified affected vendors through known phone contacts, while leadership documented the incident and reviewed whether any other payments had been altered.
The organization had a meaningful advantage: the controller escalated the concern before acting. But the response also revealed a gap. The company did not have a formal, tested business email compromise playbook. Responsibilities were understood generally, yet no one had a predefined checklist for securing accounts, preserving evidence, notifying financial institutions, or communicating with vendors.
That gap did not cause the incident, but it could have increased the damage if a payment had already been released. Fast decisions are easier when the right steps have been agreed upon before a crisis.
Controls That Failed and Controls That Worked
Several controls worked as intended. The employee recognized that the request deserved scrutiny. Finance used an out-of-band verification method instead of trusting the email thread. IT had sufficient access to investigate the account quickly. Those actions prevented a six-figure loss.
Other controls needed improvement. The organization’s MFA method was vulnerable to token theft. Conditional access policies did not sufficiently challenge sign-ins from unfamiliar devices or risky locations. Alerts for suspicious inbox rules were available but had not been tuned and routed for rapid review. Most importantly, the vendor banking-change process did not require independent verification every time.
That final point is the most practical lesson. No security product can validate whether new wire instructions are legitimate. A mandatory phone callback to a verified number can. For larger payments, some organizations require dual approval and a second verifier who is not involved in the original email exchange.
The right level of control depends on the business. A small company processing occasional payments may use a callback and documented approval. A mortgage, escrow, construction, healthcare, or professional services organization handling high-value or time-sensitive disbursements may need tighter segregation of duties, payment holds, and bank-side transaction controls. The principle stays the same: a change in payment instructions should be treated as high risk until independently confirmed.
How to Reduce Email Compromise Risk Before the Next Request
Start by protecting identities, because cloud email accounts are often the attacker’s entry point. Use phishing-resistant MFA where practical, such as FIDO2 security keys or passkeys, especially for finance leaders, administrators, executives, and employees with access to sensitive transactions. Pair MFA with conditional access policies that evaluate device health, location, risk signals, and unusual sign-in behavior.
Then improve visibility. Security monitoring should alert the right people when an inbox rule forwards messages externally, moves emails unexpectedly, or grants access to another user. Logging is valuable only when someone reviews meaningful alerts and knows how to respond. For an internal IT team already managing daily tickets, this is often where a managed cybersecurity partner can add needed coverage and escalation capacity.
Finally, make financial verification non-negotiable. Banking changes, urgent wire requests, payroll updates, and changes to customer payment instructions should be confirmed outside email using information already on file. Employees need permission to slow down a transaction when something feels off. A culture that rewards speed at all costs creates room for criminals to exploit normal business urgency.
A concise business email compromise response plan should identify who can disable accounts, who contacts the bank, who verifies vendor communications, who informs leadership, and how evidence is retained. Test the plan with a realistic scenario. The goal is not to create fear or add bureaucracy. It is to ensure that a single deceptive message does not become an operational or financial emergency.
The Business Lesson Behind the Incident
The near miss was not caused by one careless employee. It resulted from a capable attacker finding the narrow space between trusted communication, busy operations, and incomplete controls. That is why email security must be managed as a business continuity issue, not merely an IT setting.
A well-protected organization expects suspicious requests to occasionally reach employees. Its advantage comes from layers: protected identities, monitored infrastructure, clear payment controls, responsive support, and people who know they can pause and verify. When an email asks to move money, change account information, or bypass normal process, a five-minute phone call can protect far more than one transaction. It can protect the trust your business has spent years building.