Full Report
Discover how Huntress caught an attempted business email compromise (BEC) scam that would have cost the company more than $100,000 had it gone undetected.
Analysis Summary
# Incident Report: Attempted $100k BEC via Vendor Compromise
## Executive Summary
Huntress successfully intercepted a Business Email Compromise (BEC) attempt targeting a $103,000 ACH payment. The incident involved the compromise of a third-party vendor’s email environment, where attackers masqueraded as vendor contacts to redirect funds to a fraudulent bank account. The attack was defeated through strict internal financial controls (out-of-band verification) and security awareness training rather than automated technical alerts.
## Incident Details
- **Discovery Date:** August 7, 2023
- **Incident Date:** August 4 – August 8, 2023
- **Affected Organization:** Huntress (Target); Undisclosed Marketing Vendor (Compromised Entity)
- **Sector:** Cybersecurity / Field Marketing
- **Geography:** United States (implied by ACH and Regions Bank involvement)
## Timeline of Events
### Initial Access
- **Date/Time:** Prior to August 4, 2023
- **Vector:** Compromise of third-party vendor’s Microsoft 365/email environment.
- **Details:** The threat actor gained full access to the vendor contact’s (“Darla”) email, allowing them to monitor ongoing financial transactions.
### Lateral Movement
- **Details:** The attacker expanded their footprint within the vendor’s organization, eventually compromising at least one other employee (“Nick”) to add legitimacy to fraudulent email chains.
### Data Exfiltration/Impact
- **Details:** No Huntress data was exfiltrated; however, the attacker monitored sensitive financial communications and attempted to divert $103,000 via a fraudulent bank change request.
### Detection & Response
- **August 4:** Huntress initiates a legitimate $103k ACH payment.
- **August 7 (Morning):** Attacker (as “Darla”) sends an email claiming "suspicious activity" in their bank and asks Huntress to stop the payment. Huntress stops the payment.
- **August 7 (Afternoon):** Attacker sends new fraudulent bank routing details.
- **August 7 (Detection):** Huntress staff follows the "Security-Centric Procedure" of out-of-band verification and calls the vendor. The vendor confirms they did not send the email.
- **August 8:** Attacker sends a follow-up "nudge" even after the vendor claimed to have shut down the compromised account, confirming persistent access.
## Attack Methodology
- **Initial Access:** Likely Phishing or Credential Stuffing (targeting the vendor).
- **Persistence:** Compromised legitimate Microsoft 365 accounts.
- **Defense Evasion:** Used legitimate, established email threads and correct signatures to bypass spam filters.
- **Discovery:** Monitored inbox for keywords like "invoice," "payment," and "ACH."
- **Lateral Movement:** Compromised multiple accounts within the vendor domain to "CC" each other and provide social proof.
- **Impact:** Financial Theft (Attempted).
## Impact Assessment
- **Financial:** $0 (Potential loss of $103,000 was averted).
- **Data Breach:** None for Huntress; Full email compromise for the vendor.
- **Operational:** Minor disruption to Huntress accounting; Significant disruption to vendor operations (shutting down email).
- **Reputational:** High for the vendor; Huntress utilized the event as a case study for security efficacy.
## Indicators of Compromise
- **Behavioral indicators:**
- Sudden request to change bank details during an active transaction.
- Claims of "suspicious activity" used as a pretext to stop a legitimate payment.
- Continued emails from an account that the owner claimed was deactivated.
## Response Actions
- **Containment:** Huntress immediately halted the ACH transfer at the bank level.
- **Eradication:** Vendor IT team deactivated compromised email accounts.
- **Recovery:** Out-of-band communication (phone calls) established to verify legitimate payment details.
- **Reporting:** Huntress reported the fraudulent account to Regions Bank.
## Lessons Learned
- **Process Over Tools:** In BEC cases involving compromised trusted partners, automated tools often fail because the traffic appears legitimate.
- **Out-of-Band Verification:** A mandatory phone call to a known number before changing payment details is the single most effective defense against BEC.
- **Vendor Risk:** An organization’s security is only as strong as its least secure vendor.
## Recommendations
- **MFA:** Ensure all vendors and internal staff utilize Multi-Factor Authentication (MFA).
- **Verification Policy:** Implement a formal policy requiring two-person authorization or voice verification for any change in banking instructions.
- **Security Awareness:** Train accounting departments specifically on the "pretexts" used in BEC, such as urgent bank changes or warnings of "account issues."