The Cyber Attack That Almost Worked
One of the biggest misconceptions about cybercrime is that attackers rely solely on mass phishing campaigns filled with obvious spelling mistakes and suspicious links.
In reality, many of today’s most successful attacks are carefully targeted, researched, and designed to blend seamlessly into legitimate business activity.
Recently, an organisation identified and reported an attempted payment diversion attack that demonstrates just how sophisticated modern Business Email Compromise (BEC) incidents have become. The attack ultimately failed, but it offers valuable lessons for businesses of every size. The incident involved a fraudulent email designed to impersonate a legitimate business contact and influence the handling of invoice payments. The message appeared convincing because it referenced genuine business activity, existing invoices, and known contacts involved in previous conversations.
Fortunately, vigilant staff recognised something wasn’t right and escalated the issue before any financial loss occurred.
Why Business Email Compromise Is So Effective
Unlike traditional phishing attacks, Business Email Compromise attacks often involve:
- Genuine supplier or customer relationships
- Real invoice references
- Existing email conversation topics
- Familiar names and job roles
- Time-sensitive financial requests
Attackers know that employees process large volumes of email every day. If a message appears to come from a trusted contact and fits into an existing business process, the recipient may not question it.
The goal is simple: create enough trust to convince someone to change payment details, transfer funds, disclose information, or bypass normal verification procedures.
Business Email Compromise Is Not a Rare Threat
Business Email Compromise (BEC) has become one of the most financially damaging forms of cybercrime worldwide. The threat is so significant that Ireland’s National Cyber Security Centre (NCSC) has published dedicated guidance to help organisations recognise and defend against these attacks. Businesses that handle invoices, supplier payments, payroll, or financial approvals should familiarise themselves with the guidance, available from the NCSC in their publication: NCSC Business Email Compromise Guidance.
The reason for this focus is simple: BEC attacks work. Criminals no longer rely on poorly written phishing emails. Instead, they research organisations, exploit trusted relationships, and craft highly convincing requests that appear to come from legitimate suppliers, customers, executives, or colleagues.
Real-world incidents highlighted by the NCSC demonstrate just how costly these attacks can be:
Irish Public Sector Loss Exceeding €500,000
In 2023, an Irish local authority transferred more than €500,000 to a fraudster after receiving a fake invoice from what appeared to be a legitimate supplier email address. The message was convincing, and payment was processed without additional verification. The funds were not recovered.
Irish Private Sector Incident Involving €98,000
In another Irish case, a private company lost more than €98,000 through a Business Email Compromise scam. The funds were transferred to a bank account in Portugal. Fortunately, rapid collaboration between the victim organisation and the financial institution resulted in the payment being stopped and the full amount recovered.
€40 Million CEO Impersonation Fraud
One of the most widely cited examples occurred in Germany, where a finance executive authorised payments totalling approximately €40 million after receiving convincing emails and phone calls purporting to come from senior executives and legal counsel. Investigators later determined that the attackers had spent considerable time studying the organisation’s operations, leadership structure, and approval processes before launching the attack.
These examples reinforce an important point: organisations of any size can become targets. Public bodies, SMEs, multinational organisations, and charities all face similar risks when financial processes depend on trust and email communications.
The incident discussed in this article demonstrated many of the same tactics seen in successful BEC attacks: use of a lookalike domain, reference to genuine invoices, knowledge of legitimate business relationships, and an attempt to initiate a bank detail change process. The difference was that vigilant employees questioned the request, checked the sender’s domain carefully, and escalated the email before any payment could be diverted.
This is a powerful reminder that while technology is essential, cyber awareness remains one of the most effective defences against Business Email Compromise.

The Warning Sign That Prevented This Incident
In this case, an employee noticed a subtle discrepancy.
The sender’s address looked legitimate at first glance, but the domain name differed slightly from the genuine organisation’s website and email domain. The fraudulent domain had been designed specifically to resemble the legitimate business and increase credibility.
That small detail triggered further scrutiny.
Instead of acting immediately, the recipient escalated the email internally. This simple action prevented the attack from progressing further and allowed an investigation to begin.
The incident is an excellent example of why cyber awareness training remains one of the most effective security controls available.
Technology plays an important role, but informed employees frequently become the last line of defence.
A Bigger Lesson: Sometimes the Breach Happens Elsewhere
One of the interesting findings from the investigation was that evidence suggested attackers had access to genuine business information that enabled them to craft a highly convincing email. The wider investigation indicated that information exposure may have originated from a compromised business environment elsewhere within the communication chain rather than from the organisation being impersonated.
This highlights an increasingly important reality:
Your organisation can become a victim even when your own systems have not been compromised.
Cybersecurity is now part of a broader supply chain challenge. Attackers frequently exploit weaker links within customer, supplier, partner, or third-party environments to gather intelligence before launching targeted attacks.
Five Practical Lessons Every Business Should Apply
1. Verify Every Request to Change Payment Details
Any request involving:
- Bank account changes
- Payment schedule updates
- New payment instructions
- Urgent invoice amendments
should be verified using a trusted communication channel.
A phone call to a known contact can prevent significant financial loss.
Never rely solely on information contained within the email itself.
2. Train Staff to Check Sender Domains Carefully
Many attacks rely on:
- Typographical variations
- Additional characters
- Hyphens
- Alternative top-level domains
Employees should be trained to inspect email addresses rather than relying only on display names.
A single character difference might be the only visible indicator of fraud.
3. Develop a Strong Reporting Culture
The most positive aspect of this incident was that the suspicious email was escalated quickly and appropriately.
Organisations should encourage employees to:
- Ask questions
- Report concerns
- Escalate suspicious messages
- Avoid fear of “raising a false alarm”
A false positive costs minutes.
A missed incident can cost thousands.
4. Prepare for Supply Chain Risk
Businesses should assume that cyber exposure can come from:
- Customers
- Suppliers
- Contractors
- Managed service providers
- Third-party software providers
Risk assessments should extend beyond internal systems and consider how trusted relationships could be abused by attackers.
5. Strengthen Email Security and Domain Monitoring
Organisations should review:
- Multi-factor authentication
- Email authentication controls
- Mailbox monitoring
- Suspicious forwarding rules
- Domain impersonation monitoring
- Lookalike domain detection
Attackers increasingly register domains that closely resemble legitimate brands. Early detection can reduce risk significantly.
Cybersecurity Is a Shared Responsibility
The most encouraging aspect of this incident was the collaborative response. Staff remained vigilant, the suspicious message was escalated quickly, investigations were coordinated across organisations, and corrective action was taken before any financial loss occurred.
This is what effective cyber resilience looks like.
No organisation can guarantee that attackers will never target them. Success is measured by how quickly suspicious activity is recognised, reported, investigated, and contained.
Cybersecurity is not just a technology challenge. It is a people, process, and awareness challenge.
When those elements work together, businesses become significantly harder targets.
Concerned about invoice fraud, phishing, or Business Email Compromise?
NexGen Cyber helps organisations strengthen email security, improve staff awareness, and build practical cyber resilience. Contact our team to assess your exposure to modern impersonation and payment diversion attacks before they become a costly incident.
FAQ:
What is Business Email Compromise (BEC)?
A cybercrime technique where attackers impersonate trusted contacts to manipulate employees into making payments, sharing information, or bypassing normal processes.
How can I spot a payment diversion scam?
Check sender domains carefully, verify any requests involving money, and confirm changes using a separate communication channel.
Can attackers use real invoice information?
Yes. Attackers often exploit previously exposed business information to make fraudulent emails appear genuine.
Does multi-factor authentication stop invoice fraud?
MFA helps protect accounts but should be combined with user awareness, payment verification procedures, and email security controls.