Huntress shares a real incident where a vendor's email account was compromised and attackers attempted a $103,000 business email compromise (BEC) scam. A threat actor hijacked the vendor contact's email, fabricated bank account change requests, and even continued sending emails after the account was supposedly shut down. The scam was foiled because Huntress had a standing procedure to call vendors directly to confirm any new bank details — a call that revealed the vendor had sent no such emails. The post highlights how security awareness training and procedural safeguards, not technical tools, stopped the fraud, and recommends out-of-band verification for any sensitive financial requests.
1 Impression