Cybercrime Case Study
Case study: how a finance team caught an invoice-fraud attempt in time
26 Jul 2026 · English
The following is anonymised and does not identify any client or individual.
An attacker registered a domain one character different from a real supplier's domain, then emailed an organisation's accounts team requesting that future payments be sent to a new bank account.
The request used correct invoice numbers and formatting, suggesting the attacker had access to prior email threads, most likely from an earlier, separate compromise.
The payment was stopped because the finance team had a standing rule: any change of payment details is confirmed by phone, using a number already on file — not a number provided in the email.
That one control was the difference between a near-miss and a loss.