External Third Party Impersonation Overdue Payment BEC Attack
Initial Email Content
Dear Manager Accounts,
EUROCONTROL HEREBY REMINDS YOU OF THE UNPAID INVOICES WHICH HAS BEEN SENT TO YOU. WE ADVISED THAT YOU EXPEDITE ACTIONS NOW TO SETTLE THE
BILLS AS EARLY AS POSSIBLE SO THAT WE CAN CLOSE THIS FILE .THE PAYMENTS ARE OVERDUE NOW AND HENCE ,IT IS IMPORTANT THAT YOU TAKE THE NECESSARY ACTIONS AS SOON AS POSSIBLE TO MAKE PAYMENTS.
WE ALSO HEREBY,INFORM YOU OF THE CHANGE IN OUR ACCOUNT DETAILS FOR ALL EUROCONTROL PAYMENTS AS THE CASE MAY BE, FOR SPECIFIC TRANSACTIONS AND
AS DIRECTED BY THE MANAGEMENT. YOU ARE ADVISED TO INFORM US ADEQUATELY BEFORE ANY PAYMENTS ARE MADE SO THAT WE CAN PROVIDE YOU WITH THE NEW
ACCOUNTS.
PLEASE YOU ARE ADVISED TO CONFIRM THIS FROM US IMMEDIATELY.THE DETAILS WILL BE FORWARDED TO YOU IN GOOD TIME AS SOON AS WE RECEIVE YOUR
ADVISE. PLEASE TAKE NOTE,WE DO NOT WANT ANY MIX-UPS AND MISUNDERSTANDING AGAIN.
KINDLY CONFIRM RECEIPT OF THIS NOTICE BY PROMPT RESPONSE
WE APPRECIATE YOUR UNDERSTANDING AND ALWAYS COUNT ON YOUR COOPERATION.
Best Regards,
[Impersonated Third Party Name]
Assistant to the Treasurer
DR/PFO - Treasury Section
EUROCONTROL 96 Rue de la Fusee
1130 Brussels,Belgium.
Malicious Artifacts
Additional Indicators of Compromise
Type
Description
Attack Description
This text-based BEC attack impersonates an external third party using display name spoofing, a free webmail account, overdue payment theme, and payment account update theme to request a fraudulent payment.