Back to All Attacks
Attack Details
Attack Date:
Apr 25, 2022

External Third Party Impersonation Overdue Payment BEC Attack

Initial Email Content

Subject
Re: Eurocontrol Unpaid Invoices!!!
Body

Dear Manager Accounts,

EUROCONTROL HEREBY REMINDS YOU OF THE UNPAID INVOICES WHICH HAS BEEN SENT TO YOU. WE ADVISED THAT YOU EXPEDITE ACTIONS NOW TO SETTLE THE
BILLS AS EARLY AS POSSIBLE SO THAT WE CAN CLOSE THIS FILE .THE PAYMENTS ARE OVERDUE NOW AND HENCE ,IT IS IMPORTANT THAT YOU TAKE THE NECESSARY ACTIONS AS SOON AS POSSIBLE TO MAKE PAYMENTS.

WE ALSO HEREBY,INFORM YOU OF THE CHANGE IN OUR ACCOUNT DETAILS FOR ALL EUROCONTROL PAYMENTS AS THE CASE MAY BE, FOR SPECIFIC TRANSACTIONS AND
AS DIRECTED BY THE MANAGEMENT. YOU ARE ADVISED TO INFORM US ADEQUATELY BEFORE ANY PAYMENTS ARE MADE SO THAT WE CAN PROVIDE YOU WITH THE NEW
ACCOUNTS.

PLEASE YOU ARE ADVISED TO CONFIRM THIS FROM US IMMEDIATELY.THE DETAILS WILL BE FORWARDED TO YOU IN GOOD TIME AS SOON AS WE RECEIVE YOUR
ADVISE. PLEASE TAKE NOTE,WE DO NOT WANT ANY MIX-UPS AND MISUNDERSTANDING AGAIN.

KINDLY CONFIRM RECEIPT OF THIS NOTICE BY PROMPT RESPONSE

WE APPRECIATE YOUR UNDERSTANDING AND ALWAYS COUNT ON YOUR COOPERATION.

Best Regards,


[Impersonated Third Party Name]
Assistant to the Treasurer
DR/PFO - Treasury Section
EUROCONTROL 96 Rue de la Fusee
1130 Brussels,Belgium.

Attack Screenshots

No items found.

Malicious Artifacts

Additional Indicators of Compromise

Type

Description

No items found.

Attack Description

This text-based BEC attack impersonates an external third party using display name spoofing, a free webmail account, overdue payment theme, and payment account update theme to request a fraudulent payment.

Analysis Overview

Tactic
Spoofed Display Name
Free Webmail Account
Goal
Payment Fraud
Impersonated Party
External Party - Other
Vector
Text-based
Theme
Overdue Payment
Language