Back to All Attacks
Attack Details
Attack Date:
Apr 27, 2022

Vendor Impersonation Overdue Payment BEC Attack

Initial Email Content

Subject
[Impersonated Vendor]: Due Invoices
Body

Hello,

We are pleased to send a friendly reminder to your accounting department regarding the due invoices and outstanding payment.

It would be much appreciated if you could let us know and advise when payment will be processed so that we can update you with our new bank details for remittance all payment as our main account is presently being reviewed due to some inconclusive L/C issue so therefore, all account activities including incoming and outgoing funds can no longer be verified at the moment.

Please, we request that you should attach us all invoices according to what your records show to revise with the correct payment instructions. We will appreciate it if all concerned people treat this as urgent.

Regards,


[Impersonated Vendor Employee Name]
Sales Director

Home
[Impersonated Vendor Company Name]
[Impersonated Vendor Address]

Attack Screenshots

No items found.

Malicious Artifacts

Additional Indicators of Compromise

Type

Description

No items found.

Attack Description

This text-based BEC attack impersonates a vendor/supplier using display name spoofing, a maliciously registered domain, an overdue payment theme, and a payment account update theme to request a fraudulent payment.

Analysis Overview

Type
Tactic
Spoofed Display Name
Maliciously Registered Domain
Goal
Payment Fraud
Impersonated Party
External Party - Vendor/Supplier
Vector
Text-based
Theme
Overdue Payment
Language