Skip to content
BreachPathAttack Path LibraryStart
FoundationalPayment / invoice fraud

Business email compromise to invoice fraud

A compromised finance or executive mailbox is used to study payment processes, establish stealthy persistence, and redirect a legitimate payment to an attacker-controlled account.

Technologies
Microsoft 365, Google Workspace
Entry points
Phishing, Stolen credentials
Sectors
Professional services, Legal, Manufacturingโ€ฆ
Stages
3
01

A finance or executive mailbox is compromised

Through phishing or reused credentials, the attacker gains access to a mailbox belonging to finance staff or an executive whose instructions carry weight in the payment process.

Attacker objective

Gain access to a mailbox involved in, or able to authorise, payments.

Controls that should stop this
  • Phishing-resistant MFA on all mailboxes
  • Conditional Access restricting risky sign-ins
  • User reporting and fast triage of phishing lures
What defenders should see
  • Sign-ins from unusual locations or impossible travel
  • Risky sign-in alerts from identity protection
  • Mail access from unfamiliar clients or IPs
What a pentest validates
  • Social-engineering assessment of finance and executive staff
  • Test MFA strength and Conditional Access coverage
  • Review sign-in monitoring and response
Business impact

The attacker can now read sensitive payment correspondence as a trusted insider.

02

Payment processes are studied and quiet persistence is set

The attacker reads correspondence to understand suppliers, approval chains and timing, and sets inbox rules that hide or divert messages so their interference goes unnoticed.

Attacker objective

Learn how payments are approved and stay hidden while waiting for the right moment.

Controls that should stop this
  • Alerting on inbox-rule creation, especially delete/forward rules
  • Out-of-band verification for payment changes, independent of email
  • Separation of duties in payment approval
What defenders should see
  • New mailbox rules that hide, move or forward messages
  • Access to historical finance correspondence in bulk
  • External forwarding configuration changes
What a pentest validates
  • Test whether inbox-rule creation is detected and alerted
  • Validate out-of-band verification for bank-detail changes
  • Review separation of duties in the payment workflow
Business impact

The attacker understands the payment process and can operate unseen within it.

03

A payment is redirected to the attacker

At an opportune moment โ€” often around a real invoice โ€” the attacker inserts altered bank details or a convincing payment instruction, using the trusted mailbox so the request appears genuine.

Attacker objective

Cause a legitimate payment to be sent to an attacker-controlled account.

MITRE ATT&CK
Controls that should stop this
  • Mandatory call-back verification to a known number for any bank-detail change
  • Dual authorisation for new or changed payees
  • Finance-team awareness of BEC patterns and pressure tactics
What defenders should see
  • Payment-detail change requests correlated with mailbox anomalies
  • Emails from look-alike external domains in the payment thread
  • Unusual urgency or out-of-process instructions
What a pentest validates
  • Tabletop or controlled social-engineering test of the payment-change process
  • Validate call-back and dual-authorisation controls actually trigger
  • Review whether finance staff can be pressured out of process
Business impact

Funds are sent to the attacker โ€” a direct, often unrecoverable financial loss.

ATT&CK techniques in this chain

If this chain completes

Direct financial loss from a redirected payment, plus erosion of trust with the counterparty whose invoice was impersonated โ€” one of the most common and costly attacks against organisations of any size.

Should you test this against your environment?

Turn this chain into a scoped red-team brief โ€” objective, systems and identities in scope, testing assumptions and the questions to answer before commissioning.