Phishing Case 2 – What happened

The following story came from a friend of mine, it is another example of what can happen when an email system is compromised. 

A business owner is regularly in contact with their accountant. There are invoices which need to be paid, are regularly passed between the two parties.  One day the accountant calls the business owner to check on an email they received which looked like a copy of another one. Both carried invoices. It was a sanity check. 

It turns out that the second copy of the email carried a modified invoice with a different account on it. So someone had infiltrated an email system somewhere between the two parties and was now trying to commit fraud by inserting their bank account into the transactions between the two parties. 

It was only through the vigilance of the accountant in this case was it spotted. 

How is it done?

Very often it is simply achieved by tricking someone to click on a link in an email which takes them to a seemingly official website and inviting them to log in. If they log in with their email address and password, that information is passed to a third party. Now the third party can get into the person’s account. It is quite possible that if they do this passively the person who has their email account compromised may be unaware of it. 

Change your passwords regularly.

 

Wingrove-Services
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

You can adjust all of your cookie settings by navigating the tabs on the left hand side.

My privacy policy can be located here: Wingrove Media Privacy Policy (opens in a new window)

My Cookies Policy can be found here: Wingrove Media Cookies Policy (opens in a new window)