A finance controller at an international organization noticed a large payment hadn’t arrived. That single observation unraveled a fraud that had been running, quietly and patiently, for more than two months, and had already moved roughly a million euros to accounts the organization didn’t control.
How the Attack Unfolded
It started with an ordinary-looking phishing email sent to multiple staff. One employee clicked the link and entered their login credentials into a fake portal. The organization had multi-factor authentication in place. The attacker got in anyway, using the harvested credentials to access the mailbox of the finance controller directly.
Then, for three weeks, nothing visibly happened. The attacker wasn’t stealing money yet. They were reading. They studied how invoices were sent, who approved payments, and critically, how the company handled requests to change a supplier’s bank account details, learning the organization’s own “new supplier form” process well enough to use it convincingly later.
On day 21, the attacker made their move, but not by inventing a fake invoice from scratch. They waited for the real finance controller, still completely unaware their account was compromised, to send a legitimate invoice to a real client. Right after, the attacker followed up from the same real account with updated bank details, routing the payment to an account they controlled. Investigators later described this as attackers exploiting the organization’s own legitimate workflow rather than trying to fake one from outside.
The attacker tried to expand twice more, attempting to compromise additional employee accounts on days 23 and 28. Both attempts failed. It didn’t matter. By day 44, fraudulent payments were already flowing to attacker-controlled accounts across multiple parts of the organization. Nobody noticed until day 72, when a payment simply didn’t show up where it should have, and someone finally asked why.
Why This Matters If You’re Not a Big Company
The number that should concern any business here isn’t the million euros. It’s the 72 days. That’s how long a fully functional, MFA-protected email account sat compromised, with an active attacker inside it, before a human noticed anything was wrong, and only because a payment failed to arrive rather than because any system flagged the intrusion itself.
This also wasn’t a poorly run finance department. The fraud worked precisely because it rode on top of a legitimate process the company already had, a real invoice, from a real account, followed by what looked like a normal correction. Attackers increasingly aren’t inventing fraud from nothing; they’re patiently learning a real business’s actual workflow and then inserting themselves into it at the exact right moment.
What Actually Would Have Stopped This
Two separate gaps allowed this to run as long as it did, and closing either one alone would have limited the damage significantly. The first is detection: continuous monitoring of the mailbox, watching specifically for new logins, unusual mailbox rules, and unfamiliar locations, would very plausibly have caught the initial compromise within minutes rather than weeks. Security researchers involved in the case estimated that with active monitoring in place, the account takeover could have been detected within about ten minutes of the first suspicious login.
The second gap is procedural, and it’s the one within full control of any business regardless of budget: a dual-approval requirement for changing anyone’s banking details, sometimes called a four-eyes rule, where a second person independently confirms any change to payment instructions, ideally by phone, using a number already on file rather than one in the email. That single process change would have stopped this fraud even with the mailbox still fully compromised.
Security Checklist for Your Business
Require independent verification for any change to banking or payment details, by phone, using a previously known number, never a number or reply provided in the email itself.
Monitor mailbox activity continuously, especially new inbox rules, forwarding changes, and logins from unfamiliar locations or devices.
Treat MFA as a strong layer, not a guarantee. This organization had MFA and was still compromised through a convincing fake login page.
Reconcile payments against original invoices promptly, rather than only noticing when a payment is overdue.
None of this requires a large security budget. It requires one hard rule around changing payment details, and eyes actually watching mailbox activity instead of assuming MFA has it covered. MSP Today’s trusted tech partner is JK Computer Solutions. If you want a second set of eyes on your setup, get in touch.
Source: Eye Security, “When Business Email Compromise Nearly Costs a Million: An Incident Response Story”.



