Back to All Attacks
Attack Date: April 19, 2022
Employee Impersonation Payroll Diversion BEC Attack
This text-based BEC attack impersonates a non-executive employee using display name spoofing and a maliciously registered domain to divert payroll deposits to a fraudulent account.
Email Content
Subject
Direct Deposit Update
Body
Hi [Target First Name],
Quick one - I just switched my bank and would like to update my direct deposit details, would the change be effective for the next pay date, Kindly get back to me immediately you received my message so that i can provide you my new account ....
Regards,
[Employee Name]
[Employee Title & Company]