Back to All Attacks
Attack Date: June 29, 2022
Vendor Impersonated with Hijacked Email Thread to Steal Payments
Attackers impersonate a vendor using a hijacked email thread and a lookalike domain to request payment for a fraudulent invoice worth nearly $10,000.
Email Content
Subject
RE: FW: [Hijacked Thread Subject]
Body
Good Morning,
I am circling back around with you regarding the final payment breakdown for the claim payment(s) that have been issued.
We are currently sitting at an amount owed of $ 9874.18 to pay this account in full. Please provide a response ASAP or we will be forced to place a lien on the insured’s property.
[Vendor Employee Name]
A/R Manager
---
[Hijacked Thread Content]