logo

The Security Tool That Delivered the $48,500 Invoice Fraud

ID: 3de14787-f945-59e4-b26f-20e2c15785e8

STIX ID: report--3de14787-f945-59e4-b26f-20e2c15785e8

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-05-03

Date Updated: 2026-05-03

Author: [email protected] (Audian Paxson)

...
...

A $48,500 payment-diversion BEC targeted a mid-size financial institution using a fabricated multi-turn email thread and a programmatically generated PDF invoice; the message transited a Votiro CDR relay that sanitized attachments but broke SPF/DKIM/DMARC alignment, causing DMARC failure while still delivering the message due to trusted relay behavior. The report includes IOCs (sender email and domain, relay IP/hostname, attachment hashes, bank routing/account details), maps to relevant MITRE techniques, and provides mailbox and CDR policy recommendations to prevent similar attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.