logo

Past Due Invoice, Future Wire Fraud: How a BEC Campaign Passed Every Authentication Check

ID: 75eed9bf-59ab-5e51-be2d-e825f19ceb35

STIX ID: report--75eed9bf-59ab-5e51-be2d-e825f19ceb35

Feed Name: IRONSCALES

Threat Score
72/100

Date Published: 2026-04-16

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

A mid-size technology services firm was targeted by a Business Email Compromise (BEC) invoice diversion campaign that used display-name spoofing and SendGrid's authenticated infrastructure to deliver seemingly legitimate “Past due invoice.” messages. The attacker used a recently registered Reply-To domain and an attacker-controlled payment address to capture replies and redirect payments; VERP bounce tracking was used for recipient reconnaissance. Three mailboxes received the message, which IRONSCALES' behavioral detection quarantined before any payment occurred. The report includes IOCs (sender, reply-to, payment address, sending IP), MITRE mappings, and recommendations emphasizing behavioral detection beyond SPF/DKIM/DMARC.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.