The R600,000 email

The Big Issue, a South African nonprofit, lost R600,000 to an email. Nothing was hacked in the way the word suggests. Attackers studied legitimate email correspondence, imitated it well, and supplied changed banking details at the moment an invoice was due. The payment went where the email said, and the email lied. The scheme has a name, business email compromise, and it takes more money from organisations than almost any other kind of cybercrime.

Why it works

Business email compromise succeeds because it attacks trust rather than technology. The message arrives inside a real conversation, or inside a convincing imitation of one, from a sender the recipient deals with routinely. It asks for something ordinary, since paying an invoice and updating banking details are both things finance teams do every day. There is no malware to detect and no login to steal, only a well-timed lie in a familiar voice, which is why technically sound organisations fall for it as readily as careless ones.

What actually stops it

The defence is a small set of habits enforced without exception, backed by basic technical controls.

  • Verify every change of banking details out of band, by phoning a number you already had rather than one the email provides. This single habit would have stopped the loss above, and it stops most of this class of crime.
  • Put two-factor authentication on every mailbox, because a compromised mailbox turns imitation into impersonation and makes the lie nearly undetectable.
  • Train the people who move money to recognise the pattern: unexpected urgency, changed details, and pressure to keep the matter quiet are each a reason to slow down, and together they are a reason to stop.
  • Make the safe path the easy path, since a verification habit that requires heroics will be skipped on the busiest day, which is exactly the day the email arrives.

The uncomfortable lesson

Email security spend usually flows toward filters and gateways, which matter and which this crime is designed to walk straight past. A fraudulent instruction in a legitimate-looking thread reaches a human, and only a human procedure stands between it and the bank. The R600,000 lesson is that the procedure has to exist before the email arrives, because no one invents it under deadline pressure with a convincing sender waiting on payment.

Would your finance team catch the email? Tell us what’s on fire