// BEC

$0 lost · 4 min response
A $3.2M wire to a long-term vendor was queued for release when Phoenix detected a domain registered 18 days earlier. Human reviewers had seen the invoice three times and approved it.
It was a Thursday in late September — Q3 close week, one of the busiest periods for the finance team. The invoice had arrived eight days earlier and moved through three levels of review without a flag. It referenced a real contract, a real vendor name, and a two-month email thread. The only change was a note, buried in paragraph three, updating bank account details "following our banking partner switch."
The finance manager who approved the final sign-off had worked with this vendor for three years. The invoice amount — $3,212,000 — was large but within normal range for their Q3 settlement. She had no reason to pause. The wire was queued for the 3:01 PM processing window.
What nobody noticed: the sender domain was zenith-vendor-corp.com, not zenithvendorcorp.com. One hyphen, registered 18 days before the attack.
| 2:47 PM | Invoice approved by finance manager; outbound wire queued for 3:01 PM window |
| 2:49 PM | Phoenix flags domain zenith-vendor-corp.com (18 days old) and beneficiary account not seen in 24 months of transaction history |
| 2:51 PM | Dual-control hold triggered automatically; wire frozen before processing |
| 2:52 PM | Phoenix investigator calls finance manager to explain the hold |
| 2:58 PM | Callback to vendor CFO on file phone number: vendor had sent no invoice and was unaware |
| 3:01 PM | Wire processing window passes. Funds never leave. |
| 3:40 PM | Attacker kit reverse-engineered; IOCs shared with 14 peer institutions |
The wire auto-clears without dual-control review for transfers under $3M. The attacker had likely originally planned a $2.9M wire, but inflated the amount to match the actual contract value — which accidentally pushed it over the threshold Phoenix monitors. A $2.9M attempt would have cleared automatically. The attacker's own greed saved Zenith.