Why trusted conversations are targeted
Attackers may compromise a mailbox, imitate a supplier or register a lookalike domain, then wait for a real payment conversation. Messages can appear convincing because they use familiar names, signatures and timing.
Property, finance, legal and professional-service businesses are particularly exposed when staff regularly exchange invoices, settlement information or bank details.
Layer email and identity controls
Multi-factor authentication, secure administration, MailGuard or appropriate filtering, impersonation protection, DNS security and managed endpoint detection reduce different parts of the attack path. Domain email-authentication records also help receiving systems assess authorised senders.
- Protect every mailbox with MFA
- Review forwarding rules and suspicious sign-ins
- Restrict administrator access
- Train staff to report unusual messages quickly
- Keep devices and browsers supported and patched
Verify financial changes outside email
A request to change bank details should be verified using a known phone number or another trusted channel, not contact details supplied in the message. Approval limits and separation of duties add protection when one person is pressured or deceived.
ITSPLUS helps combine technical email protection with practical incident and verification processes.