How a normal Tuesday becomes a six-figure loss
The timeline on this page is a composite of how business email compromise typically unfolds. Nothing in it would trip a traditional spam filter, because nothing in it is technically malicious.
Every step relies on a busy person doing their job. That is exactly why it works, and why the defense has to understand context rather than just scan attachments.
Illustrative scenario, not a specific customer
- Monday, 16:10
A lookalike domain goes live
The attacker registers a domain one character away from a real supplier's and studies public details about your accounts team.
- Tuesday, 09:14
The email arrives
"Our bank has changed, please use the new account for invoice 4471." Correct invoice number, correct supplier name, a familiar signature.
- 09:22
It is read between meetings
Nothing looks wrong on a phone screen. The sender name matches the contact card, and the tone is routine.
- 09:31
Pressure is applied
A follow-up says the payment is overdue and asks for email-only contact. The phone call that would expose the fraud never happens.
- 09:54
The payment is released
Funds move to an account the attacker controls. By the time the real supplier chases the invoice, the money has left the destination bank.