The NJCCIC observed a Business Email Compromise (BEC) campaign targeting accounts payable departments. The email body contains language indicative of attempts to steal personal or sensitive information, citing recent cybersecurity incidents and AI-assisted BEC to create a plausible, urgent pretext for requesting verification of banking and remittance details. The message instructs the recipient not to trust prior communications and claims it will not send its banking details via unsolicited mass email. Instead, it urges the victim to reply directly to initiate a controlled verification process, ensuring the target engages directly with the threat actor.

The threat actor also uses coercive language, threatening to place the recipient's account on Credit Hold and to suspend orders, and stating that the vendor will not be responsible for any loss of funds if payment details are not updated. It continues to cite cybersecurity incidents and payment fraud risks to pressure the recipient into promptly completing the verification process. A phone number is provided for the victim, serving as another means for the threat actor to exert pressure.
Recommendations
- Facilitate user awareness training to include these types of phishing-based techniques.
- Confirm requests from senders via contact information obtained from verified and official sources.
- Review the Don’t Take the Bait! Phishing and Other Social Engineering Attacks NJCCIC product for more information on common phishing and social engineering attacks.
- Review the Don’t Be Fooled: Ways to Prevent BEC Victimization NJCCIC Informational Report for additional information.
- If funds are unintentionally wired to a fraudulent account, immediately notify a supervisor, the banking institution, the FBI, and the US Secret Service to stop the wire transfer. Unless the fraudulent transaction is discovered quickly (typically within 48 hours), it can be difficult, if not impossible, to return the stolen funds.

