Skip to main content
ITSIGNSolutions
Confidential client

Stopping a six-figure wire after a lookalike invoice

Accounts payable received a familiar invoice from a long-standing vendor — on a domain one character off. The callback rule we had just written caught it before the wire left the trust account.

Professional ServicesCloud and Microsoft 365

$186k

Payment stopped

100%

Mailboxes with MFA

0

Later attempts that reached a wire

The challenge

A 40-person firm had already paid two smaller invoices to a lookalike domain the previous quarter. The third request was $186,000, timed for a Friday afternoon when the partner who usually approved payments was in court. Shared mailboxes for billing had no MFA. There was no written rule for changing bank details.

What we did

We enrolled every mailbox that could move or approve money in phishing-resistant MFA, converted the shared billing addresses so they could no longer be signed into, and wrote a callback rule: no new bank detail without a voice call on a number already on file. Finance ran one tabletop on a real lookalike. DMARC was moved from monitor to reject once the legitimate senders were listed.

The outcome

The $186,000 payment was stopped on the callback. The lookalike domain was reported. The following quarter, two further attempts were forwarded to us in under ten minutes and never reached a wire.

Let's talk about what you are running

A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.