A story we hear too often
The Monday a plumbing company’s invoices went out with someone else’s bank details
the owner of a 22-truck plumbing and HVAC company
Ray started with one van in Berwyn. Twenty-two trucks later, the office runs on a field-service app, a bookkeeper named Teresa and a customer list of 9,000 homes with every water heater and furnace they have ever installed.
Monday at 7:30, a customer calls to say the invoice she got Friday night had new ‘updated payment instructions’ and she paid it. Teresa did not send that invoice. Someone has been inside the office mailbox for eleven days, reading, waiting, and then sending 140 invoices with a different account number from the real address.
In the version that goes badly, customers pay for a week before anyone notices, the money is unrecoverable, Ray refunds the ones who paid twice to keep his reputation, and the customer list, with addresses and equipment details, is sold to a burglary crew.
In Ray’s version, the login from another country tripped the watch on day one. The engineer cut the session, reset the mailbox and found the forwarding rule the attacker had planted. The 140 invoices never went out. Teresa spends Monday sending the real ones.
Someone has been inside the office mailbox for eleven days, reading, waiting, and then sending 140 invoices with a different account number from the real address.
What changes the ending
- MFA on the office mailbox and the invoicing app, with forwarding rules watched (CIS Controls 5 and 9)
- Login monitoring that flags a session from a country your business has never been in (CIS Control 13, Network Monitoring and Defense)
- A rule, taught to customers, that payment details never change by email (CIS Control 14, Security Awareness and Skills Training)