Business Email Compromise Attack Hijacks Session Token to Steal Vendor Payments

BEC cyberattack

Cybersecurity firm TrendAI uncovered a business email compromise (BEC) scheme in which an attacker tricked a victim into clicking on a link and was then able to reroute payments that were sent by the victim’s company and intended for its vendors, it said in a Aug. 14 blog post.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    yesSubscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    In this attack, the adversary targeted a finance user with a spear-phishing email, used an Adversary-in-the-Middle phishing page to bypass multifactor authentication, and hijacked the victim’s live Microsoft 365 session token, according to the post.

    The spear-phishing email included the target’s name, job title and organization, said it concerned “PTO Request Denied” and called on the target to click a button labeled “View Conflicting PTO Dates,” the post said.

    Having hijacked the victim’s live Microsoft 365 session token, the adversary then used three malicious inbox rules to auto-archive and mark as read incoming vendor and internal collection emails to conceal the fraud from the victim for 30 days while the attacker impersonated vendors and rerouted the company’s payments to bank accounts controlled by the attacker, per the post.

    “The BEC campaign is another illustration of where the enterprise perimeter really sits today: trust and identity,” TrendAI said in the post. “By stealing a single authenticated session, the minds behind this campaign gained everything they needed to impersonate a finance user and redirect real money.”

    PYMNTS reported in December 2024 that business email compromise attacks have evolved with a level of sophistication that is reshaping how companies must defend themselves.

    While traditional BEC schemes often relied on impersonating high-ranking executives or key suppliers, the modern iteration is far more nuanced and multilayered, as phishing attempts get a shot in the arm from the democratization of artificial intelligence.

    The PYMNTS Intelligence report “Winning the Fraud Fight: How AP Automation Can Deflect Rising Security Threats” found that 83% of U.S. companies had been targeted by highly sophisticated cyberfraud and that business email compromise schemes comprised the lion’s share of those attacks.

    “Acting now is critical to prevent future losses as fraudsters continue to develop new tactics,” the report said. “Companies that adopt comprehensive fraud prevention strategies today will be better positioned to protect their assets and ensure long-term security.”