Lakhs Lost in Business Email Scam After .com Changed to .cam
An engineering firm lost ₹10.45 lakh after cybercriminals altered a supplier’s domain to redirect payments, leading to a business email compromise (BEC) scam.
The Incident
An engineering firm based in Pune’s Kalepadal area lost ₹10.45 lakh following a business email compromise (BEC) scheme. Cybercriminals altered a supplier’s domain from .com to .cam, redirecting payments to a Dubai-based account. The victim organization, which produces polymer products, sourced raw materials from a Chinese supplier and conducted routine transactions via email.
How the Scam Worked
Attackers created a spoofed email address by modifying the domain from .com to .cam, mimicking the supplier’s legitimate contact. The subtle change went undetected by the company’s accounts department. The scam unfolded when fraudsters claimed the supplier’s primary bank account was under audit and directed the company to transfer payment for a recent order to an alternative Dubai account.
The Scam Execution
The email replicated the structure, language, and formatting of previous communications, convincing a 25-year-old accounts executive to process the transaction without verification. The fraudulent payment was made to a Dubai account, which the Chinese supplier later denied requesting, exposing the deception.
Discovery of the Deception
Several weeks later, the Chinese supplier contacted the Pune-based firm to inquire about a delayed payment. Upon learning the funds had been sent to a Dubai account, the supplier denied any request for a banking detail change, revealing the scam.
Expert Insights
According to a researcher at Algoritha Security, BEC attacks exploit human error by altering contact details or domains to manipulate financial transactions. These schemes often succeed due to insufficient verification protocols.
Cybersecurity Advice
Cybersecurity experts emphasize that confirming any request for payment modifications through independent channels is critical. Organizations are advised to implement multi-factor authentication, deploy advanced threat detection tools, and conduct regular employee training to mitigate risks. Additionally, verifying all banking instruction changes via direct communication with suppliers is essential.
Legal Measures
Law enforcement is analyzing digital evidence, banking records, and technical data to identify the perpetrators. Further legal measures will follow based on the investigation’s findings.
Conclusion
The incident highlights the vulnerability of businesses to BEC scams, emphasizing the need for robust verification processes and employee awareness. Cybercriminals exploit subtle domain changes and human trust to execute financial fraud, underscoring the importance of proactive cybersecurity measures.
