Cyberlium

Cybersecurity › Module 7 › Lesson 3

BeginnerModule 7Lesson 3/6

Email Links & Attachments — Red Flags

Catch BEC, invoice fraud, and payment-change tricks

15 min+23 XP3 quiz
Module progress3 of 6

Opening

The most expensive email may look perfectly boring

Not every scam screams "URGENT PRIZE." Business Email Compromise (BEC) and invoice fraud succeed because they look like ordinary work: a vendor updated banking details, a boss asks for a quiet gift-card purchase, a client wants the wire sent to a "new" account before Friday. This lesson goes deeper than "don't click links." You will learn domain lookalikes, reply-to tricks, and a second-channel verification rule that protects money moves.

1. What BEC and invoice fraud actually exploit

Attackers study how money already moves in your life or workplace: who sends invoices, which email threads look normal, and when deadlines create pressure. They then insert a believable payment-change instruction into that flow. The malware payload is optional — the goal is a human-approved transfer to an account the criminal controls. You do not need to work in a Fortune 500 finance team to be a target. Freelancers, students paying rent to a "landlord," families settling shared bills, and small shops paying suppliers all follow the same fragile pattern: trust the last email in the thread.

2. Mechanisms: lookalikes, reply-to, and thread hijacks

Domain lookalikes: display name says "Aisha — Acme Supplies," but the real address is [email protected] or acrne.com (r/n swap) instead of acme.com. Humans read the friendly name; mail clients show the truth only if you expand the header. Reply-to tricks: the visible From may be spoofed or close enough, while Reply-To silently routes your answer to an attacker inbox. You think you are continuing with your vendor; you are coaching the thief. Compromised real mailboxes: sometimes the vendor's mailbox is already taken over. The domain is correct, the thread history is real, and only the payment details changed. That is why "the email looks authentic" is not enough — money-change instructions need a second channel using a phone number you already trust from before the request.

Money-move verification rules:

  • Out-of-band confirm

    Any new bank account, UPI/wallet ID, wire instructions, or gift-card request gets a voice/video call to a known number — not the number inside the suspicious email.

  • Expand the real address

    Tap/click the sender to reveal the full mailbox and domain before you trust tone or logos.

  • Slow the deadline

    Artificial "pay in 30 minutes or contract dies" pressure is a feature of fraud, not of healthy vendors.

3. Wrong vs right: "updated banking details"

Worked failure — same invoice email thread:

  • Wrong

    An email in an existing vendor thread says "Our account was audited — pay this new IBAN only." You reply "Got it," update payroll, and send funds. Days later the real vendor asks why invoice #4412 is unpaid.

  • Right

    You freeze the payment change. You call the vendor using the phone number saved in your contacts/contract from last quarter — not any number in the email. They confirm no change. You report the message and keep paying the old verified account.

4. Practical: payment-change verification protocol

BEC / invoice fraud — second-channel checklist

# BEFORE changing ANY payment destination
TRIGGER = new bank account / wallet ID / wire path / "buy gift cards" / "keep this quiet"

1) STOP — do not update accounting systems yet
2) EXPAND sender:
   - Full email address (not display name)
   - Domain spelling vs known vendor domain
   - Reply-To header if visible (desktop: show original / headers)
3) COMPARE:
   - Does urgency + secrecy appear together?
   - Did banking details change without a prior expected notice?
4) VERIFY OUT-OF-BAND:
   - Call/video using a number from your OLD contract, official website you typed, or prior invoices
   - Do NOT call numbers provided only inside the suspect message
   - Ask a challenge only the real party knows (invoice #, last payment date)
5) DOCUMENT:
   - Who confirmed, date/time, and what details were approved
6) ONLY THEN update payment records

# PERSONAL / FAMILY VERSION
Rent, tuition, shared bills, "boss needs gift cards":
Same rule — voice-confirm with a known contact path before sending money.

# IF YOU ALREADY SENT FUNDS
1) Contact your bank/payment app fraud team immediately
2) Notify the real vendor/payee
3) Preserve the email headers/raw message for investigators
4) Rotate passwords on any mailbox that might be involved

# ETHICAL PRACTICE
Use only your own mail and sample headers from accounts you own.

Mission: install a money-change rule

1) Write your rule: "No payment detail changes without a call to a known number." 2) Save official phone numbers for your landlord/vendor/payroll contact in your phone book now. 3) On desktop or mobile, practice expanding a real sender address on 3 recent emails (no clicking shady links). 4) If you handle invoices, add a calendar reminder to re-verify any banking change requests this month.

Stuck? Ask Cyberlium AI Mentor

Ask: "Hint only: if a vendor email looks real but changes wire details, why is calling a number from the email unsafe — and what number should I use instead?" Do not paste real IBAN/account numbers into Mentor.

Boring emails can move real money — your second channel stops that. Next — Safe Online Banking & Shopping — harden the apps and checkout paths where those payments actually clear.

Knowledge Check

1

APPLY: You receive an email in an ongoing supplier thread: "New account on file — divert this week's wire." The logo and tone match. What is the strongest next step?

Multiple choice

Knowledge Check

2

APPLY: Display name shows your CEO. The address is [email protected] and the message asks for gift cards "quietly before the offsite." Best response?

Multiple choice

Knowledge Check

3

APPLY: Why can calling the phone number printed inside a suspicious "vendor update" email still fail as verification?

Multiple choice

← Previous

Answer all 3 knowledge checks to continue. (0/3 answered)