The article describes a real business email compromise (BEC) attempt against a small community sports club, where an attacker impersonated a superior and requested an urgent payment. It explains how attackers can use AI to automate the research and message-writing steps, making it easier to target many smaller victims. It also highlights practical disruption points: email controls, AI-provider detection, and stricter payment verification processes.
Key findings
- A real BEC attempt targeted a small community sports club and was detected because the email’s tone seemed wrong.
- The article argues AI can automate time-consuming preparation (finding targets, spoofed identities, and plausible lures), making smaller victims more profitable to target at scale.
- Defenders can disrupt different points in the workflow, especially delivery via email controls (rate-limiting, reputation blocks) and payment processes (verification, delays).
- The author suggests “canary organizations” (honeypot entities) to catch and block sources attempting BEC at scale.
Who’s being targeted
- Commonly targeted roles: Finance, Accounts Payable, Treasurers, Executive Assistants, Leadership.
- Affected industries: Arts, Entertainment, and Recreation, Nonprofits and community organizations, Small businesses.
- Attack channels: email.
- Impersonated: A superior in the same organization.
Awareness takeaways
- Treat urgent payment requests, especially those claiming to come from leadership, as high-risk and verify via a known, separate channel.
- Assume smaller organizations are targets too; scale makes “lower value fraud against many targets” profitable.
- Build process controls that slow down or block fraudulent payments (purchase orders, verification, and delays).
- Use email-service controls (monitoring for anomalous behavior and high-volume sending) to stop BEC delivery before it reaches users.
Red flags to watch for
- Unusual urgency around making a payment
- Message tone/wording doesn’t match the supposed sender
- Payment request bypasses normal approval steps (e.g., purchase order)
Read the video transcript
“Hi, can you make an urgent payment today? Please treat this as a priority.” That hit a tiny community sports club’s inbox. This wasn’t a one-off. With AI, someone can scrape small clubs, charities, and teams, clone leaders’ writing style, and blast out these boss-impersonation payment emails at scale. In the real case, the treasurer caught it because the tone felt off and it skipped normal steps, no purchase order, just hurry up and pay this new bank account. Your move: any urgent payment request from a “boss” in email is high-risk, pause, and confirm it using a known channel, like calling their usual number before you pay.