In partnership with

Stop Paying for 10 Tools. One AI Does It All.

Most e-commerce sellers are running their store across 6 to 10 separate tools — and spending more time managing software than growing their business. StoreClaw replaces your entire stack with one autonomous AI engine that monitors competitors, optimizes listings, automates marketing, and tracks real profit across Shopify, Amazon, and beyond.

It doesn't wait for you to ask. It runs 24/7 in the background, so you wake up to a full dashboard instead of a list of things you forgot to check.

Connect your store, and StoreClaw gets to work — no prompts, no complex setup, no six-app stack.

Free to start. No credit card required.

This issue kicks off a pillar we have not covered directly yet: small business security. Fitting topic to start with, because it is the one that drains bank accounts the most efficiently, and it does not need a single line of malware.

It is called business email compromise, and inside it, the version that hits small businesses hardest is invoice fraud: a vendor you already work with appears to email you new banking details. You update your records. You send the next payment. It goes to an attacker.

The FBI's own numbers call this the most financially destructive enterprise-targeted cybercrime category there is. Not ransomware. Not data theft. A convincing email and a bank account.

Real attack breakdown: the letter nobody caught

In January 2023, a workers union based in Massachusetts received an email that looked exactly like it always did. It appeared to come from their investment and consulting manager, from an address they had corresponded with before.

Here is the catch: that address had been changed by exactly one letter.

The email instructed the union to wire $6,400,000 to a different bank account than the one on file. They did. From there, the money moved fast: through several domestic bank accounts, attempted transfers to a cryptocurrency exchange, and wires to foreign accounts in Hong Kong, China, Singapore, and Nigeria.

Investigators eventually traced the money to seven domestic accounts and seized what was left. In March 2025, roughly $5,315,746 of the stolen funds was formally forfeited back through a federal court order. That recovery is a genuine success story. It is also two years, a multi-agency investigation, and about $1.1 million that never came back, all to correct one changed character in an email address.

Why this matters right now

This was not a rare, sophisticated attack. It is the default version of this crime.

The FBI's 2025 Internet Crime Report logged nearly 25,000 BEC complaints in the US for the year, totaling roughly $3.05 billion in reported losses, up about 10 percent from the year before. The average loss per incident is now around $123,000, and that figure has climbed sharply over the past several years. Over the past decade, BEC has cost more than $55 billion globally. It is, by dollar losses, the most financially destructive enterprise-targeted cybercrime category the FBI tracks, ahead of ransomware.

The mechanism behind most of it is almost boring: attackers study a vendor's or a company's normal invoicing rhythm, then send a payment change request that looks exactly like every other email in that relationship, timed to land right when a payment is due.

Here is something worth noticing if you have been reading this newsletter for a while: this is the third issue in a row that lands on the same fix, from three different directions. Device code phishing (issue 002) was defeated by not finishing a login you did not start. A help desk breach (issue 005) was defeated by verifying identity through a channel the caller does not control. Invoice fraud is defeated by verifying a banking change through a channel the email does not control.

Practical fixes you can apply this week

For small business owners

1. Verify any banking or payment change by phone, using a number you already have. Not the number in the email. Not a number the email provides "to make it easy." Your own records, or a call to a contact you already trust.

2. Read the sender address, not just the sender name. Email clients show a display name by default, which is exactly what an attacker controls. Tap or hover to see the actual address, and read it character by character on anything involving money.

3. Slow down on urgency, especially near a normal payment date. Attackers time these requests to arrive right when a real payment would be expected. That timing is not a coincidence, it is reconnaissance.

For admins and finance processes

4. Require a second approval for any vendor bank detail change. One person updating payment records based on an email alone is the entire vulnerability. A second person confirming it, out of band, closes it.

5. Keep a verified contact list separate from your inbox. If your only record of a vendor's phone number is in the same inbox an attacker could compromise, that list is not actually independent verification.

6. Report it fast if it happens. Recovery in the Massachusetts case worked because it was investigated quickly enough to trace and freeze accounts. Speed matters more than almost anything else once money has moved.

This Week in "Please Don't Do That"

Someone, somewhere, is about to update a vendor's banking details because the email had the right logo, the right signature, and said "please update our new account before the next payment."

Please do not let a correct logo do your verification for you. A logo is an image file. It does not prove anything about who sent the email.

If a payment detail changes, pick up the phone and call a number you already had before this email arrived.

Tool worth knowing: dnstwister.report

Remember the one-letter domain from this issue's story? This is the free tool built to catch exactly that.

dnstwister.report is a free, browser-based tool built on the open-source dnstwist project. Type in a domain, your own or a vendor's, and it generates the likely lookalike variations attackers would register: swapped letters, added characters, look-alike substitutions, then checks which of those variations are actually registered right now.

Use it two ways: check your own domain occasionally to see what lookalikes exist that someone could use to impersonate you, and check a vendor's domain before wiring money to a "new" account if anything about the request feels off.

Checklist tie-in

This is the third issue that ends here, and that is the point. The "financial requests are verified out-of-band with a phone call before any wire transfer or banking change" item in the SecureByDefault 25-Point Security Checklist is not a random line item. It is the single habit that would have stopped device code phishing, the help desk breach, and the $6.4 million email in this issue.

One question for you

Does your business have an actual person whose job it is to verify banking changes by phone, or is it "whoever gets the email handles it"?

Hit reply and tell me honestly. If the answer is the second one, that is worth fixing this week. I read every one.

Talk soon,
Ron
Cloud and Cybersecurity Engineer, SecureByDefault

Sources

U.S. Department of Justice and U.S. Secret Service press releases on the Massachusetts workers union business email compromise case (forfeiture announced March 2025) · FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report · FBI IC3 PSA230324, "Business Email Compromise Tactics Used to Facilitate the Acquisition of Commodities and Defrauding Vendors" · dnstwister.report / the open-source dnstwist project · SecureByDefault 25-Point Security Checklist

Reply

Avatar

or to participate

Recommended for you

View all
caret-right