IntelliOS Threat Intel Operating System
IntelliOSRolling Intelligence|AIRolling BEC & Fraud Watch

Business Email Compromise Rolling Intelligence Card

AI-generated, AI-updated weekly, AI quality-checked, and source-cited, this rolling 90-day BEC Rolling Intelligence Card reconciles provider telemetry, incident-response findings, campaign research, phishing infrastructure, and claims data. It explains which identities and payment workflows attackers exploit, how ordinary MFA can be bypassed, what losses look like, and which finance, identity, and response controls prevent an unrecoverable transfer.

Coverage
Apr 30–Jul 28, 2026
Record Version
v13
Updated
Jul 28, 2026
AI Monitor
Weekly · Tue midday ET
Evidence
16 Retained Sources
Product
Rolling Intelligence Card
Classification
TLP:CLEAR

Research Framing

Reporting-Period Statistics

Rolling 90-Day Intelligence Snapshot

At-a-glance measures from the retained evidence set. Citations identify the source controlling each statistic.

Period Coverage

Apr 30, 2026Jul 28, 2026

90 calendar days, inclusive. Records are included by their first-observed date inside this window; the period does not imply that every underlying incident began or was confirmed during it.

90-day windowWeekly on Tuesday at midday ET

~9M[7]

April BEC spike

Microsoft detections; +121% from March, then returned toward baselineEvidence dated Jul 23, 2026

67K+[7]

Automated campaign reach

Users across 42K+ organizations in under three hoursEvidence dated Jul 23, 2026

79%[11]

Operational finance language

Cofense-observed Q1 2026 finance-phishing subject-line patterns; not BEC compromise or lossEvidence dated Jul 15, 2026

$71,295[1]

Average June wire request

Attempted/requested amount in Fortra engagements—not confirmed financial lossEvidence dated Jul 8, 2026

$4.856M[8]

Case-level recovered funds

Dickinson Public Schools BEC funds seized in one DOJ/FBI-linked case; not an aggregate recovery rateEvidence dated Apr 30, 2026

Not published[6][8][9]

Current-window aggregate actual / claimed loss

No retained source reports an Apr 30–Jul 28 aggregate. DOJ/FBI-linked cases provide case-level amounts; Verizon’s in-window study covers 2019–2024 claims.First cited source Apr 30, 2026 · Latest cited source Jun 25, 2026

Evidence-Prioritized Access Paths

Top Initial Access & Account-Takeover Vectors

Evidence-prioritized, not a synthetic prevalence ranking: the retained sources use different datasets and collection methods. Beazley is the only retained source that explicitly identifies a leading vector. OAuth device-code phishing is a separate user-authorization path—not AiTM reverse-proxy token theft. It remains monitored in the connected Kali365 product, but the current Microsoft device-code publication predates this card’s Apr 30 cutoff and is therefore not counted as an in-window vector.

1

Trusted-account compromise

Compromised third-party vendor mailbox[3]Evidence dated May 12, 2026

Leading vector in Beazley’s Q1 response cases

How it starts
An attacker gains control of a real supplier or service-provider mailbox, studies an existing relationship, and sends a request from the legitimate account or thread.
Attacker outcome
Invoice or bank-detail diversion that inherits the vendor’s real domain, signature, history, and business context.
What to monitor
Vendor payment changes; unusual reply-to or sending patterns; new inbox rules; anomalous vendor sign-ins; requests that resist callback to a known number.
2

Look-alike identity

Typosquatted vendor domain and credential lure[3]Evidence dated May 12, 2026

Recurring vendor-impersonation path

How it starts
A near-match domain impersonates a known vendor and delivers a malicious attachment, credential-harvest page, or altered payment instruction.
Attacker outcome
Credential theft, account takeover, or direct payment diversion without first compromising the real vendor.
What to monitor
Newly registered look-alike domains; character substitutions; reply-to mismatch; altered remittance details; attachment-to-login chains.
3

Reverse-proxy token theft

AiTM phishing lure and session takeover[2][3]First cited source May 4, 2026 · Latest cited source May 12, 2026

Confirmed campaign technique; also observed in response cases

How it starts
A PDF or link moves the victim through CAPTCHA and redirect stages to a proxy in front of the real Microsoft sign-in page. The victim completes ordinary authentication and MFA through the proxy.
Attacker outcome
The proxy captures the authenticated session token, enabling mailbox access without requiring the attacker to repeat the MFA challenge.
What to monitor
Compliance-themed PDFs; CAPTCHA-to-login chains; unfamiliar session properties; token replay; impossible travel; mailbox searches, rules, or messages after the sign-in.
4

Conversational trust entry

Authenticated, link-free role-mailbox outreach[7]Evidence dated Jul 23, 2026

Confirmed high-scale June campaign

How it starts
Python-generated messages sent through Amazon SES pass SPF and DKIM, contain no link or attachment, and target accounts-receivable, HR, payroll, and other role mailboxes.
Attacker outcome
A reply opens a trusted conversation that can progress from aging-report or customer-data collection to payroll or payment diversion.
What to monitor
New senders asking for aging reports, employee data, or availability; tracking pixels; unusual bulk outreach; role mailboxes replying outside an approved workflow.
5

Conversational BEC

Generic availability check followed by financial request[4][7]First cited source Apr 30, 2026 · Latest cited source Jul 23, 2026

Dominant initial-contact pattern in Microsoft telemetry

How it starts
A short message asks whether the recipient is available, at a desk, or able to complete a task; the attacker withholds the financial request until the recipient responds.
Attacker outcome
Gift-card purchase, wire transfer, payroll change, sensitive-document release, or a pivot into a longer impersonation exchange.
What to monitor
Short executive or vendor availability messages; secrecy or urgency after the first reply; abrupt moves to personal email, gift cards, payroll, or payment.
6

Process-language social engineering

Routine finance-workflow credential lure[11]Evidence dated Jul 15, 2026

Dominant language class in Cofense’s Q1 2026 finance-phishing observations

How it starts
The subject and message resemble ordinary remittance advice, invoice review, settlement, procurement, contract, e-signature, or vendor-follow-up work instead of using obvious pressure language.
Attacker outcome
The recipient opens a credential-harvest page, releases a document, or continues a payment conversation because the request looks like normal operational traffic.
What to monitor
First-seen counterparties; unexpected remittance or review links; business-process references the recipient cannot independently validate; changes to payment, settlement, or document-sharing workflows.
7

Device-fingerprinted delivery

Platform-aware adaptive phishing[14]Evidence dated Jul 1, 2026

Observed Cofense Intelligence campaign pattern

How it starts
A link collects browser, operating-system, language, time-zone, screen, and location information before selecting the next page or payload.
Attacker outcome
The same infrastructure can deliver credential phishing to one device and a remote-access tool to another, increasing campaign reach and complicating siloed detection.
What to monitor
Multi-stage redirects; user-agent or Cloudflare gating; the same lure producing different outcomes by device; shared domains or paths across email, identity, endpoint, and mobile telemetry.
8

Credential theft

Commodity credential-phishing kit[3]Evidence dated May 12, 2026

Less common than vendor impersonation in Beazley’s case mix

How it starts
A familiar cloud-login, document, voicemail, or security-alert lure sends the user to a credential-harvesting page operated through a reusable phishing kit.
Attacker outcome
Mailbox or SaaS account takeover that supports reconnaissance, internal impersonation, persistence, and later payment fraud.
What to monitor
New credential-collection domains; cloned login pages; password reuse; unfamiliar sign-ins; new MFA methods, OAuth grants, or forwarding rules.
9

Identity impersonation without account compromise

Executive or display-name impersonation[1][3][5]First cited source May 12, 2026 · Latest cited source Jul 8, 2026

Observed but less common in Beazley’s response cases

How it starts
The attacker uses an executive’s name, role, signature, and situational context from a free-webmail or deceptive sender address without controlling the real account.
Attacker outcome
Urgent gift-card, payroll, invoice, wire, cryptocurrency, or sensitive-data request that exploits authority rather than technical access.
What to monitor
Display-name/address mismatch; personal-mail senders; secrecy; urgency; bypassed approval steps; requests that move conversation off the corporate channel.
10

Delivery infrastructure

Free-webmail impersonation and malicious-domain delivery[1][5]First cited source May 21, 2026 · Latest cited source Jul 8, 2026

72% free-webmail share in two time-bounded datasets

How it starts
Attackers use disposable or aged consumer-mail accounts, or newly registered domains, to deliver impersonation and payment lures at low cost.
Attacker outcome
Direct fraud conversation, credential harvesting, or a first-stage message that identifies responsive targets.
What to monitor
Consumer-mail senders claiming to be executives or vendors; first-seen domains; domain age; sender/reply-to mismatch; repeated language or wallet/account reuse.

Intended Reader and Decision Context

Persona / Audience

Who this brief is written for, the geographic and organizational lens it uses, and how readers should apply the intelligence.

Audience fieldPrimary audienceAssessmentExecutives, CFOs, controllers, treasury and accounts-payable leaders, CISOs, identity and email-security teams, legal and incident-response owners, insurers, and risk managers.
Audience fieldOrganization profileAssessmentMost relevant to organizations that move money, change vendor bank details, issue payroll, buy gift cards, administer Microsoft 365, or rely on email for approval and account recovery.
Audience fieldDecision perspectiveAssessmentUse the brief to set transaction-verification rules, define who can stop a payment, identify high-risk identities, and trigger immediate session revocation, evidence preservation, bank coordination, and law-enforcement escalation.
Audience fieldEvidence postureAssessmentA suspicious message, domain, wallet, or login is an investigative signal. A confirmed financial loss, mailbox compromise, or actor attribution requires organization-specific evidence.

Chronology and Decision Milestones

Timeline of Notable Activity

Observed phishing and session-theft activity, fraud-pattern windows, technical disclosures, and publication dates are separated so campaign timing and reporting timing remain clear.

  1. Quarterly threat publication

    Microsoft quantifies the conversational opening of BEC

    Microsoft publishes Q1 telemetry covering about 10.7 million BEC attacks. Generic outreach accounts for 83.1% of observed content, with explicit payroll, invoice, and gift-card requests representing much smaller shares. The finding shifts monitoring toward short availability checks and relationship-building messages before a financial request appears.[4]

  2. Official recovery case

    DOJ and FBI report $4.856 million recovered for Dickinson Public Schools

    The North Dakota U.S. Attorney’s Office and FBI report seizure of funds fraudulently obtained through a BEC scheme after tracing the money to a Citibank account. IntelliOS treats the amount as one official recovery case, not a current-window recovery rate.[8]

  3. Technical disclosure

    Microsoft publishes the campaign analysis

    The report separates initial email delivery, redirect infrastructure, CAPTCHA evasion, legitimate authentication proxying, and token compromise, giving defenders a concrete basis for session revocation, sign-in review, mailbox hunting, and phishing-resistant MFA decisions.[2]

  4. Targeting and victimology

    Microsoft documents a broad, U.S.-weighted AiTM target set

    The disclosure reports more than 35,000 targeted users across over 13,000 organizations in 26 countries. Ninety-two percent of targets were in the United States, with healthcare, financial services, professional services, and technology most represented.[2]

  5. Identity and downstream risk

    The disclosed chain explains why a password reset alone is insufficient

    CAPTCHA gates and staged redirects led to a proxied real sign-in and token capture. A stolen session can expose messages, invoices, contacts, and files; create malicious mailbox rules; and support internal, customer, or vendor impersonation until sessions and persistence are removed.[2]

  6. Incident-response publication

    Beazley identifies vendor trust and partial MFA as recurring weaknesses

    Beazley reports vendor impersonation as the leading vector in its Q1 BEC cases, professional services and financial institutions as a combined 37% of cases, and full or partial MFA at approximately 53% of responding organizations.[3]

  7. Ecosystem baseline

    APWG publishes the Q1 BEC cash-out and infrastructure mix

    APWG’s Fortra-contributed analysis places gift cards at 48% of observed cash-out methods, wires at 19%, payroll diversion at 11%, and the average requested wire at $42,663. Free webmail carries 72% of observed attacks and Gmail represents 53% of that free-webmail subset.[5]

  8. Automated BEC campaign

    Aging-report theft pivots to payroll diversion at mass scale

    Microsoft observes an actor reach more than 67,000 users at over 42,000 organizations in under three hours. Python-generated messages sent through Amazon SES passed SPF and DKIM, targeted accounts-receivable, HR, payroll, and other role mailboxes, tracked opens, and contained no link or attachment.[7]

  9. Practitioner guidance article

    Cofense replaces the “spot the bad email” test with post-delivery resilience measures

    Cofense argues that credible, conversational, and polymorphic messages require leaders to measure reporting rate, time to classify, time to remediate, repeat exposure, and false-positive/false-negative trends—not click rate alone. The article supports program design and does not provide a BEC attack count.[16]

    Source format: Practitioner guidance article
  10. Executive webinar synthesis

    Cofense describes the shape-shifting inbox as a campaign-correlation problem

    The webinar takeaways describe AI-assisted variation across subjects, senders, URLs, language, and payloads; recommend campaign-level visibility, human-in-the-loop validation, and defense in depth; and propose resilience measures including remediation time, dwell time, analyst efficiency, and cost per resolved incident.[15]

    Source format: Webinar takeaways / executive synthesis
  11. Claims-impact publication

    Verizon supplies a historical loss and recovery baseline

    The Breach Impact Study examines 3,934 BEC insurance claims from 2019–2024. Median loss falls in the mid-$50,000s, occasional claims approach $10 million, and 64% include response or recovery activity. IntelliOS uses the study for impact planning, not current-quarter prevalence.[6]

  12. Fraud activity window

    Fortra observes higher BEC volume and gift-card concentration

    FIRE records a 22% increase over May within its active-defense engagements. Gift cards account for 59.9% of cash-out methods, followed by advanced-fee fraud at 22.4% and wires at 10%, showing that transaction controls must cover everyday requests as well as large transfers.[1]

  13. Loss-severity signal

    Wire frequency falls while requested loss increases

    Fortra observes 7% fewer wire attacks, but the average requested wire rises 32% to $71,295; 14% exceed $100,000 and another 15% fall between $50,000 and $100,000. Approval thresholds should therefore reflect possible severity rather than technique frequency.[1]

  14. Delivery and cash-out infrastructure

    Free webmail, malicious domains, mule accounts, and cryptocurrency diversify the path

    Seventy-two percent of observed attacks use free webmail, while Fortra also identifies 1,318 maliciously registered domains, regional and major U.S. banks as leading mule-account types, and 32 cryptocurrency scams involving 28 Bitcoin wallets.[1]

  15. Official prosecution case

    Florida defendant pleads guilty in $3 million-plus BEC scheme

    DOJ reports that compromised payee email accounts were used to redirect legitimate wire payments into personal and illegitimate business accounts. The case supports monitoring for payee-account compromise, layered recipient accounts, restitution, and forfeiture rather than a rolling-window aggregate-loss statistic.[9]

  16. Threat-intelligence blog article

    Cofense documents platform-aware phishing delivery

    Cofense Intelligence reports kits collecting browser, operating-system, language, local-time, screen, and geolocation data before presenting credential phishing or remote-access delivery. The same lure can therefore create different observable outcomes on Windows, macOS, and Android while sharing infrastructure and intent.[14]

    Source format: Threat-intelligence blog article
  17. Trend publication

    Fortra publishes the June BEC Global Insights Report

    The report consolidates cash-out mix, wire severity, bank type, webmail, malicious domains, cryptocurrency, payroll, and qualified attacker-location context. Compared with APWG’s Q1 baseline, the June report shows a higher requested-wire average, but IntelliOS keeps each period and methodology explicit rather than presenting a single global trend line.[1][5]

  18. Threat-intelligence blog article

    Cofense finds finance-themed phishing hiding inside routine work language

    Cofense reports operational business language in roughly 59%–79% of observed finance-phishing subject-line patterns from Q1 2025 through Q1 2026, reaching 79% in Q1 2026. The practical warning shifts from urgency words to unverified remittance, settlement, procurement, invoice, e-signature, and vendor-follow-up context.[11]

    Source format: Threat-intelligence blog article
  19. Campaign-analysis blog article

    A fake Google Ads synchronization notice leads to credential capture

    Cofense’s Phishing Defense Center traces a staged chain from a non-Google sender through a Blogspot redirect and newly created look-alike domain to a JavaScript form imitating Google sign-in. The observation establishes the lure and infrastructure, not successful compromise or BEC loss.[13]

    Source format: Campaign-analysis blog article
  20. Quarterly synthesis

    Microsoft distinguishes an April anomaly from the Q2 baseline

    Microsoft publishes Q2 telemetry showing nearly 9 million BEC attacks in April, followed by 3.4 million in May and 3.9 million in June. Generic outreach remains 87–92% of initial contact, while the June 1 campaign demonstrates that authenticated, link-free messages can still scale financial fraud.[7]

  21. Mid-year webinar synthesis

    Cofense connects AI-assisted BEC to polymorphic, campaign-scale defense

    Cofense’s webinar takeaways describe professionally written BEC using real employees, vendors, projects, and workflows, often without malicious links or attachments. It recommends correlating shared infrastructure, behavior, and objectives across message variants rather than treating each email as an isolated incident.[12]

    Source format: Webinar takeaways / analyst synthesis

Bottom Line Up Front

BLUF

Coverage periodApr 30, 2026Jul 28, 202690 calendar days, inclusiveUpdated Jul 28, 2026
  • Most BEC begins as conversation, not an invoice: Microsoft’s Q2 telemetry found generic outreach in 87–92% of initial contact and explicit financial or document requests in only 3–8%. April spiked to nearly 9 million BEC attacks before May and June returned to the prior monthly baseline.[7]Evidence dated Jul 23, 2026

  • Automation can turn one operator into a mass campaign: On June 1, Microsoft observed a scripted BEC campaign reach more than 67,000 users across over 42,000 organizations in under three hours. It targeted role mailboxes, personalized display names, tracked opens, and shifted from aging-report theft to payroll diversion.[7]Evidence dated Jul 23, 2026

  • The same crime spans low-friction and high-severity cash-out: APWG’s Q1 dataset put gift cards at 48% of cash-out methods and the average requested wire at $42,663. Fortra’s June engagements placed gift cards at 59.9% and average requested wires at $71,295; 14% of June wire requests exceeded $100,000.[1][5]First cited source May 21, 2026 · Latest cited source Jul 8, 2026

  • Vendor trust is the central attack surface: Beazley found vendor impersonation was the leading vector in its Q1 response cases, while professional services and financial institutions represented a combined 37% of investigated cases. A legitimate vendor mailbox or familiar invoice thread can defeat superficial sender checks.[3]Evidence dated May 12, 2026

  • Routine finance language now deserves more scrutiny than obvious urgency: Cofense found operational business language represented 59%–79% of observed finance-phishing subject-line patterns from Q1 2025 through Q1 2026 and reached 79% in Q1 2026. Invoices, remittance notices, procurement requests, settlement documents, and vendor follow-ups can look ordinary because normal workflow—not panic—is the lure.[11]Evidence dated Jul 15, 2026

    Source format: Threat-intelligence blog article
  • Ordinary MFA is not enough: Approximately 53% of organizations in Beazley’s BEC response cases reported full or partial MFA. Microsoft’s April campaign shows why: an adversary-in-the-middle proxy relayed the real sign-in and stole the authenticated session token.[2][3]First cited source May 4, 2026 · Latest cited source May 12, 2026

  • Credential-theft precursors adapt to trusted brands and the recipient’s device: Cofense documented a Google Ads maintenance lure that moved through Blogspot and a look-alike domain to a JavaScript credential form. Separate Cofense research shows kits fingerprinting browser, operating system, language, time zone, screen size, and geolocation before choosing credential phishing or remote-access delivery.[13][14]First cited source Jul 1, 2026 · Latest cited source Jul 21, 2026

    Source formats: Campaign-analysis blog article · Threat-intelligence blog article
  • The financial impact is material even when operations continue: Verizon’s 3,934 BEC insurance claims from 2019–2024 had a median loss in the mid-$50,000s, occasional losses near $10 million, and response or recovery costs in 64% of claims. DOJ/FBI-linked cases in this window separately show a $4.856 million school recovery path and a $3 million-plus wire-diversion scheme.[6][8][9]First cited source Apr 30, 2026 · Latest cited source Jun 25, 2026

  • Executive decision: Require independent callback verification and dual approval even for authenticated, link-free, or routine-looking email; deploy phishing-resistant authentication; correlate related messages as campaigns; monitor role mailboxes, inbox rules, and anomalous sessions; and give one person authority to stop a payment, preserve evidence, and contact the bank immediately.[1][2][3][4][5][6][7][8][9][11][12][13][14][15][16]First cited source Apr 30, 2026 · Latest cited source Jul 23, 2026

    Source formats: Threat-intelligence blog article · Webinar takeaways / analyst synthesis · Campaign-analysis blog article · Webinar takeaways / executive synthesis · Practitioner guidance article

Decision Context

Executive Summary

Coverage periodApr 30, 2026Jul 28, 202690 calendar days, inclusiveUpdated Jul 28, 2026

Business email compromise is a coordinated failure of identity trust and financial control, not merely an email-filter problem. Microsoft’s newest Q2 telemetry shows why raw volume needs interpretation: April surged 121% from March to nearly 9 million BEC attacks, then fell to 3.4 million in May and 3.9 million in June. Microsoft attributes the spike to a small number of high-volume campaigns rather than a durable doubling of the threat. Generic outreach still dominated 87–92% of initial contact, so the attacker usually tests a trusted conversation before asking for money or documents.[7]Evidence dated Jul 23, 2026

Automation is making those conversations scalable. On June 1, Microsoft observed one actor reach more than 67,000 users at over 42,000 organizations in under three hours. Python-generated messages were sent through Amazon SES from a DKIM-configured domain, passed SPF and DKIM, contained no malicious link or attachment, targeted role mailboxes such as accounts receivable, HR, and payroll, and used tracking pixels to identify recipients who opened the message. The lures sought aging reports and customer contacts before switching to payroll diversion.[7]Evidence dated Jul 23, 2026

Current incident-response evidence shows why a familiar sender and ordinary MFA cannot be treated as proof. Beazley reported that trusted-vendor impersonation—either through a genuinely compromised vendor account or a typosquatted domain—was the largest attack vector in its Q1 cases. Approximately 53% of responding organizations reported full or partial MFA, demonstrating that partially deployed MFA, session theft, and adversary-in-the-middle phishing can preserve an attacker’s access even after a user completes an authentication challenge.[3]Evidence dated May 12, 2026

Cofense’s finance-themed phishing analysis explains why awareness programs built around urgency and poor grammar are now incomplete. Across its Q1 2025–Q1 2026 observations, operational business language represented about 59%–79% of subject-line patterns, compared with 21%–41% for traditional urgency-oriented language; operational language reached 79% in Q1 2026. The practical risk is not a particular keyword. It is a message that fits the recipient’s routine: remittance advice, an invoice statement, a procurement request, an e-signature workflow, a contract revision, or a vendor follow-up that appears to continue work already in progress.[11]Evidence dated Jul 15, 2026

Source format: Threat-intelligence blog article

Microsoft’s April code-of-conduct campaign provides the concrete example. More than 35,000 users at over 13,000 organizations in 26 countries received staged compliance lures. The chain used PDFs, CAPTCHA gates, redirect infrastructure, and a proxy in front of the real sign-in page. The user saw and authenticated to Microsoft, but the proxy captured the resulting session token. That token could provide immediate mailbox access without asking the attacker to defeat MFA a second time.[2]Evidence dated May 4, 2026

A July Cofense Phishing Defense Center case shows how a trusted brand can create the access needed for later mailbox fraud. A fake Google Ads MMC synchronization notice used a non-Google sender, a Blogspot redirect, a newly created look-alike domain, and a JavaScript form imitating Google sign-in. Cofense did not claim that every recipient was compromised or that the campaign produced BEC loss. Its value here is the observable sequence: familiar business-service maintenance, staged legitimacy, credential capture, and potential account takeover.[13]Evidence dated Jul 21, 2026

Source format: Campaign-analysis blog article

Cofense’s platform-aware delivery research widens that precursor view. The observed kits collected browser, operating-system, language, local time, time zone, screen dimensions, and geolocation, then varied delivery across Windows, macOS, and Android. One campaign can therefore present a remote-access tool to one user and a credential-harvest page to another while sharing the same lure and infrastructure. Email, endpoint, identity, and mobile telemetry must be correlated as one campaign rather than triaged as unrelated device-specific events.[14]Evidence dated Jul 1, 2026

Source format: Threat-intelligence blog article

Cash-out data shows that BEC ranges from routine-looking gift-card requests to material wire fraud. APWG’s Q1 report, using Fortra analysis, recorded gift cards as 48% of observed cash-out methods, wires as 19%, and payroll diversion as 11%; the average requested wire was $42,663. Fortra’s June engagements then showed a 22% monthly rise in engagement volume, gift cards at 59.9%, and an average requested wire of $71,295. Those datasets are related but time-bounded: the useful conclusion is that finance controls must cover both frequent low-friction requests and less frequent high-severity transfers.[1][5]First cited source May 21, 2026 · Latest cited source Jul 8, 2026

Infrastructure indicators help investigations but do not solve the process weakness. APWG and Fortra both observed 72% of BEC delivery through free webmail in their respective periods, while Fortra also identified 1,318 maliciously registered domains in June. A company that only monitors look-alike domains will miss the larger free-webmail problem; a company that only filters external senders may still lose money when a legitimate vendor mailbox or authenticated employee session is compromised.[1][3][5]First cited source May 12, 2026 · Latest cited source Jul 8, 2026

The loss profile is serious even when the business never experiences encryption or visible downtime. Verizon’s study of 3,934 BEC insurance claims from 2019–2024 found a median loss in the mid-$50,000s, occasional losses near $10 million, and response or recovery activity in 64% of claims. The claims are historical, but the study was published inside this rolling window and provides a useful executive impact baseline for budgeting approval controls, incident response, legal work, and recovery support.[6]Evidence dated Jun 2026

The victimology follows money and trusted relationships. Beazley’s largest Q1 concentration was professional services plus financial institutions at 37% of investigated BEC cases. Microsoft’s April campaign was 92% U.S.-targeted and concentrated in healthcare, financial services, professional services, and technology. Verizon’s claims data also shows BEC appearing across healthcare, manufacturing, retail, public administration, and smaller organizations, where a mid-five-figure loss can be especially disruptive.[2][3][6]First cited source May 4, 2026 · Latest cited source Jun 2026

Official case evidence adds a practical recovery boundary without changing prevalence. The North Dakota U.S. Attorney’s Office and FBI reported seizure of $4,856,578.51 fraudulently obtained from Dickinson Public Schools after tracing the funds to a Citibank account, while a separate Western District of Virginia plea described a $3 million-plus BEC scheme in which compromised payee email accounts redirected legitimate wire payments to personal and illegitimate business accounts. Those cases reinforce the need to preserve evidence, trace funds, and escalate through banks and law enforcement immediately.[8][9]First cited source Apr 30, 2026 · Latest cited source Jun 25, 2026

Cofense’s two 2026 webinar summaries sharpen how the program should be measured. AI-assisted variation changes sender data, URLs, attachments, hashes, language, and subject lines while preserving the campaign objective, so blocking one indicator is temporary. The defensible operating model combines employee reporting, campaign-level correlation, expert validation, automated remediation, and post-delivery containment; measures reporting rate, time to classify, time to remediate, dwell time, repeat exposure, and false-positive/false-negative trends; and keeps human authority over consequential action.[12][15][16]First cited source Jun 16, 2026 · Latest cited source Jul 23, 2026

Source formats: Webinar takeaways / analyst synthesis · Webinar takeaways / executive synthesis · Practitioner guidance article

The management standard is therefore joint ownership. Finance must independently verify bank, payroll, gift-card, cryptocurrency, aging-report, and customer-data requests—even when SPF and DKIM pass, the prose looks professional, and there is no link to inspect. Identity teams must deploy phishing-resistant authentication and revoke sessions; security must preserve sign-in, mailbox, rule, OAuth, message, endpoint, and campaign-correlation evidence; and leadership must preauthorize bank, insurer, counsel, and law-enforcement escalation. The first response must run in minutes because recovery becomes harder after funds leave the first mule account or layered account path.[1][2][3][4][5][6][7][8][9][11][12][13][14][15][16]First cited source Apr 30, 2026 · Latest cited source Jul 23, 2026

Source formats: Threat-intelligence blog article · Webinar takeaways / analyst synthesis · Campaign-analysis blog article · Webinar takeaways / executive synthesis · Practitioner guidance article

Executive Briefing Priorities

Top 10 Briefing Points

  1. 1

    April’s BEC spike was severe but not a new baselineMicrosoft detected nearly 9 million BEC attacks in April, up 121% from March, before volume fell to 3.4 million in May and 3.9 million in June. A small number of high-volume campaigns drove the anomaly.[7]Evidence dated Jul 23, 2026

  2. 2

    Automation can scale authenticated, link-free fraudA June 1 campaign reached over 67,000 users at more than 42,000 organizations in under three hours. Messages passed SPF and DKIM, contained no link or attachment, targeted role mailboxes, and tracked opens; across Q2, generic outreach made up 87–92% of initial contact.[7]Evidence dated Jul 23, 2026

  3. 3

    Trusted vendors are the most important impersonation pathBeazley found vendor impersonation was the leading vector in its Q1 BEC response cases, including both compromised vendor accounts and typosquatted domains.[3]Evidence dated May 12, 2026

  4. 4

    Finance-themed phishing is shifting from pressure to processCofense observed operational business language in 59%–79% of finance-phishing subject-line patterns across Q1 2025–Q1 2026, reaching 79% in Q1 2026. Routine-looking remittance, settlement, procurement, and review language now deserves verification even without urgency words.[11]Evidence dated Jul 15, 2026

  5. 5

    MFA presence did not equal phishing resistanceApproximately 53% of organizations in Beazley’s response cases reported full or partial MFA. Microsoft’s April campaign demonstrates how an AiTM proxy can steal the authenticated session after the user completes ordinary MFA.[2][3]First cited source May 4, 2026 · Latest cited source May 12, 2026

  6. 6

    One phishing campaign can present different threats to different devicesCofense documented kits fingerprinting browser, operating system, language, time zone, screen size, and geolocation before selecting credential phishing or remote-access delivery. Correlate email, identity, endpoint, and mobile events by lure and infrastructure.[14]Evidence dated Jul 1, 2026

  7. 7

    Q1 cash-out favored gift cards while wires carried larger exposureAPWG reported gift cards at 48% of observed cash-out methods, wires at 19%, payroll diversion at 11%, and an average requested wire of $42,663; total observed wire-transfer attacks fell 25% from Q4.[5]Evidence dated May 21, 2026

  8. 8

    Fortra’s June engagement volume and wire severity increasedFIRE reported a 22% monthly rise in engagement volume and a 32% rise in the average requested wire to $71,295, even while wire frequency declined 7%.[1]Evidence dated Jul 8, 2026

  9. 9

    Nearly three in ten June wire requests exceeded $50,000Fourteen percent of Fortra-observed requests exceeded $100,000 and another 15% fell between $50,000 and $100,000, making mid-five-figure approval thresholds strategically important.[1]Evidence dated Jul 8, 2026

  10. 10

    Most observed delivery used free webmailAPWG’s Q1 analysis and Fortra’s June report each placed free-webmail delivery at 72%. Domain monitoring remains useful, but cannot substitute for identity and transaction verification.[1][5]First cited source May 21, 2026 · Latest cited source Jul 8, 2026

  11. 11

    Claims data places typical loss in the mid-five figuresAcross 3,934 Verizon BEC claims from 2019–2024, median loss was in the mid-$50,000s, outliers approached $10 million, and 64% included response or recovery activity.[6]Evidence dated Jun 2026

  12. 12

    Recovery depends on speed and traceabilityOfficial case records show both sides of the response problem: a $4.856 million school recovery after funds were traced and seized, and a separate $3 million-plus BEC scheme using redirected wires and layered accounts. Payment controls need known-bank contacts, evidence preservation, and immediate stop-payment authority.[8][9]First cited source Apr 30, 2026 · Latest cited source Jun 25, 2026

Source-Bound Exposure and Targeting

Victimology Matrix

This is not a raw victim list. Publicly named organizations are shown when reliable sources identify them, with confirmation and attribution boundaries preserved. Where no defensible name exists, IntelliOS uses the narrowest supported exposure population. Sector or geography matches remain scoping signals; they do not prove compromise.

Victim / exposure populationEmployees handling payments, gift cards, payroll, or vendor changes[1]Evidence dated Jul 8, 2026SectorsCross-industry; especially organizations with frequent vendor payments or distributed approval workflowsGeographyFortra’s attacker-location telemetry placed the United States at 33% and Nigeria at 28%, with proxy limitations explicitly notedConfirmation statusActive-defense engagement telemetry; not a complete victim censusHow companies should use itPrioritize finance users, executive assistants, payroll, HR, procurement, and anyone authorized to change payment instructions.
Victim / exposure populationUsers targeted by the Microsoft code-of-conduct AiTM campaign[2]Evidence dated May 4, 2026SectorsHealthcare and life sciences 19%; financial services 18%; professional services 11%; technology and software 11%GeographyMore than 35,000 users across over 13,000 organizations in 26 countries; 92% of targets were in the United StatesConfirmation statusMicrosoft campaign telemetry from April 14–16, 2026How companies should use itU.S. organizations should hunt for compliance-themed lures and validate phishing-resistant authentication for high-risk identities.
Victim / exposure populationRole mailboxes and users targeted by Microsoft’s June 1 automated campaign[7]Evidence dated Jul 23, 2026SectorsRetail and consumer goods 17%; technology and software 15%; financial services 14%; broad cross-industry targetingGeographyMore than 67,000 users across over 42,000 organizations, almost exclusively in the United StatesConfirmation statusMicrosoft-observed campaign targeting, not confirmed compromise or payroll lossHow companies should use itMonitor accounts-receivable, HR, payroll, and other generic mailboxes; detect aging-report and bank-change requests even when SPF/DKIM pass and no link or attachment is present.
Victim / exposure populationOrganizations investigated by Beazley Security[3]Evidence dated May 12, 2026SectorsProfessional services and financial institutions represented a combined 37% of Q1 BEC response cases; healthcare increased from the prior quarterGeographyBeazley’s response portfolio; not a population-wide prevalence estimateConfirmation statusQ1 incident-response case mix; vendor impersonation was the leading attack vector and approximately 53% reported full or partial MFAHow companies should use itPrioritize vendor-facing teams, client-money workflows, high-risk identities, and phishing-resistant authentication rather than assuming MFA presence closes the risk.
Victim / exposure populationOrganizations represented in Verizon insurance claims[6]Evidence dated Jun 2026SectorsBEC appeared in healthcare, manufacturing, retail, public administration, and smaller organizations; the study reports sector-specific claim shares rather than named victimsGeographyCyberAcuView claims dataset from U.S. policyholdersConfirmation status3,934 BEC claims from 2019–2024; historical impact baseline published in the current windowHow companies should use itUse the mid-$50,000 median loss, occasional near-$10 million outliers, and 64% response/recovery rate to size approval controls, insurance, and response capacity.
Victim / exposure populationNamed official case victims and payees[8][9]First cited source Apr 30, 2026 · Latest cited source Jun 25, 2026SectorsEducation/public-sector payments and businesses receiving legitimate wire paymentsGeographyUnited States case publications from North Dakota and the Western District of VirginiaConfirmation statusOfficial case-level recovery, plea, restitution, and forfeiture reporting; not an aggregate victimology sampleHow companies should use itTreat school districts, public agencies, payees, and settlement/payment recipients as high-risk workflows requiring dual control, callback verification, and bank escalation playbooks.
Victim / exposure populationOrganizations making wire transfers[1]Evidence dated Jul 8, 2026SectorsAny company with accounts payable, treasury, closing, settlement, or large vendor paymentsGeographyRegional and major U.S. banks dominated Fortra’s June observed mule-account bank typesConfirmation statusFortra engagement datasetHow companies should use itPreauthorize bank contacts, dual approval, transaction thresholds, call-back verification, and stop-payment authority.
Victim / exposure populationMicrosoft 365 identities protected only by ordinary MFA[2][3]First cited source May 4, 2026 · Latest cited source May 12, 2026SectorsCross-industryGeographyCampaign observed globally with a strong U.S. concentrationConfirmation statusMicrosoft observed AiTM token compromise; Beazley observed MFA presence in approximately 53% of its response casesHow companies should use itPrioritize FIDO2/passkeys or certificate-based authentication, token and sign-in monitoring, and rapid session revocation.

Distinct Operational Records

BEC Campaigns & Fraud Patterns

Fortra-observed BEC cash-out ecosystem

June engagements show gift cards, advanced-fee fraud, wires, payroll diversion, and cryptocurrency requests operating as distinct cash-out paths with different approval, evidence, and recovery requirements.[1]Evidence dated Jul 8, 2026

Microsoft code-of-conduct AiTM credential campaign

Between April 14 and 16, Microsoft observed compliance-themed PDF lures, CAPTCHA gates, staged redirects, and a proxied legitimate sign-in that captured authentication tokens.[2]Evidence dated May 4, 2026

Microsoft June 1 automated aging-report and payroll-diversion campaign

A scripted actor used Python, Amazon SES, authenticated mail, role-based targeting, per-message variables, and open tracking to reach over 67,000 users at more than 42,000 organizations in under three hours without a malicious link or attachment.[7]Evidence dated Jul 23, 2026

Vendor-account and vendor-domain impersonation

Beazley’s leading Q1 vector combined genuine third-party mailbox compromise with typosquatted vendor domains, allowing attackers to exploit existing business relationships and invoice context.[3]Evidence dated May 12, 2026

Conversational BEC at Microsoft scale

Microsoft’s Q1 telemetry shows that the dominant pattern begins with a generic availability check rather than a financial instruction, then advances after the recipient responds.[4]Evidence dated Apr 30, 2026

Cofense finance-workflow phishing evolution

Cofense’s Q1 2025–Q1 2026 subject-line analysis shows attackers increasingly making finance lures look like ordinary remittance, settlement, procurement, and document-review work rather than relying on conspicuous urgency.[11]Evidence dated Jul 15, 2026

Cofense Google Ads Sync credential-harvest chain

A fake maintenance notice moved through a Blogspot redirect and a newly created look-alike domain to a JavaScript Google sign-in imitation. It is retained as a mailbox-compromise precursor, not proof of BEC loss.[13]Evidence dated Jul 21, 2026

Cofense platform-aware phishing operations

Cofense observed kits fingerprinting the recipient’s environment before selecting credential phishing or legitimate remote-access-tool delivery, allowing one lure and infrastructure set to monetize Windows, macOS, and Android users differently.[14]Evidence dated Jul 1, 2026

Dickinson Public Schools recovery case

DOJ and the FBI reported seizure of $4,856,578.51 obtained from Dickinson Public Schools through a BEC scheme after tracing the funds to a Citibank account. The case is retained for recovery timing and evidence-preservation lessons, not prevalence.[8]Evidence dated Apr 30, 2026

Florida wire-diversion plea

A Western District of Virginia plea describes a $3 million-plus BEC scheme in which compromised email accounts redirected legitimate payee wires into personal and illegitimate business accounts, with restitution and forfeiture ordered at sentencing.[9]Evidence dated Jun 25, 2026

Source-Bound Actor Context

Notable Actors & Criminal Ecosystems

Scripted Sparrow

APWG describes Scripted Sparrow as a prolific BEC group. In Fortra’s Q1 observations, Green Dot/Go2Bank held 45% of the group’s collected mule accounts, while the group used accounts at 24 financial institutions. Treat bank concentration as a hunting and recovery lead, not proof that every account at a named institution is malicious.[5]Evidence dated May 21, 2026

Unattributed Microsoft code-of-conduct operator

Microsoft documented the April campaign’s infrastructure, delivery chain, and token-theft behavior without assigning a named actor. IntelliOS preserves that boundary rather than merging the activity into Scripted Sparrow or another BEC identity.[2]Evidence dated May 4, 2026

Enterprise Exposure

Affected Technologies & Trust Boundaries

Microsoft 365 authentication sessions

AiTM phishing can relay a real sign-in, capture the resulting token, and provide immediate account access even when the user completes ordinary MFA.[2]Evidence dated May 4, 2026

Authenticated cloud email and open tracking

Microsoft’s June 1 campaign used Amazon SES and a DKIM-configured domain, passed SPF and DKIM, and embedded per-message tracking pixels. Authentication proved which infrastructure sent the message; it did not prove the request was trustworthy.[7]Evidence dated Jul 23, 2026

Free webmail, legitimate vendor accounts, and look-alike domains

APWG and Fortra observed free webmail carrying most delivery, while Beazley saw both compromised vendor accounts and typosquatted domains. No single sender-reputation control covers all three paths.[1][3][5]First cited source May 12, 2026 · Latest cited source Jul 8, 2026

Email-driven payment and payroll workflows

The exploitable condition is procedural: the same channel can request, approve, and document a transaction unless the company inserts independent verification and dual control.[1][4][5]First cited source Apr 30, 2026 · Latest cited source Jul 8, 2026

Inbox rules, OAuth grants, and session persistence

Once an identity is compromised, hidden forwarding rules, malicious OAuth consent, and active sessions can preserve access and support internal or downstream impersonation after a password change.[2][3]First cited source May 4, 2026 · Latest cited source May 12, 2026

Platform-aware phishing kits

Cofense observed kits collecting browser, operating system, language, time zone, screen dimensions, and geolocation before choosing credential phishing or remote-access delivery. Campaign correlation must span device silos.[14]Evidence dated Jul 1, 2026

Current Carry-Forward Watchlist

Top 10 Specific Threats to Monitor

Prioritized source-backed developments that convert the rolling activity record into named operational monitoring requirements.

1Threat / Category

Finance-workflow phishing

Routine remittance, settlement, procurement, and document-review language[11]Evidence dated Jul 15, 2026

Why it mattersCofense observed operational business language in 59%–79% of finance-phishing subject-line patterns across Q1 2025–Q1 2026. Absence of urgency is not reassurance.What to monitorUnexpected remittance advice; first-seen payment or review links; unfamiliar counterparties; references to transactions the recipient cannot validate; requests that continue a process without a verifiable system record.IntelliOS coverage
2Threat / Category

Payment fraud

New or changed vendor bank instructions[3]Evidence dated May 12, 2026

Why it mattersBeazley identifies vendor impersonation as the leading vector in its Q1 response cases; a genuine vendor mailbox or invoice thread may be weaponized.What to monitorEmail-only change requests; urgency; new routing/account numbers; changed contact details; mismatched domains; refusal to confirm by a known phone number.IntelliOS coverage
3Threat / Category

Conversational BEC

Availability checks and role-mailbox outreach[7]Evidence dated Jul 23, 2026

Why it mattersMicrosoft observed generic outreach in 87–92% of Q2 initial contact; its June 1 campaign targeted accounts-receivable, HR, payroll, and other generic addresses.What to monitorShort executive or vendor messages; aging-report or customer-contact requests; new conversations that shift to secrecy, payroll, gift cards, documents, or payment.IntelliOS coverage
4Threat / Category

Wire fraud

High-value or unusual wire requests[1][5]First cited source May 21, 2026 · Latest cited source Jul 8, 2026

Why it mattersThe average requested wire was $42,663 in APWG’s Q1 dataset and $71,295 in Fortra’s June engagements; 29% of June requests exceeded $50,000.What to monitorNew beneficiaries; after-hours approvals; executive pressure; skipped controls; unusual countries, banks, or payment narratives.IntelliOS coverage
5Threat / Category

Gift-card fraud

Apple, Amazon, and other bulk gift-card requests[1][5]First cited source May 21, 2026 · Latest cited source Jul 8, 2026

Why it mattersGift cards represented 48% of APWG’s Q1 cash-out mix and 59.9% of Fortra’s June engagements.What to monitorSecrecy; personal email delivery; rapid purchase instructions; requests from executives outside normal workflow; repeated low-value cards.IntelliOS coverage
6Threat / Category

Payroll fraud

Direct-deposit change requests[4][5]First cited source Apr 30, 2026 · Latest cited source May 21, 2026

Why it mattersPayroll diversion represented 11% of APWG’s Q1 cash-out mix; Microsoft also observed payroll-update requests rising 15% in February to an eight-month high.What to monitorBank-detail changes submitted by email; new devices; changed personal details; multiple employee requests sharing the same destination.IntelliOS coverage
7Threat / Category

Cryptocurrency fraud

Bitcoin wallet and urgent crypto payment requests[1]Evidence dated Jul 8, 2026

Why it mattersFortra identified 32 scams and 28 wallets in the June dataset.What to monitorFirst-time wallet payments; QR codes; pressure to bypass procurement; reuse of known wallets; transfers outside normal treasury channels.IntelliOS coverage
8Threat / Category

Identity compromise

AiTM token theft and anomalous sessions[2][3]First cited source May 4, 2026 · Latest cited source May 12, 2026

Why it mattersProxied authentication can bypass ordinary MFA; Beazley saw full or partial MFA reported in approximately 53% of its response cases.What to monitorAnomalous tokens; unfamiliar sign-in properties; impossible travel; new session cookies; repeated CAPTCHA-to-login chains; unusual browser or device context.IntelliOS coverage
9Threat / Category

Brand and platform abuse

Trusted-service maintenance and device-adaptive landing pages[13][14]First cited source Jul 1, 2026 · Latest cited source Jul 21, 2026

Why it mattersCofense documented Google Ads brand impersonation and separate platform-aware kits that vary credential or remote-access delivery by browser and operating system.What to monitorNon-vendor sender domains; Blogspot or other trusted-host redirects; newly registered look-alike domains; JavaScript login forms; user-agent gating; one lure producing different payloads across devices.IntelliOS coverage
10Threat / Category

Mailbox abuse

Post-compromise email activity[2][3]First cited source May 4, 2026 · Latest cited source May 12, 2026

Why it mattersA stolen session can expose prior messages and support internal, customer, or vendor impersonation.What to monitorNew inbox or forwarding rules; message deletion; unusual searches; sent-mail anomalies; new OAuth grants; MFA-method changes.IntelliOS coverage
11Threat / Category

Sender trust

Compromised vendors, free webmail, and authenticated cloud delivery[1][3][5][7]First cited source May 12, 2026 · Latest cited source Jul 23, 2026

Why it mattersCurrent evidence covers legitimate vendor accounts, free webmail, look-alike domains, and a Microsoft-observed campaign that passed SPF/DKIM through Amazon SES.What to monitorLook-alike domains; reply-to mismatches; display-name impersonation; free-webmail senders; unusual vendor mail; link-free requests from newly observed authenticated domains; tracking pixels.IntelliOS coverage
12Threat / Category

Response readiness

Bank, insurer, and law-enforcement escalation speed[1][6][8][9]First cited source Apr 30, 2026 · Latest cited source Jul 8, 2026

Why it mattersVerizon found response or recovery activity in 64% of historical BEC claims; DOJ/FBI-linked case evidence shows why tracing, seizure, restitution, and forfeiture depend on fast evidence preservation and financial-institution coordination.What to monitorCurrent 24x7 bank contacts; documented stop-payment authority; preserved messages, headers, logs, and payment records; IC3/law-enforcement routing; insurer and counsel triggers.IntelliOS coverage

Operational Standards from the Evidence

Best Practices and Lessons Learned

The practices below convert the retained public evidence into repeatable executive standards. Each lesson remains bounded to its cited sources.

Coverage periodApr 30, 2026Jul 28, 202690 calendar days, inclusiveUpdated Jul 28, 2026
  1. 1

    Best Practice

    Verify outside the requesting channel[3]Evidence dated May 12, 2026

    Lesson Learned

    A compromised vendor mailbox can make the sender, thread, signature, and prior invoice history look legitimate.

    Minimum Operating Standard

    Confirm every bank-detail or high-risk payment change using a known phone number or separate trusted workflow, never contact information supplied in the request.

  2. 2

    Best Practice

    Use dual control for every form of value movement[1][4][5]First cited source Apr 30, 2026 · Latest cited source Jul 8, 2026

    Lesson Learned

    Current evidence spans gift cards, wires, payroll diversion, cryptocurrency, and document requests rather than one fraud type.

    Minimum Operating Standard

    Require two independent approvers and explicit thresholds for wires, payroll, gift cards, cryptocurrency, and changes to vendor master data.

  3. 3

    Best Practice

    Deploy phishing-resistant authentication[2][3]First cited source May 4, 2026 · Latest cited source May 12, 2026

    Lesson Learned

    AiTM can capture tokens after ordinary MFA succeeds, and Beazley observed MFA presence in approximately 53% of responding organizations.

    Minimum Operating Standard

    Prioritize passkeys/FIDO2, certificate-based authentication, or equivalent phishing-resistant methods for finance, executives, admins, help desks, and vendor-management teams.

  4. 4

    Best Practice

    Revoke sessions, not just passwords[2][3]First cited source May 4, 2026 · Latest cited source May 12, 2026

    Lesson Learned

    A captured token may remain valid after a password change.

    Minimum Operating Standard

    Terminate sessions, reset credentials, review MFA methods and OAuth grants, remove mailbox persistence, and scope messages sent from the account.

  5. 5

    Best Practice

    Preauthorize the financial response[1][6][8][9]First cited source Apr 30, 2026 · Latest cited source Jul 8, 2026

    Lesson Learned

    Recovery options shrink as funds move through mule accounts or cryptocurrency, while DOJ/FBI-linked cases show that trace, seizure, restitution, and forfeiture depend on preserved evidence and rapid coordination.

    Minimum Operating Standard

    Maintain tested bank contacts, stop-payment authority, evidence checklists, insurer/counsel escalation, and law-enforcement reporting procedures.

  6. 6

    Best Practice

    Measure both the conversation and the transaction[7]Evidence dated Jul 23, 2026

    Lesson Learned

    Most Microsoft-observed Q2 BEC began with generic outreach, while its June 1 campaign used authenticated, link-free messages and open tracking.

    Minimum Operating Standard

    Track suspicious availability and aging-report requests, role-mailbox exposure, verification completion, overrides, failed callbacks, high-risk transactions, and time from alert to bank contact.

  7. 7

    Best Practice

    Train on current business-process lures[11][16]First cited source Jun 16, 2026 · Latest cited source Jul 15, 2026

    Lesson Learned

    Cofense observed finance phishing moving toward ordinary operational language that can evade awareness programs centered on urgency, grammar, and obvious red flags.

    Minimum Operating Standard

    Use recent remittance, settlement, procurement, invoice, and document-review examples; test whether users verify workflow context and counterparties rather than merely recognize suspicious wording.

  8. 8

    Best Practice

    Investigate the campaign, not only the message[12][14][15][16]First cited source Jun 16, 2026 · Latest cited source Jul 23, 2026

    Lesson Learned

    Polymorphic and platform-aware phishing can change visible indicators and deliver different outcomes by device while retaining common infrastructure, behavior, and objectives.

    Minimum Operating Standard

    Correlate employee reports, mail telemetry, redirects, identity events, endpoint activity, and mobile access; measure time to classify and remediate the related campaign across every affected mailbox.

Automation Transparency

AI Agent Run Status

AgentBEC Rolling Intelligence Card Publisher
StatusActive · rolling 90-day automation
CadenceWeekly on Tuesday at midday ET; publish only when retained evidence materially changes fraud, identity, or response decisions
Previous run28-Jul-2026 · 4:30 PM ET · Run ACT-BEC-20260728-COFENSE
Previous resultMaterial Cofense research revision published as v13; added the weekly blog discovery route and six article-level records covering routine finance language, brand impersonation, credential theft, platform-aware delivery, polymorphic campaigns, and post-delivery resilience.
What the previous run found
  • Added Cofense Blog to the weekly BEC discovery monitor
  • Retained six Cofense article-level citations with publication format and claim boundaries
  • Added finance-workflow phishing to Research Framing, BLUF, Executive Summary, metrics, vectors, timeline, monitoring, and best practices
  • Added the Google Ads Sync credential-harvest chain as a mailbox-compromise precursor without representing it as successful BEC
  • Added platform-aware phishing delivery and campaign-level correlation across email, identity, endpoint, and mobile telemetry
  • Kept webinar takeaways qualitative and excluded them from attack, compromise, and loss totals
Next run04-Aug-2026 · midday ET
Sources monitored
  • Fortra FIRE and APWG BEC research
  • Microsoft Security and Defender campaign telemetry
  • Cofense Blog, Cofense Intelligence, and Cofense Phishing Defense Center research
  • Beazley Security incident-response reporting
  • Verizon Breach Impact Study / CyberAcuView claims analysis
  • DOJ, FBI, and IC3 case, PSA, recovery, and annual reporting
  • Coveware, Coalition, Abnormal Security, and other BEC, identity, fraud, insurance, and incident-response source streams
  • Connected IntelliOS identity, claims, and DFIR products
  • PETRA report database query constrained to the active rolling 90-day publication window; older reports remain discovery-only
Publication and alert policyPublish and alert only for a material source-backed change; do not notify for no-change checks or date-only rolling-window movement.

Related Intelligence and CARDS Records

Other IntelliOS Products

Publication History

Version Change Log

Versionv13Date28-Jul-2026ChangeAdded Cofense Blog as a weekly discovery source and retained six article-level records. Expanded Research Framing, BLUF, Executive Summary, top briefing points, metrics, initial-access vectors, campaign and technology highlights, Timeline of Notable Activity, monitoring priorities, best practices, AI Agent Status, citations, and methodology with finance-workflow phishing, brand-impersonation credential theft, platform-aware delivery, polymorphic campaign analysis, and post-delivery resilience. Labeled threat-intelligence articles, campaign analysis, webinar synthesis, and practitioner guidance separately and did not convert qualitative Cofense claims into BEC prevalence, compromise, or loss totals.MonitoringWeekly Tuesday rolling 90-day check and material-change publication
Versionv12Date28-Jul-2026ChangeAdded two official DOJ/FBI-linked case-level BEC records: a $4,856,578.51 Dickinson Public Schools recovery and a Florida $3 million-plus wire-diversion plea. Updated Tier 0 source coverage, Research Framing, BLUF, Executive Summary, statistics, victimology, structured fraud-pattern cards, timeline, monitoring table, best practices, AI Agent Status, and methodology boundaries while preserving that no retained source publishes an Apr 30–Jul 28 aggregate actual or claimed BEC loss.MonitoringWeekly Tuesday rolling 90-day check and material-change publication
Versionv11Date24-Jul-2026ChangeAdded the PETRA report database to the governed source audit and weekly monitor. The 90-day query returned no qualifying Apr 26–Jul 24 publication; older BEC, claims, and annual reports remain discovery context and are not treated as current-window evidence.MonitoringWeekly Tuesday rolling 90-day check and material-change publication
Versionv10Date24-Jul-2026ChangeReplaced the abbreviated four-class Research Framing source summary with a complete Tier 0–Tier 8 audit showing checked, candidate-hit, selected, and not-used counts plus the retained and excluded source names in every tier.MonitoringWeekly Tuesday rolling 90-day check and material-change publication
Versionv9Date24-Jul-2026ChangeAdded a Current-window actual / claimed loss metric to Card 2. It states that no retained source publishes an Apr 26–Jul 24 aggregate, distinguishes Fortra’s $71,295 average requested wire from confirmed loss, and preserves Verizon’s mid-$50,000 2019–2024 claims median as historical context rather than a rolling-period figure.MonitoringWeekly Tuesday rolling 90-day check and material-change publication
Versionv8Date24-Jul-2026ChangeRemoved the low-information three-point Microsoft Q2 BEC line chart from Card 2. The April, May, and June figures remain in cited metrics and narrative, while the card now prioritizes the more actionable initial-access and trust-abuse vector table.MonitoringWeekly Tuesday rolling 90-day check and material-change publication
Versionv7Date24-Jul-2026ChangeExpanded Card 2 with an eight-row, source-cited Initial Access and Trust-Abuse Vector table. Separated compromised vendor mailboxes, typosquatted domains, AiTM reverse-proxy session theft, authenticated link-free role-mailbox outreach, conversational BEC, commodity credential phishing, executive impersonation, and delivery infrastructure; explicitly distinguished OAuth device-code phishing and excluded its out-of-window publication from the in-window table.MonitoringWeekly Tuesday rolling 90-day check and material-change publication
Versionv6Date24-Jul-2026ChangeAdded a source-cited Q2 line chart comparing Microsoft-observed BEC detections in April, May, and June and visually separating the campaign-driven April spike from the lower May and June baseline.MonitoringWeekly Tuesday rolling 90-day check and material-change publication
Versionv5Date24-Jul-2026ChangeRead and reconciled seven retained BEC sources; added Microsoft Q1 and Q2 conversational-attack telemetry, the June 1 automated aging-report/payroll campaign, Beazley incident-response and MFA findings, APWG cash-out and infrastructure baselines, and Verizon claims impact. Rewrote Research Framing, BLUF, Executive Summary, top-ten briefing points, metrics, victimology, campaign and technology context, timeline, monitoring priorities, and best practices. Recorded Coveware, FBI IC3, Coalition, and Abnormal Security as checked but excluded because their relevant BEC publications fall outside the April 26 cutoff.MonitoringWeekly Tuesday rolling 90-day check and material-change publication
Versionv4Date24-Jul-2026ChangeRebuilt Research Framing with explicit Fortra-versus-Microsoft source roles, campaign and targeting boundaries, and a finance/identity decision standard; moved Timeline of Notable Activity ahead of BLUF; and expanded the timeline from four to eight milestones covering lure delivery, AiTM token theft, downstream fraud risk, fraud economics, loss severity, infrastructure, and publication dates.MonitoringWeekly Tuesday rolling 90-day check and material-change publication
Versionv3Date24-Jul-2026ChangeRebuilt the card to the Government Activity gold standard with shared banner, Research Framing, Persona / Audience, BLUF, Executive Summary, victimology, campaign and technology context, timeline, top-10 monitoring table, best practices, AI Agent status, related IntelliOS products, and source-bound defaults.MonitoringWeekly Tuesday rolling 90-day check and cumulative publication
Versionv2Date24-Jul-2026ChangeConverted the product to a rolling 90-day window and excluded evidence outside the active display period.MonitoringSuperseded by v3
Versionv1Date17-Jul-2026ChangeInitial Business Email Compromise Rolling Intelligence Card publication.MonitoringSuperseded by v3

Citations

Retained Sources and Claim Treatment

Source1PublisherFortra FIREPublished2026-07-08Publication / evidenceSource indexprimary researchWhy used / claim treatmentMetrics reflect Fortra's active-defense engagements and should not be treated as the entire BEC market.SourceBEC Global Insights Report: June 2026

https://www.fortra.com/blog/bec-global-insights-report-june-2026

Source2PublisherMicrosoft Defender Security ResearchPublished2026-05-04Publication / evidenceSource indexprimary researchWhy used / claim treatmentCampaign-specific Microsoft telemetry; used for technique and exposure context, not June volume.SourceBreaking the code: Multi-stage phishing leads to AiTM token compromise

https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/

Source3PublisherBeazley SecurityPublished2026-05-12Publication / evidenceSource indexincident responseWhy used / claim treatmentQ1 incident-response and MDR case mix published May 12; sector, MFA, and attack-vector percentages are limited to Beazley Security engagements.SourceQuarterly Threat Report: First Quarter, 2026

https://beazley.security/insights/quarterly-threat-report-first-quarter-2026

Source4PublisherMicrosoft SecurityPublished2026-04-30Publication / evidenceSource indexprimary researchWhy used / claim treatmentMicrosoft email-threat telemetry for Q1 2026; attack counts and message-theme shares are provider-observed detections, not confirmed losses.SourceEmail threat landscape Q1 2026: Trends and insights

https://www.microsoft.com/en-us/security/blog/2026/04/30/email-threat-landscape-q1-2026-trends-and-insights/

Source5PublisherAnti-Phishing Working GroupPublished2026-05-21Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentAPWG member reporting and Fortra analysis of thousands of BEC attempts; cash-out and infrastructure figures are dataset-scoped and describe Q1 activity.SourcePhishing Activity Trends Report: 1st Quarter 2026

https://docs.apwg.org/reports/apwg_trends_report_q1_2026.pdf

Source6PublisherVerizon BusinessPublished2026-06Publication / evidenceSource indexprimary researchWhy used / claim treatmentPublished during the rolling window but based on 3,934 BEC insurance claims from 2019–2024; used as an impact and recovery baseline, not current-quarter prevalence.Source2026 Breach Impact Study

https://www.verizon.com/business/resources/reports/2026-breach-impact-study-dbir.pdf

Source7PublisherMicrosoft SecurityPublished2026-07-23Publication / evidenceSource indexprimary researchWhy used / claim treatmentMicrosoft Q2 detection telemetry and campaign analysis; message and target counts describe observed attacks, not confirmed account compromise or financial loss.SourceEmail threat landscape Q2 2026: Trends and insights

https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/

Source8PublisherU.S. Department of Justice / FBIPublished2026-04-30Publication / evidenceSource indexofficialWhy used / claim treatmentOfficial case-level recovery and civil-forfeiture reporting. The seized amount is a specific Dickinson Public Schools BEC recovery path, not an aggregate 90-day loss, recovery rate, or proof that every similar transfer is recoverable.SourceNorth Dakota FBI and U.S. Attorney's Office Recover $4.8 Million Dollars Scammed from Dickinson Public Schools

https://www.justice.gov/usao-nd/pr/north-dakota-fbi-and-us-attorneys-office-recover-48-million-dollars-scammed-dickinson

Source9PublisherU.S. Department of Justice / FBIPublished2026-06-25Publication / evidenceSource indexofficialWhy used / claim treatmentOfficial case-level plea reporting. The described $3 million-plus BEC scheme and restitution/forfeiture terms are legal-case evidence, not a prevalence dataset or current-window aggregate loss measure.SourceFlorida Woman Pleads Guilty for Role in Business Email Scam

https://www.justice.gov/usao-wdva/pr/florida-woman-pleads-guilty-role-business-email-scam

Source10PublisherCofensePublishedNot availablePublication / evidenceThreat-research blog indexecosystem monitorWhy used / claim treatmentOfficial Cofense publication index monitored weekly for BEC, phishing, credential-theft, brand-impersonation, and email-defense research. The index is a discovery route; each retained article controls its own finding.SourceCofense Blog

https://cofense.com/blog

Source11PublisherCofense IntelligencePublished2026-07-15Publication / evidenceThreat-intelligence blog articleprimary researchWhy used / claim treatmentCofense Intelligence analysis of finance-themed phishing subject lines from Q1 2025 through Q1 2026. Percentages describe Cofense-observed campaign language, not BEC losses, confirmed account compromise, or all malicious email.SourceWhen Routine Becomes the Threat: The Evolution of Finance-Themed Phishing

https://cofense.com/blog/when-routine-becomes-the-threat-the-evolution-of-finance-themed-phishing

Source12PublisherCofensePublished2026-07-23Publication / evidenceWebinar takeaways / analyst synthesisecosystem monitorWhy used / claim treatmentCofense summary of its mid-year webinar. It supports qualitative conclusions about AI-assisted, polymorphic, campaign-scale phishing and BEC; it does not publish a reproducible BEC prevalence denominator in the article.Source5 Key Takeaways from the Cofense 2026 Mid-Year Threat Report Webinar

https://cofense.com/blog/5-key-takeaways-from-the-cofense-2026-mid-year-threat-report-webinar

Source13PublisherCofense Phishing Defense CenterPublished2026-07-21Publication / evidenceCampaign-analysis blog articleprimary researchWhy used / claim treatmentFirst-party Cofense campaign observation documenting one Google Ads-themed credential-harvest chain. It establishes the observed lure and infrastructure, not successful compromise, BEC conversion, or campaign-wide victim totals.SourceClick to Sync: From Google Ads Maintenance Notice to Credential Theft

https://cofense.com/blog/click-to-sync-from-google-ads-maintenance-notice-to-credential-theft

Source14PublisherCofense IntelligencePublished2026-07-01Publication / evidenceThreat-intelligence blog articleprimary researchWhy used / claim treatmentCofense Intelligence analysis of platform-aware phishing delivery. It supports technique and defensive-visibility conclusions; linked Active Threat Reports control their campaign-specific indicators.SourceThe Platform You Trust Is the Platform They Target

https://cofense.com/blog/the-platform-you-trust-is-the-platform-they-target

Source15PublisherCofensePublished2026-06-18Publication / evidenceWebinar takeaways / executive synthesisecosystem monitorWhy used / claim treatmentExecutive synthesis of a Cofense webinar. It supports program and measurement priorities, not quantitative prevalence or incident attribution.Source5 Key Takeaways from Inside the Shape-Shifting Inbox: A Modern Playbook for Security Leaders

https://cofense.com/blog/5-key-takeaways-from-inside-the-shape-shifting-inbox-a-modern-playbook-for-security-leaders

Source16PublisherCofensePublished2026-06-16Publication / evidencePractitioner guidance articleecosystem monitorWhy used / claim treatmentCofense practitioner guidance on post-delivery resilience and phishing-program measurement. It supports operating standards, not a count of attacks, compromises, or losses.SourcePhishing No Longer Looks Wrong: What Security Leaders Should Do Next

https://cofense.com/blog/phishing-no-longer-looks-wrong-what-security-leaders-should-do-next