How it works
Entry comes via credential theft or helpdesk-style social engineering against employees with banking access; attackers persist while studying payment patterns; then transfers are styled to look routine — often ACH batches and wires sized under review thresholds (see dual authorization).
Warning signs
- Unfamiliar payees appearing in templates.
- Changed contact details or alert settings on bank accounts.
- MFA resets nobody remembers requesting.
- Small "test" transactions preceding larger ones.
Controls
- Dedicated devices or hardened access for banking.
- Dual authorization on payment release.
- ACH positive pay filters (see ACH positive pay).
- Verified out-of-band confirmation for new payees and limit changes.
- Verification on the reset flows that guard all of it — see account takeover prevention.