// SIMULATION — STEP 2

Incorrect Response

You processed the wire immediately. Here's what happened.

FUND TRANSFER PROCESSED — $340K LOST
What happened: You processed the wire to Prosperity Financial Services, acct 8847-2291-0034. Within 90 minutes, the funds were withdrawn from the intermediary account and moved through a series of mule accounts. By 3pm, the money was unrecoverable. At 3:15pm, you received a call from the real Lucia Rodriguez, who had no idea what you were talking about. She was in meetings all day — she never sent that email.

The attack: Attackers scraped Lucia's LinkedIn posts, conference presentations, and internal emails to build a writing profile. They registered @meridian-group.com (one letter off from the real domain). They spoofed the email to appear legitimate on mobile, where the full domain isn't always visible. The $340K was gone before anyone realized the attack had occurred.
// WHAT WENT WRONG
• Domain spoofing: @meridian-group.com ≠ @meridianfg.com
• Dual-approval bypassed without escalation
• No verification via a separate channel
• Urgency exploited to prevent careful review
Correct action: You should have called Lucia on her known number (from your CRM, not the incoming email) before processing any wire. The domain mismatch alone was sufficient signal to stop.
See the Correct Response Back to Module