What happened: You processed the wire to Prosperity Financial Services, acct 8847-2291-0034. Within 90 minutes, the funds were withdrawn from the intermediary account and moved through a series of mule accounts. By 3pm, the money was unrecoverable. At 3:15pm, you received a call from the real Lucia Rodriguez, who had no idea what you were talking about. She was in meetings all day — she never sent that email.
The attack: Attackers scraped Lucia's LinkedIn posts, conference presentations, and internal emails to build a writing profile. They registered @meridian-group.com (one letter off from the real domain). They spoofed the email to appear legitimate on mobile, where the full domain isn't always visible. The $340K was gone before anyone realized the attack had occurred.
// WHAT WENT WRONG
• Domain spoofing: @meridian-group.com ≠ @meridianfg.com
• Dual-approval bypassed without escalation
• No verification via a separate channel
• Urgency exploited to prevent careful review
Correct action: You should have called Lucia on her known number (from your CRM, not the incoming email) before processing any wire. The domain mismatch alone was sufficient signal to stop.