// SIMULATION — STEP 4

Correct Response

You stopped and verified before processing. Here's what happened.

ATTACK STOPPED — $340K PROTECTED
What happened: You didn't reply. You didn't process the wire. You pulled up Lucia's contact from your CRM and called her direct line. She picked up on the second ring — she was in her 11am leadership meeting. When you told her about the email, she went quiet for three seconds and then said: "I didn't send that. Don't process anything. I'll call you in 15 minutes."

Within 20 minutes, Lucia had confirmed to you and the security team that the email was a spoof. The domain @meridian-group.com was investigated — it had been registered 6 days prior with a privacy proxy. The attack had been waiting for the right moment — a day when the CFO was in back-to-back meetings and couldn't easily be reached by phone.
// WHAT YOU DID RIGHT
✓ Did not reply to the incoming email (avoided confirming the address)
✓ Did not process the wire (stopped the financial action)
✓ Used a verified channel (CRM contact, not the incoming email)
✓ Escalated to security immediately after confirmation
✓ The domain mismatch was recognized and acted upon
Aftermath: The security team identified the attack infrastructure within 48 hours. The $340K was never at risk because the verification cascade was followed. The board was notified. The incident was logged and used to update email filtering rules across the organization. This is how it should work.
See Full Scenario Summary Complete Module