What happened: You forwarded the email to your VP of Finance asking "does this look right to you?" Within 8 minutes, the VP replied: "Looks like Lucia, but domain looks off — check it." You both noticed the domain mismatch simultaneously. You were about to call Lucia when you noticed — the attacker's reply chain was now sitting in your VP's inbox too.
More critically: while you were coordinating with your VP, time was passing. At 1:15pm, the attacker — monitoring the real Lucia's calendar — sent a follow-up: "Can you confirm we're good to process? Time is tight." You almost missed it while discussing. If either you or your VP had processed at that moment under pressure, the wire would have gone through.
// WHAT WENT WRONG
• Forwarding distributed the threat to another inbox (if the email contained trackers or malicious links, your VP's machine is now at risk)
• Coordination delays created time pressure — which is exactly what the attacker wanted
• The "second opinion" conversation happened in the same compromised thread
• The attacker's follow-up (sent while you were distracted) is a pressure escalation tactic
Correct action: Don't forward. If you need a second opinion, describe the situation in a separate channel (text, Slack, separate email) — don't forward the attacker's email. Then call Lucia directly to verify. The verification cascade is: stop → call known number → escalate.