---
title: "Fraud through hijacked email accounts"
url: https://www.hqsolutions.ro/en/guides/business-email-compromise/
lang: en
site: HQ
---

> Reduce the risk of business email compromise. Verify payment and data requests by phone and protect your company’s accounts with two-factor authentication.

# Fraud through hijacked email accounts

An invoice arrives from your supplier’s real email address, but the bank account details have been replaced with an account controlled by an attacker. This can happen when an attacker gains access to the supplier’s email account and sends messages in their name. It is a form of business email compromise (BEC), a type of fraud that tricks employees into sending money or confidential information. Confirm requests to change bank details or share data by calling a known number, even when you recognize the sender’s address and the conversation.

## How attackers gain access

An attacker can gain access to an email account using a stolen password. Software that collects saved passwords (infostealer malware) can extract login details from an infected computer.

Once inside the account, the attacker can read correspondence with business partners and send messages from the real address. A fraudulent request can then appear in a conversation your team already knows.

## Requests from familiar email addresses

An attacker using a supplier’s account can send you an invoice with new bank details. The message may explain the change, while directing your payment to an account the attacker controls.

A request that appears to come from a manager or a public authority may ask for customer data or company documents. A hijacked account can also be used to request access permissions.

Recognizing the sender’s address does not establish that the account owner authorized the request. Email authentication checks can confirm that a message came through infrastructure authorized for the domain, without establishing who controls the account. A fraudulent message sent from a real account can therefore pass those checks and reach your inbox, even when you use an email filter.

> A message sent from a real account can pass email authentication checks and reach your inbox.

## Checking requests before approval

Make it company policy to verify requests through another channel whenever they involve changing bank details, sharing data, sending customer documents, or granting access permissions. Apply the rule regardless of who sent the message, including requests within an existing conversation.

Call a verified number your company already holds in a contract or internal contact list. If the message appears to come from a public authority, use the number on its official website, which you access independently of the message. Do not use a number supplied in the email or its signature for this check.

After the phone confirmation, require 2 people to approve payments to a new bank account so the employee receiving the request does not decide alone. Urgent requests go through the same check, and the payment or data transfer waits for confirmation.

> 2 people approve a payment to a new bank account after the phone confirmation.

## Protecting your company’s email accounts

Enable two-factor authentication for your company’s email accounts so signing in requires an additional check beyond the password. This protects your own accounts, while requests from a supplier whose account has been hijacked still need verification.

Set up alerts for new rules that automatically forward messages to another address, as well as other unusual account changes. Assign responsibility for receiving the alerts and checking whether each change was authorized.

> Check forwarding-rule alerts to establish whether the change was authorized.

## Responding after a fraudulent payment

If you have already paid in response to a fraudulent request, call your bank immediately. Give the bank the transfer details and ask what action can still be taken.

At the same time, report the fraud to Romania’s National Cyber Security Directorate (DNSC) on 1911 and file a report with the police.

> If you have already paid, call your bank immediately.

## Where we come in

We configure your email filter and roll out two-factor authentication across the company, including a procedure for an employee who loses their phone. We can also configure alerts for forwarding rules and other unusual email account changes.

We help your team recognize suspicious messages using concrete examples and agree on the response plan in advance. For critical incidents, we respond within 1 hour under the service-level agreement (SLA).

During an on-site audit, we check your backups, access permissions, updates, and network configuration, and give you a written report to keep whatever you decide. Request a free audit.
