Fictitious case. Spoofed email from company director instructed finance team to make urgent £45,000 transfer. Email headers analysed, payment trail traced to Eastern European accounts. Classic BEC attack with domain spoofing.
| Element | Finding | Risk |
|---|---|---|
| Sending domain | acme-grp.com (vs legitimate acme-group.com). Registered 3 days prior via Tucows. Mail server: 45.XX.XX.XX (Romania) | HIGH |
| Email headers | X-Originating-IP: 45.XX.XX.XX (RO). No SPF record on lookalike domain. DKIM not configured | HIGH |
| Receiving account | Meridian Consulting SIA — Latvian company registered 2 weeks prior. Single director (nominee). Citadele bank | HIGH |
| Funds movement | £45,000 → Latvia → split into 3 transfers to Lithuania, Poland, Ukraine within 4 hours | HIGH |
Statement of facts
On behalf of REDACTED LTD, I report that on 14 May 2026 our company was the victim of a Business Email Compromise attack. A fraudulent email impersonating our Managing Director instructed our Finance Manager to transfer £45,000 to an account in Latvia controlled by the perpetrators. The forensic investigation has identified the attack infrastructure and traced the fund flow across four jurisdictions.
Start your free report: within minutes you will receive a forensic investigation report and a formal statement ready to submit to the authorities.
Start your report →No obligation. You only pay if you decide to download the documents.