Scenario library / Fraud
Business Email Compromise Wire Fraud: a tabletop exercise scenario
A supplier payment is redirected to a new account after a convincing email thread. The first payment has already been released when the exercise opens.
60–90 min · Executive + finance

What this is modelled on
Modelled on invoice and executive-impersonation fraud, where a compromised or spoofed mail thread redirects a legitimate payment to an attacker-controlled account, often discovered only when the real supplier chases payment.
Why it matters
Money leaves in minutes and recovery windows are measured in hours. Payment controls, escalation paths and banking relationships all get tested at once.
Exercise objectives
- Test payment change controls and out-of-band verification
- Rehearse rapid recall through banking partners
- Confirm insurer and law enforcement engagement steps
- Assess mailbox compromise investigation capability
Decision points tested
- Freeze all outbound payments or target specific runs
- Who contacts the bank, insurer and police, and in what order
- Whether the mailbox compromise triggers wider notification
- Immediate control changes to payment approvals
Sample inject timeline
- T+0
Supplier chase
The real supplier reports non-payment of an invoice marked as paid.
- T+15
Mail evidence
A forwarding rule is found on a finance mailbox with a lookalike domain in the thread.
- T+35
Second payment
A further payment run is scheduled to the same account within the hour.
- T+55
Recovery window
The bank advises that funds may already be onward-transferred.
What the after-action report should capture
- Payment verification control effectiveness
- Time to bank contact
- Mailbox forensics coverage
- Control changes and owners agreed
Run this scenario with your team
Tailor it to your environment with AI, run the injects live, and export a web or PDF after-action report when the exercise ends.
