A wire change request in March
- The problem
- A staff accountant receives an email that looks like it came from a partner, asking to update the payment details on a client refund. The domain is off by one character.
- What we do
- Impersonation protection flags the lookalike domain and quarantines the message, and the accountant has already seen the same pattern in a phishing simulation, so it gets reported rather than actioned.
- The result
- No funds move, and the attempt becomes a training example instead of a loss the firm has to disclose.