After a successful phish, a vendor-payment thread is sent from the city comptroller's real mailbox asking a contractor to change the ACH destination. Which term best describes this activity?
Select an answer to reveal the explanation.
Short Explanation
The invoice looks official because it is the comptroller's mailbox — hijacked, not a brand-new encryptor. Email compromise is the attacker sitting in a real civic inbox and steering money, classic BEC-style abuse. Do not invent ransomware or a kiosk botnet to explain a fraudulent thread.
Full Explanation
Email compromise is attacker use of a legitimate civic mailbox, often after phishing, to continue trusted threads such as vendor ACH changes. That BEC-style abuse is not a new malware family, not a botnet flood, and not a mail-gateway DoS. Objective 2.2 lists email compromise separately from ransomware and botnets so analysts classify the behavior, not the lure. Civic SOCs should pull mailbox audit, forwarding, and sent-item evidence in Splunk ES instead of pivoting first to endpoint encryption signatures.