Accounts payable at the county construction office receives an email from what looks like a long-time vendor asking to redirect the next progress payment to a new bank account. The From domain is one character off the real vendor domain. Which attack best matches this scenario?
Select an answer to reveal the explanation.
Short Explanation
One wrong letter in the vendor domain plus a "send the check here instead" ask is textbook BEC with a lookalike domain. It is payment fraud by brand impersonation, not a phone-only scam or a USB drop. Always verify bank-change requests out of band.
Full Explanation
Business email compromise (BEC) often combines social engineering with brand impersonation or typosquatting so finance staff trust a payment-change request. Objective 2.2 groups BEC and related impersonation vectors as human and messaging attack surfaces that enable fraud. Voice-only vishing, watering-hole site compromise, and removable-media drops are separate vectors. Municipal AP workflows should require dual control and verified callback before changing vendor banking details.