Field Notes / Incident Reconstruction
Anatomy of a phishing attack: how a Manila SME lost PHP 4.7M in five minutes
A minute-by-minute reconstruction of a real business email compromise at a Makati trading firm. Every beat annotated with the control that would have caught it, and every control was already paid for.
01 The five minutes the money moved
t 14:03 an email landed in the CFO's inbox. A payment reminder from a Hong Kong supplier the firm had traded with for 11 years. PHP 4.7 million, due now, the original invoice attached, bank details sitting inline at the bottom. The bookkeeper had forwarded it with one line: “Pa-approve please, due today.” The CFO recognised the supplier, the invoice and the amount. All three checked out.
At 14:05 he sent the bookkeeper a Viber message. “Confirm legit?” Two minutes later: “Yes sir, supplier sent reminder, I forwarded to you. Same amount as before.” From where he sat that was triple confirmation. The email, the forward, the direct reply. He did not call the supplier. He did not check the account number against the attached PDF. He did not notice the bank details in the body differed from the details on the invoice itself.
At 14:07 the CFO logged into the corporate banking portal. For transfers under PHP 5 million the bank asked for a password only. His password was strong by the old rulebook: nine characters, mixed case, a number and a symbol. No second factor was required at this tier. He clicked Approve at 14:08. The bank settled in real time over an instant SWIFT corridor. By 14:11 the funds had left the account. By 14:13 the receiving bank in Mauritius confirmed the deposit, and the attacker moved the money through three correspondent accounts before anyone at the originating bank looked at it.
02 Why the email looked exactly right
Half an hour after the wire cleared, at 14:43, the bookkeeper messaged again. Had he paid the supplier yet? He sent the receipt. Her reply came back in Taglish: the invoice she had seen was for a lower amount, and PHP 4.7 million had shocked her. Last week's invoice was PHP 1.8 million.
The CFO went cold and pulled up the morning's PDF. PHP 1.8 million. The email body said PHP 4.7 million. He had read the body and approved the body. The PDF was the real invoice. The body was the attacker's work. Forensics later found the whole chain: a credential-stuffing attack against the bookkeeper's Microsoft 365 account, using a password that matched a dump from an unrelated 2022 breach, an inbox forwarding rule that fed the attacker every incoming supplier email, nine days of reading, and a look-alike domain registered 11 days earlier through a Russian registrar.
This is the part most write-ups undersell. The action phase gets the attention because that is where money moves. The attack itself happened during the nine days of reconnaissance. By the time the email arrived, the attacker had read months of genuine correspondence between the firm and its supplier and could mimic the tone, the cadence and the invoice format exactly. Stolen credentials are already the single largest action in confirmed breaches worldwide, and the share climbs every year Verizon DBIR 2024 . Training staff to spot a fake will not beat a message the attacker spent nine days perfecting.
The gap between an intruder getting in and being noticed is measured in days, not minutes, which is exactly how a nine-day dwell time goes unseen inside a busy inbox IBM 2024 . The firm never absorbed the loss back. It was not recoverable and not insurable. They covered it from operating cash and a personal injection from the owner. They are still trading. The CFO no longer approves any payment without a callback.
03 The controls already paid for
Walk the timeline again and mark the control that would have stopped each beat. Every one of them was available to this firm at no extra cost. Most were sitting inside a Microsoft 365 Business Premium licence they already paid for each month.
At 14:03, domain-impersonation detection in Microsoft Defender for Office 365 would have flagged the Cyrillic look-alike domain the moment its first email arrived, and dropped a warning banner into the inbox. The feature ships with Business Premium. It had never been enabled. At 14:05, a written callback rule for any payment above PHP 100,000 would have sent the CFO to a phone number stored outside the email thread, not the number in the supplier's signature that the attacker had already changed. That control costs nothing and takes about four minutes per payment. It catches the majority of BEC fraud at the point of approval.
At 14:07, mandatory MFA at the bank for transfers above PHP 250,000 would have blocked the login outright, because the attacker working remotely had no authenticator. Most Philippine banks now offer this as an opt-in. Most SMBs leave it off because the bank does not force it. And underneath all of it, MFA on the Microsoft 365 tenant would have stopped the original credential-stuffing login that started the whole nine days Verizon DBIR 2024 .
04 The two-week fix
None of this needs a large budget. The cost is calendar time, not money. Turn on the four upstream controls in order of leverage and you close the route this attacker used, inside two weeks and without new headcount. The firm did exactly that after the debrief.
- Enforce MFA on the Microsoft 365 tenant for every account, using an authenticator app rather than SMS.
- Turn on alerts for new inbox forwarding rules, the trick attackers use to watch your mail unseen.
- Enable domain-impersonation detection in Defender for Office 365, already included with Business Premium.
- Write a callback rule: any payment above PHP 100,000 is verified by phone on a number stored outside email.
- Switch on bank-side MFA and first-time-recipient flags for transfers above PHP 250,000.
When we debriefed the CFO three weeks on, he kept returning to one point. He had read about BEC fraud and thought it happened to other companies. Every control that would have stopped the attack was already in his licence. He had simply never enabled it. That is the honest lesson for most Filipino SMBs. The features are paid for. Nobody has connected the abstract risk to the concrete task of switching them on this Tuesday. If you want a second pair of eyes on your inbox security and your payment process, a free audit runs a quick external check and tells you which of the four upstream controls to turn on first, before an attacker finds the gap for you.
References
Sources
- Verizon. 2024 Data Breach Investigations Report (DBIR), Business Email Compromise section. Verizon Business, 2024. verizon.com
- IBM. Cost of a Data Breach Report 2024. IBM Security, 2024. ibm.com
- FBI. Internet Crime Report 2024. FBI Internet Crime Complaint Center (IC3), 2024. ic3.gov
- Bangko Sentral ng Pilipinas. Memorandum on Anti-Fraud and Anti-Money-Laundering Measures. BSP, 2024. bsp.gov.ph