🔍 Suspicious message?
Analyze senders, links or files in real time with our scanner.
In this article, we analyze a real case in which a Spanish company suffered a €79,500 fraud after receiving manipulated documentation and seemingly legitimate communications from a foreign supplier. No sensitive data is revealed, but the key technical elements of the case are highlighted.
BEC fraud is one of the cybercrimes with the highest economic impact on Spanish companies. According to the FBI, BEC fraud generated more than 2.9 billion dollars in losses in 2023. In Spain, the National Police records a steady increase in cases every year, especially in B2B trade operations. Unlike mass phishing, BEC fraud is a targeted attack—the attacker studies their victim before acting.
1. The Context: A Legitimate Commercial Operation
The affected company was negotiating the purchase of an industrial machine from a well-known foreign supplier. The process was unfolding in a seemingly normal manner:
- Email exchanges containing real technical documentation.
- Authentic photographs of the asset.
- Consistent quotes and order confirmations.
- A standard commercial flow between client and supplier.
On the surface, nothing suggested that a third party had infiltrated the communication.
2. The Attacker Infiltrates the Communication
The cybercriminal managed to access real information about the operation: machine model, amount, key dates, and negotiation status. This level of detail is not obtained by chance, but through some form of access to information.
In this type of fraud, the most common scenarios are:
- Compromise of the buying company's email.
- Compromise of the legitimate supplier's email.
- Prior access to the supplier's internal documentation (via leaks or data breaches).
The critical point is that the attacker knew exactly when and which document was expected, and seized that moment to introduce their manipulated version.
3. The Manipulated Document: The Key Piece of the Fraud
The attacker sent a PDF file that mimicked the format of the real supplier. At first glance, the document seemed legitimate: logos, structure, language, and technical content were consistent. However, when analyzing its metadata with forensic tools, the story changed completely.
Below is an excerpt of the metadata obtained with ExifTool:
ExifTool Version Number : 13.55 File Name : second.pdf File Size : 193 kB Zone Identifier : Exists File Modification Date/Time : 2026:03:26 16:02:00+01:00 File Access Date/Time : 2026:04:15 02:25:50+02:00 File Creation Date/Time : 2026:04:10 23:25:28+02:00 PDF Version : 1.7 Page Count : 5 Producer : iLovePDF Modify Date : 2026:02:26 12:56:39Z
This metadata reveals several critical points:
- The document was internally modified on a date prior to its creation in the system, indicating it was reconstructed or downloaded subsequently.
- The Producer field indicates that iLovePDF was used, a non-corporate online tool highly inconsistent with a formal corporate document flow.
- The presence of Zone Identifier: Exists indicates that the file was downloaded from the Internet, rather than being generated internally in a controlled environment.
In summary: the PDF was not an original document from the supplier, but a manipulated and reprocessed file by the attacker to introduce false bank details.
4. Impersonation via WhatsApp Business
To reinforce the credibility of the fraud, the attacker also used a WhatsApp Business profile. This profile included:
- Description in the legitimate supplier's language.
- Images of machinery related to the business activity.
- Location consistent with the supplier's country.
- Professional appearance and well-written messages.
One important detail: WhatsApp Business does not robustly verify identities. Anyone can create a profile that looks like a real company, making this an ideal channel to reinforce impersonations already initiated via email.
5. The Result: A Payment Diverted to a Fraudulent Account
With the manipulated document and the well-constructed impersonation, the attacker convinced the company to perform a transfer of tens of thousands of euros to a bank account that did not belong to the legitimate supplier. The fraud was executed cleanly, without the need for malware or particularly sophisticated techniques.
This type of attack relies more on:
- Information about the operation.
- Time to observe and act at the right moment.
- Social engineering to build trust.
- Document manipulation that is difficult to detect at a glance.
6. Lessons Learned from This Case
Several relevant conclusions for any company can be drawn from this real-world case:
- A PDF is not a guarantee of authenticity. Documents can be modified without the user noticing. Metadata analysis is key when suspicion arises.
- Identity impersonation is becoming increasingly credible. WhatsApp Business profiles, well-written emails, and seemingly legitimate documentation can deceive even experienced staff.
- BEC fraud does not always require compromising both ends. Simply having access to one mailbox or internal documentation is enough to reconstruct the operation and strike at the right time.
Ultimately, BEC fraud is not just a technical problem, but also one of processes and trust. Attackers don't always force doors open; many times they simply exploit the cracks in how we manage information and communications.
This case demonstrates that any organization, regardless of size, can be a target for an attack of this nature. Understanding how these frauds operate is the first step toward detecting them and reducing their impact.
Recovery Fraud: la estafa que persigue a las víctimas de fraude