Supplier impersonation fraud, known as BEC (Business Email Compromise), has become one of the most profitable threats for cybercriminals. These are not mass attacks, but rather targeted, silent operations based on social engineering and document manipulation.

Article image

🔍 Suspicious message?

Analyze senders, links or files in real time with our scanner.

Analyze now

In this article, we analyze a real case in which a Spanish company suffered a €79,500 fraud after receiving manipulated documentation and seemingly legitimate communications from a foreign supplier. No sensitive data is revealed, but the key technical elements of the case are highlighted.

BEC fraud is one of the cybercrimes with the highest economic impact on Spanish companies. According to the FBI, BEC fraud generated more than 2.9 billion dollars in losses in 2023. In Spain, the National Police records a steady increase in cases every year, especially in B2B trade operations. Unlike mass phishing, BEC fraud is a targeted attack—the attacker studies their victim before acting.

1. The Context: A Legitimate Commercial Operation

The affected company was negotiating the purchase of an industrial machine from a well-known foreign supplier. The process was unfolding in a seemingly normal manner:

On the surface, nothing suggested that a third party had infiltrated the communication.

2. The Attacker Infiltrates the Communication

The cybercriminal managed to access real information about the operation: machine model, amount, key dates, and negotiation status. This level of detail is not obtained by chance, but through some form of access to information.

In this type of fraud, the most common scenarios are:

The critical point is that the attacker knew exactly when and which document was expected, and seized that moment to introduce their manipulated version.

3. The Manipulated Document: The Key Piece of the Fraud

The attacker sent a PDF file that mimicked the format of the real supplier. At first glance, the document seemed legitimate: logos, structure, language, and technical content were consistent. However, when analyzing its metadata with forensic tools, the story changed completely.

Below is an excerpt of the metadata obtained with ExifTool:


ExifTool Version Number         : 13.55

File Name                       : second.pdf

File Size                       : 193 kB

Zone Identifier                 : Exists

File Modification Date/Time     : 2026:03:26 16:02:00+01:00

File Access Date/Time           : 2026:04:15 02:25:50+02:00

File Creation Date/Time         : 2026:04:10 23:25:28+02:00

PDF Version                     : 1.7

Page Count                      : 5

Producer                        : iLovePDF

Modify Date                     : 2026:02:26 12:56:39Z

  

This metadata reveals several critical points:

In summary: the PDF was not an original document from the supplier, but a manipulated and reprocessed file by the attacker to introduce false bank details.

4. Impersonation via WhatsApp Business

To reinforce the credibility of the fraud, the attacker also used a WhatsApp Business profile. This profile included:

One important detail: WhatsApp Business does not robustly verify identities. Anyone can create a profile that looks like a real company, making this an ideal channel to reinforce impersonations already initiated via email.

Article image

5. The Result: A Payment Diverted to a Fraudulent Account

With the manipulated document and the well-constructed impersonation, the attacker convinced the company to perform a transfer of tens of thousands of euros to a bank account that did not belong to the legitimate supplier. The fraud was executed cleanly, without the need for malware or particularly sophisticated techniques.

This type of attack relies more on:

6. Lessons Learned from This Case

Several relevant conclusions for any company can be drawn from this real-world case:

Ultimately, BEC fraud is not just a technical problem, but also one of processes and trust. Attackers don't always force doors open; many times they simply exploit the cracks in how we manage information and communications.

This case demonstrates that any organization, regardless of size, can be a target for an attack of this nature. Understanding how these frauds operate is the first step toward detecting them and reducing their impact.

Recovery Fraud: la estafa que persigue a las víctimas de fraude

The Second Scam: When Fraud Chases You After Being a Victim