A medium-sized commercial electric company learned there are many ways to lose money when attackers are creative. One of its electricians became alarmed when his payroll wasn’t processed. He contacted the HR department, and it quickly became clear that someone else had walked away with his paycheck. Hackers had infiltrated his email, were able to communicate with HR, and request changes to his payroll processing, sending his and the company’s money to a foreign entity. The money was not recoverable. Active logging of email accounts would likely have identified this compromise. Login attempts inconsistent with normal user behavior, such as logging into email simultaneously from two geographic locations, would have triggered an actionable alert. The company has since implemented training routines and logging to help mitigate these risks in the future.

