Skip to main content
Transportation & Vocational Education100+ Users, Multi-State

The Attack Came Through the 95% They Weren't Protecting

A multi-state commercial truck driving academy ran enterprise security tooling on five of its 100+ employees — the users a customer contract happened to cover. Attackers found the gap, compromised accounts payable, and went after $25,000. Here is how it was stopped, and what it cost to learn.

$0

Lost to a $25,000+
Fraud Attempt

5 → 100+

Users Under
Full Protection

Minutes

From Detection to
Account Lockdown

1

Unified Policy Across
All State Branches

On transition friction: this was not a migration. The platforms were already deployed and running correctly in the academy's own environment — on five users. Extending them across the remaining 95+ meant rolling out a configuration already proven in production, not introducing an unfamiliar stack to a workforce spread across state lines.

The Threat This Sits In

Context matters for judging whether $25,000 is a big number or a small one. Business Email Compromise is, by reported dollar losses, the most financially destructive enterprise-targeted cyber threat in the United States. The FBI's Internet Crime Complaint Center recorded $2.77 billion in BEC losses across 21,442 incidents in 2024, rising to $3.046 billion in 2025 — ahead of ransomware by a wide margin.

It carries no malware

No payload for antivirus to catch, no attachment to detonate, no known-bad domain to block. The attack is a well-written email. Every control designed to detect malicious code is structurally blind to it.

It targets process, not technology

The attacker studies how you approve and execute payments, then inserts a small, plausible change at exactly the moment a payment is expected. The request looks like work because it is work — with one field altered.

The money is usually gone

Wire transfers are fast and largely irreversible. Unlike ransomware, where you can restore from backup, a successful BEC is a completed theft. Recovery depends on catching it within hours.

Before

Security Rationed to the Users a Contract Required

The academy was not unprotected. It was selectively protected. Endpoint detection, remote monitoring, and advanced email security were all deployed — to five users. Those five sat under a major logistics customer's vendor security requirements. To keep that contract, the academy had to demonstrate specific controls on the people touching that relationship. So they deployed those controls, precisely and exactly, to those five people.

The other ninety-five-plus employees had none of it.

It is worth being fair about this, because it is not a story about negligence. The academy was not skeptical that security worked — they had already bought it, deployed it, and were running it successfully on the users a contract required. They were rationing it. The scope of the deployment was set by the contract, not by the risk.

This is the single most common security posture in the mid-market, and it has a specific structural flaw: the coverage boundary is drawn by whoever happens to be auditing you, not by where your money and data actually live. A customer's vendor requirements are designed to protect that customer's interests. They are not designed to protect your payroll, your student records, or your accounts payable process. And an attacker does not target the five people a contract covers. They target the accounts payable process.

The Incident

How It Actually Unfolded

1

The attacker got in through the unprotected 95%

The compromised account belonged to the accounts payable clerk — not one of the five covered users. Of every account in the organization, the attacker landed on the one that touches outbound payments. That is not luck. AP is the destination in nearly every BEC campaign, because AP is where the money leaves.

2

The compromised account emailed inside the organization

Working from a legitimate internal mailbox, the attacker sent mail to a colleague — and that colleague was one of the five users who did have advanced email security coverage.

3

That is where it stopped

The internal message hit an inspected mailbox, the activity surfaced, and Vigil Cyber shut the compromised account down almost immediately.

4

The wire never happened

Zero dollars moved.

Why This Sequence Is the Whole Argument

Read that chain again, because it is effectively a controlled experiment the organization ran without meaning to. Same company, same day, same attacker — one population protected, one not.

The attack succeeded everywhere there was no coverage, and died the instant it touched coverage.

There is a second, more technical lesson stacked on top of it. The message that got caught was internal. It went from one employee's mailbox to another employee's mailbox, inside the same tenant. It never crossed the network perimeter — which means a traditional secure email gateway would not have seen it at all. Gateways inspect mail entering and leaving the organization, so an attacker operating from a compromised internal account can move laterally through the entire company completely unobserved.

API-based email security inspects internal east-west mail because it sits inside Microsoft 365 rather than in front of it. That architectural difference is not a specification detail. In this incident it was the difference between a $25,000 loss and a zero-dollar one.

No Single Product Caught This

Three things had to work in sequence. Any one of them alone would likely have missed it.

The technology

Flagged internal mail that a perimeter product would never have inspected.

The humans

A workforce conditioned by ongoing phishing simulation to treat anomalous internal requests as reportable rather than routine.

The analysts

Investigated what surfaced and disabled the account in minutes rather than filing it for review.

Detection without fast response is just a well-documented loss. A fast response nobody triggers never happens at all. The organizations that lose the money are not the ones with a bad product — they are the ones with exactly one layer, or with good layers covering five percent of their people.

The Human Layer

Building a Workforce That Verifies

Technology stops technical exploits. It does not stop a competent social engineer talking to a helpful person on a deadline — and BEC is a social engineering attack wearing an email as a costume. The academy's staff had to become a control, not a liability.

Continuous conditioning

The entire 100+ user workforce runs managed, quarterly phishing simulation campaigns. The cadence is the point — annual training produces a spike in awareness that decays within weeks, while quarterly simulation against evolving lures maintains recognition as a reflex. Staff are trained not just to avoid clicking, but to report, which turns every employee into a sensor.

Annual security summits

Once a year, a comprehensive deep-dive covering compliance obligations, data handling, and the current threat landscape. A mobile instructor and a branch manager face different threats and hold different data — the summit addresses each rather than issuing generic advice aimed at an office worker who does not exist in this organization.

The proof that isn't a number

The strongest evidence this program works did not come from a dashboard. It came from the chief executive. He received a routine, entirely legitimate reminder to finish his assigned phishing awareness module. Before clicking anything, he stopped and asked one question:

"Is this legit?"

— CEO, on a genuine internal email, with no simulation running

The distinction matters more than it first appears. A simulation click rate measures how staff perform on a test, and people behave differently when they suspect they are being scored. This was not a test. There was no campaign running, no score attached, nobody watching. It was an ordinary Wednesday, an ordinary email, and the most senior person in the organization treated an unexpected request to click a link as something to verify rather than something to do.

That is the behavior every security awareness program claims to produce and very few actually deliver. It is also the behavior that stops a Business Email Compromise, because BEC does not arrive labeled as an attack. It arrives looking exactly like this: routine, plausible, mildly time-pressured, from a name you recognize. An executive who verifies before clicking is the control that would have stopped the $25,000 attempt on its own.

What Was Actually Deployed

Email security

Check Point Harmony (Avanan)

API-based inspection of inbound, outbound, and internal mail; behavioral BEC detection; post-delivery remediation.

Endpoint detection & response

Datto EDR

Behavioral detection and containment at the endpoint.

Remote monitoring & management

Datto RMM

Patch and configuration management across every branch.

Microsoft 365 management

CIPP

Identity configuration, conditional access, and tenant-wide policy applied uniformly rather than drifting per site.

Security awareness

Managed program

Quarterly phishing simulation campaigns plus an annual deep-dive security summit.

Incident orchestration

Vigilance HQ Service Desk

Single system of record and response queue across all state branches.

Scope is the story. Nearly all of this was already in the environment before the engagement expanded — running correctly, on five people. The intervention that mattered was not procurement. It was extending coverage to match the actual shape of the business.

Business Outcomes

Zero financial loss

A live, targeted wire fraud attempt of $25,000+ was intercepted before funds moved. Not detected afterward. Not recovered. Stopped.

Coverage expanded from 5 users to 100+

Protection is now scoped to where the business’s risk actually sits, rather than to the boundary a customer contract happened to draw.

A workforce that verifies

The CEO now stops and confirms unexpected click requests before acting — on genuine mail, with no simulation running. That is the behavior that stops BEC.

Multi-state standardization

Every remote and branch user operates under a single, uniformly enforced security policy regardless of location.

Full-spectrum email visibility

Internal, inbound, and outbound mail is inspected, eliminating the lateral-movement blind spot inherent to gateway-based filtering.

Reduced support load and faster onboarding

Day-to-day IT burden decreased, and new staff and locations can be brought onto the platform quickly and consistently — which matters for an organization in active expansion.

Why This Matters If You Run a Distributed Business

This academy's situation is the default condition for any organization with multiple locations, mobile staff, and money moving over email — construction firms, healthcare groups with satellite clinics, professional services with branch offices, logistics operators, franchise networks.

1

BEC does not care how good your antivirus is

There is no malware to detect. The attack is a well-written email arriving at a plausible moment. Defending against it requires behavioral and contextual analysis, not signature matching — and humans trained to treat payment changes as inherently suspicious.

2

Gateways cannot see internal mail

If your email security sits in front of your mail flow rather than inside it, a compromised internal account can phish every colleague without a single message crossing the inspection point. Ask your provider directly whether internal east-west mail is inspected. Many cannot say yes.

3

Let risk set your coverage boundary, not your largest customer’s audit

A customer’s vendor security requirements are designed to protect that customer. They say nothing about your payroll, your records, or your accounts payable process. An organization that secures only what its biggest contract audits will pass that audit and remain exposed everywhere the audit does not look — which is where the attacker will be.

4

One layer is not a program

No single product caught the $25,000 attempt. Trained users, email analysis, and human analysts caught it together. When evaluating security spend, the question is not "is this tool good?" It is "what happens when this tool is the thing that fails?"

5

Distributed operations fragment security posture by default

Without deliberate centralization, every site drifts toward its own configuration, its own exceptions, and its own blind spots. This gets worse during growth, because every shortcut taken to stand up a new location quietly becomes a permanent exception.

The Honest Version of This Story

Case studies tend to describe clients who were doing everything wrong until a vendor arrived. That is not what happened here, and the real version is more useful.

This organization had already bought good tooling. They had deployed it correctly. They were running it successfully. Their security posture failed for a reason that has nothing to do with product selection and everything to do with scope — they had drawn the boundary where a contract told them to, rather than where their risk actually lived.

That is a decision thousands of competent, well-run mid-market organizations are making right now, for entirely rational-seeming reasons. It is not incompetence. It is a category error about what security spending is for: treating it as a cost of satisfying customers rather than as a control protecting the business. The attack found the boundary. It usually does.

Ready to Reduce Risk?

Need cybersecurity support or a secure AI build?

We can review the security controls protecting your data, users, and Microsoft 365 environment, then help scope secure AI applications or workflows where they make sense.