In the first of our ‘What Could Go Wrong’ posts, we share a story to make you think about the importance of having a Supply Chain Assurance process within your organisation. All names and locations have been changed in this story (except mine) to protect all parties, though the story itself is 100% true and happened around 7 years ago.
There are certain words you don’t want to hear when you’re realising your organisation might have been compromised:
“What do you mean you don’t know about this invoice? I’ve just paid it!”
Let me share a little of how we got here . . .
I was driving back from Colchester (on a Friday afternoon), having sat in a meeting room for an hour, only to be told the person I was supposed to be meeting had been called away unexpectedly. This was after they called the meeting the day before! So my day had already been below average when all this happened. Turns out the hacker knew today was a good day to try and take advantage of us.

Anyway, back on the A1 heading north (possibly M11 still at this point) and my phone rings.
Sarah – “Richard, sorry to bother you, I know you’re in a meeting but this payment won’t go through. I know it’s urgent, but the bank is saying the account name doesn’t match and it has to because it is over £10k”
Me – “Hi Sarah, you sound stressed, what payment are you talking about?”
Sarah – “Err . . the invoice you have been emailing me about this morning! What do you think I’m talking about!?”
Me: “Sorry, I don’t know what you’re talking about Sarah, are you sure . . hang on I don’t know about any invoice!?”
Sarah: “What do you mean you don’t know about this invoice!? I’ve just paid it!”
At this point, the penny dropped. Some kind of hack or compromise was taking place, I didn’t know if it was social or technical so I told Sarah to turn off her machine and call me back from her mobile, as at this stage I didn’t know if the phone system had been compromised (it hadn’t) so I needed to talk her through a few emergency steps.
The first step according to our non-existing emergency response strategy (that I made up with Sarah on the phone as it was happening) was to call the bank and ask them to freeze and cancel all outbound payments made that day.
I then talked Sarah through how to unplug her PC from the network so we could try and diagnose what had gone wrong. We talked through her emails, and she made a few phone calls to verify some information. Turns out we had not been technically compromised, but we had nearly suffered a social hack due to a compromise at one of our suppliers. Here is a breakdown of what happened:
Here are a few things to look out for to recognise a phishing attempt:
- Grammar and Spelling Mistakes
- Generic Greetings and Urgency
- Requests for Personal Information
- Unusual Sender Email Addresses
All organisations are vulnerable to phishing, no matter their size or sector, so it’s essential to understand how you might be targeted and what you can do to prevent a breach.
Fake Email
[Spot the keywords here] Sarah had received a series of emails from “me” stating that an invoice was going to come through from one of our server hosting providers and that it was “urgent” and needed to be paid “straight away” or a considerable portion of our customer base was going to go “offline”. The email from ‘me’ also said something about it being “unbudgeted” but it was an “emergency”, and we would “talk about it next week”.
Genuine Compromise
The email from our supplier was genuine though, which after a few phone calls we established was because one of their Office 365 user accounts had been hacked (because they didn’t have 2FA enabled). To make matters worse it was one of their part-time bookkeeper accounts that worked at home, so it hadn’t been spotted for a few days. The hackers had waited for the last Friday of the month when things are busiest for finance teams, to increase the urgency and make the payment demand look more genuine.
The Combined Hack
After a few days of investigating it became apparent that the fake email from ‘me’, was from an account that looked very similar to mine, along with my actual email signature that the hacker had copied from an email I had sent this bookkeeper previously. They then created a completely fake invoice with their own bank details and sent it to Sarah in our finance team. The combination of ‘my’ emails and the supplier’s email convinced Sarah that the email and invoice were both genuine and urgent.
The only reason the payment didn’t go through was that the bank had recently introduced the account name verification checks for payments over £10k, other we would have lost nearly £20k!
We introduced several changes to our processes after this happened. Including grading our suppliers according to their risk and the level of assurance they could give us around their cyber security.
Since entering the world of cyber security, I have begun to understand this as Supply Chain Assurance, which my colleagues and I often work with our clients on.

