Journalist warns of costly scam: 23,000 euros lost instantly
Translated from Croatian, summarized and contextualized by DistantNews.
TLDR
- A sophisticated phishing scam cost a Croatian company 23,000 euros.
- The victim, an experienced procurement director, was tricked by an email that mimicked a long-time supplier, changing the bank details.
- The scam succeeded due to a subtle difference in the sender's domain name (.com.hr instead of .hr), highlighting the vulnerability of even experienced professionals to targeted attacks.
As Veฤernji List, we feel it is our duty to alert the public to the increasingly sophisticated threats lurking in the digital realm. The recent case involving the loss of 23,000 euros due to a cunning phishing scam serves as a stark reminder that no one is immune. The victim, a procurement director with 15 years of experience, exemplifies how even seasoned professionals can fall prey to well-crafted deception. This wasn't a simple hack; it was a targeted attack exploiting trust and a moment of inattention.
Despite checking the information three times, she did not notice the crucial difference: the email did not arrive from the original domain dobavljac.hr, but from an almost identical address dobavljac.com.hr.
The perpetrators masterfully mimicked a trusted supplier, using a familiar signature, logo, and communication style. The critical detailโa near-identical domain nameโwas easily overlooked, especially when the email purported to announce a change in banking details. This highlights a disturbing trend: cybercriminals are increasingly focusing on social engineering, preying on human psychology rather than solely on technical vulnerabilities. Companies, with their larger financial flows and complex internal processes, are particularly attractive targets, offering multiple points of entry for attackers.
Scammers are increasingly targeting people, especially those who believe they are experienced enough not to be fooled. Precisely such people become ideal targets.
This incident underscores the need for constant vigilance and robust security protocols, not just for IT departments but for every employee. The rise of deepfake technology and impersonation tactics, even via video calls, means that verifying identities and transactions has become more critical than ever. We urge businesses and individuals alike to be skeptical of urgent payment requests, to meticulously check sender details, and to implement multi-factor verification processes. In Croatia, as elsewhere, staying ahead of these evolving threats requires continuous education and a proactive security mindset.
Companies are often more vulnerable than individuals because they have larger sums of money, more employees involved in processes, and more potential points that attackers can exploit.
Originally published by Veฤernji List in Croatian. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.