Atestan Atestan

Where one unauthorised request becomes an expensive event


01

One root, many frauds

Every fraud below works the same way: someone impersonates a trusted party to trigger an action — a payment, a change of details, the acceptance of a document. They are one problem wearing different clothes.

$55bn+

Cumulative exposed losses from business email compromise reported to the FBI’s Internet Crime Complaint Center, October 2013 – December 2023. “Exposed loss” is IC3’s own measure and counts both attempted and actual losses.

Source: FBI IC3, “Business Email Compromise: The $55 Billion Scam”, 11 September 2024 — ic3.gov/PSA/2024/PSA240911. Verified 3 September 2026.

Exact figure: $55,499,915,582 across 305,033 incidents.

A measure of the pain, not of a market. We size the market from real buyers, never from a headline.

Nine situations, one shape: the channel is authentic and the instruction inside is not the organisation’s. Each card says what can be established TODAY — and each of those answers is bounded by the same fact: the questions are built, and no organisation is enrolled.

02

Nine names, one question

Open the situation you are in.

  1. An urgent, confidential transfer ordered by someone who writes exactly like your CFO.

  2. A real supplier relationship, a payment quietly redirected elsewhere.

  3. The narrow, high-ROI case we start from — because it is the easiest to explain and the fastest to prove.

  4. Plausible documents, correct amounts, the wrong account.

  5. A signature that looks right on a document nobody authorised.

  6. Funds diverted at the exact moment a property transaction settles.

  7. An employee’s salary account changed by someone who is not the employee.

  8. A fraudster has a false change of director registered at the company registry. He obtains a company registry extract in his name, presents himself to the bank as the new manager, and has the bank details changed or orders transfers. The banker has a document in good order before their eyes; nothing, on paper, contradicts it.

  9. The same move, another counter. The fraudster has himself registered as manager of a company that holds a property, then sells the property before a notary who also sees a company registry extract in good order.

The same question settles all of them — and it is a cryptographic question, not a judgement call.

03

The telephone check that complements the proof

For bank-detail changes above all: call the supplier on a number you already had — never the number in the request — and confirm one field with the dictated code. The code reveals nothing by itself; it confirms, it does not disclose.

CEO fraud, supplier impersonation, a redirected payroll, a closing account changed at the last minute — the attacker’s work is the same each time: make an unauthorised request look ordinary. The question that separates them from a real one does not change either: what evidence exists for THIS request?