When the Bank Calls: What a $151,000 Cyberattack Can Teach Dealers
August 12, 2026
The following is a true cyber breach story (no, it’s not becoming a TV series); however, the learnings of what to do and, more importantly, what not to do when a breach happens affect all dealer owners.
I am Tony Haux, the CTO and CISO at Accelerate2Compliance. Bob was not a customer of ours, but he is a very good friend of mine. His name is not actually Bob. I happened to call him about a month ago to say hi, and he relayed the following situation to me.
The Case Study in Four Parts:
- Part One: The Breach
- Part Two: The Aftermath
- Part Three: Prevention
- Part Four: Document Your Response Before the Attack
PART ONE: THE BREACH
“Ring, ring, ring”
“Hello”
“Hello Bob, this is Tom from your business bank. I wanted you to know that your checking balance is down to a couple hundred bucks, and you have check transactions arriving for more than that”
Bob is stunned. His head has been fully engulfed in his commercial construction project 7 days a week, and although he was busy, he was certain the account had over $100,000 in it based on the current activities.
He places a frantic call to his accountant, a person not within his company’s employ.
She had been dutifully making his payments on invoices as instructed, many of them emailed to her.
They began looking backwards and found a large invoice for $59K last week, another one for about $40K a week before that, another for about $30K a week before that, and another around $20K. All were paid by ACH out of Bob’s company’s checking account by the accountant.
Bob was again stunned; these were not anything he knew about or submitted. The accountant said, “Yes, you did; here are the emails”. Again, Bob looked at the emails she had received; they came to her email inbox from the email address that matches Bob’s email.
No plan. Panic. Angry. “You have to fix this!” Both sides immediately pointing fingers at each other.
Bob calls the bank back, frantically hoping they will be able to reverse the funds back from the destination accounts.
$151,000 is currently gone at a very bad time.
At this point, damage appears to be done, but there was a chance to chase after the funds in hopes of a recovery or claw back from the receiving accounts.
PART TWO: THE AFTERMATH
Bob and his business partner have an unhappy discussion, and they simply call their lawyer, who they think will begin to pressure the accounting firm to make this right. The problem is the emails received by the accounting firm, which would appear to be the argument in court, “I was instructed to pay….”
Lawyers on both sides are now engaged. No calls yet to the FBI or state’s attorney. Both sides essentially stop talking to each other on this subject.
Would have, should have, could have. Hindsight on an ugly situation like this is haunting. Was Bob or the accountant lazy, ignorant, careless, gullible, cavalier? Probably all of these.
What happened was an event called spear phishing. Spear phishing is a targeted form of phishing in which an attacker crafts a highly personalized message to trick a specific individual or organization into revealing sensitive information, clicking a malicious link, opening an infected attachment, or authorizing a fraudulent transaction.
The attacker knew about the relationship between the accountant and the business owner and, using an email, tested the water by sending a simple Microsoft Word invoice template for the $20K amount to the accountant from what looked to be the owner’s email address. She paid it as instructed in the email. It took her multiple ACH transactions as her authority on the account limited her to $10K increments – so she sent 2 of them to pay the bill.
Time goes by, no one notices it to be a problem. The attacker has succeeded and is going to draw more blood. A week or so later, they send another email to the accountant, appearing to be from the owner with another invoice, a different company, a different bank account ACH , about $30K. She pays it with 3 ACH transactions of $10K. Still no problem for the attacker; money is flowing. They get bolder; they do it again this way for $40K, and lastly for $59K. All go through, all are paid. No alerts, no comments.
By the time the bank is asked, they are unable to recover (reverse) the transactions as too much time had passed.
PART THREE: PREVENTION
Authentication. The information security world preaches that you should use two-factor authentication for all your accounts for access and control. In this case, a method of communication between the accountant and owner should have been in place to authenticate such large transactions – a call, or better yet a text message, would have been beneficial for reconciling what happened when, authorized by whom. A large construction company may have many large bills to pay, but the time taken by the accountant and owner would have been less than a minute total for each event. Had they had this process in place, there would not have been one dollar sent to the hacker’s account.
Monitoring. It is not atypical to have text notifications delivered to a bank account owner for transactions over a certain threshold, or when your account balance goes below or above a set amount. Seeing an unexpected $10K transaction go through would have brought attention to the first event, and there would have been a good chance to reverse the ACH; not certain, but at least probably. The owner did not have notifications on.
Training. Had both parties been trained and experienced in information security, they would have considered the risk and would have deployed the authentication above, and the monitoring.
Wasted opportunity. Contacting the FBI and the state attorney’s office may have brought the cybersecurity and finance fraud units to bear on the problem to possibly locate the money and better yet the perpetrator. Every minute that passes means the attacker can move the money and disappear – possibly moving the money immediately into a bitcoin account or digital currency account, making tracing essentially impossible. Immediate action, as in right away, may have helped at the first event, and now weeks after the last event it is almost certainly a waste of time – except to figure out how the emails occurred
Hacker technology. Back to the emails. Did Bob send them or not? One might think his account was hacked and emails were sent by his account? Well, hacker tech doesn’t need an account or credentials to spoof his email account (spoofing in this sense is getting an email to arrive at the recipient inbox with a from email address that matches the person the attacker is pretending to be). Hacker tech simply uses a hostile environment to create an email server that will send the message to the targeted recipient, sending it in as though it is actually the sender’s email address. Advanced email services also have abilities to thwart emails appearing to be delivered from an email server that is not the true host for the email domain of record.
Hacked credentials? There is a good possibility that one of the two parties had their email accounts hacked, their credentials known (likely bought on the Dark Web). With that, the hackers had the observation to know how the two parties communicated and pay bills. Complex passwords and unique passwords per account are the secure way to resist attacks. Protect your email password as the most important password you own. Your email account is typically the pathway to getting into “all” of your accounts everywhere, especially since it is used to reset passwords on those accounts.
Logging into one’s email account covertly to monitor the emails is possible, as many email systems have little to no notification of such activity – and if the hacker is “in” they can monitor for such notifications and delete them (and delete them out of the trash folder) so the person hacked never knows it.
PART FOUR: DOCUMENT YOUR RESPONSE BEFORE THE ATTACK
Incident response plan. Any good information security program would have the organization creating an incident response plan that would outline what the business should do in the event of an incident, a data breach, or a fraudulent financial event. The plan would lay out who is being brought into the issue, to do what, to remediate the situation, and to minimize the damage or possibly to repair it altogether. Knowing what to do and who to call right away is always extremely helpful when minutes and days matter.
The two firms will now be in a pitched legal battle, spending thousands of dollars that may be unlikely to be recovered from the other party. Worse yet, the original stolen money is not being chased after and most likely will not be recovered.
The lesson is that good information security training and preventative procedures create a secure environment to prevent or stop hostile events, including fraudulent transactions.
Tony Haux
CTO/CISO, Accelerate2Compliance
Why A2C?
Compliance is an incredibly complicated topic, but our solution is the opposite of complicated: it’s just simple. We take the complexities of information security compliance and simplify them, so you can know what you need to do, do it efficiently, then get back to doing what you do best. You’ll get everything you need from us, and that’s all – you will not be paying for extras you DON’T need. We know what we’re doing. As you begin your information security compliance journey with A2C, you can rest assured you’ll be headed down the road to compliance.
Let's Talk
Still need help? Let’s talk! You’ll learn how easy our product is to use and scale, and how we can save you time, money, and stress.
Address:
4737 County Road 101, Suite 146
Minnetonka, MN 55345
Sales:
[email protected]
Support:
[email protected]
