CASE STUDY
BEC Attack in Progress, Stopped in 4 Hours: How The Lovely Works Escaped Without Major Losses
The situation
BEC (business email compromise) is the most expensive type of attack on companies this size: it does not break firewalls, it breaks people, through an email that looks legitimate. When The Lovely Works contacted us, the attack was a certainty: the attackers already had active access to the email systems, and there were signs that financial fraud was being prepared.
In moments like these, every hour counts double: for as long as the attackers have access, they can read, redirect, and impersonate - and the damage grows quietly, not spectacularly.
What we did
1. Isolation and removal (4 hours): we identified the compromised accounts and access points and removed the attackers from the systems - priority zero, ahead of any analysis.
2. Investigation: how they got in, how long they had access, what they touched - so we would know what was truly compromised, not what we hoped was not.
3. Improvements: MFA everywhere, payment verification procedures, anti-phishing training - so that the same attack, attempted tomorrow, dies at the first step.
Results
- Access removed within 4 hours of taking over the case
- No major losses - operations resumed in 2 days
- Systems and people prepared: MFA makes the same attack incomparably harder to repeat
- Fraud avoided: 300,000 EUR
What this means for your company
Over 90% of attacks start with an email - the question is not whether someone in your company will receive one, but what happens in the first hours after the click. An incident handled correctly in the first hours costs days of recovery; one handled chaotically costs weeks, plus money, reputation, and clients.
“We had a serious case of business email compromise - someone hacked our email. When something like that happens, it is serious; a company can shut down over it. Daniel from HIFENCE solved the problem in the first hours, better than either of the two providers we had worked with before: he went straight to the core of the problem and left us with clear standards for security and for how we work over email from now on.
“When you have problems like this, you need to know who the person is, not talk to someone at random online. You work with someone you know (you know their face, you know who they are) and you feel safe.”
— Andrea Heatherington, Owner & Senior Producer, The Lovely Works
Schedule a free consultation
Talk to us before you need us in emergency mode.
More case studies
Studiu de caz
70k EUR
annual savings
A security audit showed that a media company was paying ~6,000 EUR per month for protection that no longer matched its reality. The money was redirected toward measures with real impact: a better security posture, on a smaller budget.
Studiu de caz
200 hours
recovered every day
A WiFi network that had grown organically was causing more than 100 operators in a manufacturing company to lose a combined 200+ hours per day. After an audit and a redesign, the time was recovered in full - the equivalent of the work of ~25 employees, without a single new hire.
Studiu de caz
6 weeks
for a complete IT takeover
The only person who had managed a distribution company’s IT for 8 years left with 30 days’ notice, without leaving behind any documentation. We took over everything without a single day of interruption, and today any system can be managed based on documentation, not on one person’s memory.