Skip to content

CR-2026-0184 · Logistics

Invoice-redirect campaign targeting Baltic logistics suppliers

Severity
Critical
Published

Summary

An active business email compromise campaign is targeting freight forwarders and their customers across the Baltic region. The operators compromise a supplier mailbox, monitor genuine invoice threads, and inject altered banking details into an existing conversation — so the fraudulent message arrives from a legitimate address, inside a thread the recipient started.

Who this affects

Organisations receiving invoices from freight forwarders, customs brokers and 3PL providers operating in EE, LV, LT and PL.

Recommended action

  1. 01

    Verify any change of banking details by voice, using a number you already hold — never one supplied in the email requesting the change.

  2. 02

    Enforce MFA on all supplier-facing mailboxes and review mailbox forwarding rules, which the operators create to maintain visibility after a password reset.

  3. 03

    Alert finance staff specifically to changes arriving inside an existing thread, which bypass the usual 'unexpected email' instinct.

  4. 04

    Review outbound payments to newly added beneficiaries over the last 60 days.

Technical detail

Indicators and detection logic

The full technical package — infrastructure indicators, hashes, sender patterns and ready-to-deploy detection rules — goes to platform customers ahead of publication. If you are in an affected sector and not a customer, ask us and we will send this one anyway.