Invoice-redirect campaign targeting Baltic logistics suppliers
- Critical
An active business email compromise campaign is targeting freight forwarders and their customers across the Baltic region. The operators compromise a supplier mailbox, monitor genuine invoice threads, and inject altered banking details into an existing conversation — so the fraudulent message arrives from a legitimate address, inside a thread the recipient started.
Who this affects
Organisations receiving invoices from freight forwarders, customs brokers and 3PL providers operating in EE, LV, LT and PL.
Verify any change of banking details by voice, using a number you already hold — never one supplied in the email requesting the change.
Enforce MFA on all supplier-facing mailboxes and review mailbox forwarding rules, which the operators create to maintain visibility after a password reset.
Alert finance staff specifically to changes arriving inside an existing thread, which bypass the usual 'unexpected email' instinct.
Review outbound payments to newly added beneficiaries over the last 60 days.
Indicators and detection logic
The full technical package — infrastructure indicators, hashes, sender patterns and ready-to-deploy detection rules — goes to platform customers ahead of publication. If you are in an affected sector and not a customer, ask us and we will send this one anyway.