WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships It Only Takes One – One Extra Letter Can be the Difference Between a Legitimate Email and Losing $1 Million
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

It Only Takes One – One Extra Letter Can be the Difference Between a Legitimate Email and Losing $1 Million

Author: Jennifer Walker

Created: Thursday, November 21, 2019 - 18:29

Categories: Cybersecurity, General Security and Resilience, Security Preparedness

The importance of scrutinizing financial-related and highly sensitive information via email cannot be overstated. In typical business email spoofing style, a scammer, as part of a multinational fraud ring, was able to defraud the CEO of an unidentified Swiss company during a real-estate transaction – an all too common trend. After two presumably legitimate communications with his attorney, the CEO received a third email with new wiring instructions for the remaining balance. The third email included the expected stuff – standard confidentiality notice, legal disclaimers, information about specific regulations on the purchase of property by a foreign company, and professional signature block with the attorney’s name and contact information. Unfortunately, the CEO did not notice the extra letter “s” hiding in the phony lawyer’s email address, and it almost cost him nearly $1 million. While this transaction was personal in nature, this scenario is a widespread trend across organizations of all types. It only takes one letter; it only takes one person – to fall for an email phishing scam that ends up costing a company thousands of dollars. Heightened awareness and a procedure for checks and balances should be required for every financial-related email. Read the post at Quartz

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar