REGULATION · US
Business email compromise attack reroutes vendor payments via session token hijacking
Cybersecurity firm TrendAI uncovered BEC scheme where attacker hijacked session tokens to redirect vendor payments. Attack vector exploits weak authentication on payment authorization—critical for treasury and AP automation risk frameworks.
WHY IT MATTERS
As BFSI adopts AI-driven payment orchestration and RPA, BEC attacks evolve to exploit API/token layers. Compliance teams must update controls for authenticated automation risk; OCC/Fed likely to issue guidance on AI-driven fraud.
Source: PYMNTS · 2026-08-20