← ATH

REGULATION · US

Business email compromise attack reroutes vendor payments via session token hijacking

Cybersecurity firm TrendAI uncovered BEC scheme where attacker hijacked session tokens to redirect vendor payments. Attack vector exploits weak authentication on payment authorization—critical for treasury and AP automation risk frameworks.

WHY IT MATTERS

As BFSI adopts AI-driven payment orchestration and RPA, BEC attacks evolve to exploit API/token layers. Compliance teams must update controls for authenticated automation risk; OCC/Fed likely to issue guidance on AI-driven fraud.

Source: PYMNTS · 2026-08-20

← BACK TO TODAY'S DECK

Business email compromise attack reroutes vendor payments via session token hijacking — ath — AITechHive