The SilverTerrier playbook: how BEC groups really target finance teams
This is an analysis piece, not an incident report. It draws on a decade of published research — chiefly Palo Alto Networks Unit 42's SilverTerrier series (2014–2022), Group-IB's work on the TMT gang (2020), INTERPOL's African Cyberthreat Assessment (2024) and the Verizon Data Breach Investigations Report (2024) — to describe how business email compromise actually reaches a CFO's desk.
The pattern
Unit 42's SilverTerrier research describes an ecosystem of hundreds of actors rather than a single gang, sustained by cheap commodity tooling: information stealers and remote-access trojans that harvest saved passwords and mailbox credentials. The DBIR has repeatedly found that the human element is involved in the large majority of breaches, and that pretexting — the social-engineering core of BEC — has grown into one of the most common attack patterns. BEC needs no zero-days. It needs one credential, one studied email thread, and one rushed approval.
How it plays out
The published casework converges on a repeatable sequence:
Harvest. Mass phishing waves — fake purchase orders, quotations, shipping documents, tender invitations — deliver credential stealers or link to counterfeit login pages. The initial victim is often not in finance at all.
Study. With mailbox access, actors read quietly, sometimes for weeks. They set auto-forwarding rules, learn who approves payments, which suppliers invoice when, and how colleagues phrase requests.
Hijack the thread. The decisive move documented across Unit 42 and Group-IB reporting is thread hijacking: replying inside a genuine, ongoing payment conversation — or spoofing a lookalike domain one character away — to announce "updated bank details" or push an urgent invoice. Every contextual cue is authentic because the context was stolen.
Cash out. Funds land in mule accounts, often opened or rented specifically for the fraud, then fragment onward within hours. INTERPOL's 2024 assessment notes the maturity of these money-movement networks across and beyond the continent.
Who it targets
CFOs, financial controllers, accounts-payable clerks and executive assistants who process payments — and, upstream of them, anyone whose mailbox touches invoices: procurement, sales administration, logistics. African organisations are targeted both as victims and as unwitting infrastructure, since a compromised African supplier's mailbox is the perfect launchpad against its overseas customers.
Breaking the pattern
- Train finance teams on thread hijacking specifically. Generic "spot the bad grammar" training fails against fraud sent from a genuine mailbox inside a real conversation.
- Make out-of-band verification mandatory for any change of bank details or urgent payment — a phone call to a known number, never a reply to the thread.
- Drill the pressure scenarios: the CEO travelling, the quarter closing, the supplier threatening to halt delivery. BEC succeeds on urgency, not deception alone.
- Protect mailboxes as payment systems: MFA everywhere, alerts on new forwarding rules, lookalike-domain monitoring for your own brand and key suppliers.
- Simulate the real lures — purchase orders, invoice updates, tender documents — so the first hijacked thread your team sees is a test.
Sources
- Palo Alto Networks Unit 42, SilverTerrier research series (2014–2022)
- Group-IB, research on the TMT BEC gang and Operation Falcon (2020)
- INTERPOL, African Cyberthreat Assessment Report (2024)
- Verizon, Data Breach Investigations Report (2024)
If your finance team has never faced a simulated thread hijack, you do not yet know your exposure — our free Human Risk Maturity Assessment is a four-minute way to find out.