Case Background
This case involves two international freight forwarding companies: Logistics Company A in Vietnam (hereinafter referred to as “Company A”) and Logistics Company B in Cambodia (hereinafter referred to as “Company B”). In 2025, the two parties signed an agency agreement under which Company B, acting as the destination agent, was to provide customs clearance and trucking services from Vietnam to Cambodia for Company A. In the normal course of business, Company A was required to pay Company B total service fees of approximately USD 8,500. However, a payment intended to settle the outstanding amount was ultimately remitted to an overseas account controlled by fraudsters due to a hacker-led email spoofing scheme, triggering a dispute between the two companies that lasted for several months.
Case Details
1.Fraudulent Intervention: Spoofed Email Sent to Falsely Notify Account Change
During the fee settlement process, the fraudsters used technical means to register a fake domain name highly similar to Company B’s official email domain and created a spoofed email account that closely resembled Company B’s legitimate email address, with only minor character differences that were easy to overlook. They then sent an email to the finance department of Company A, falsely claiming that Company B’s original bank account had been temporarily suspended due to a tax audit and instructing Company A to remit the service fees to an overseas bank account provided by the fraudsters.
2.Lack of Risk Control: Transfer Made Without Verification
After receiving the email, Company A’s finance staff failed to follow basic Risk Mitigation procedures for payment processing. They neither contacted Company B’s official representative or finance personnel through independent communication channels such as telephone, WeCom, or overseas social communication tools to verify the information, nor checked the official bank account details specified in the cooperation agreement. Instead, relying solely on the instructions in a single fraudulent email, they completed the full payment to the fraudsters’ fake account.
3.Exposure of the Issue: Non-Receipt of Funds Triggered a Dispute
After the agreed payment deadline passed, Company B had still not received the service fees and promptly sent a payment reminder to Company A. Company A’s finance staff responded that the payment had already been made and provided the bank remittance slip. Upon review, Company B found that the beneficiary account information shown on the remittance slip was completely different from its official account details and immediately informed Company A that it had fallen victim to fraud. A serious dispute over fee settlement then arose between the parties.
4.Dispute Over Liability: Recovery of the Funds Proved Difficult
After the dispute arose, Company B maintained that it had completed all services as agreed and had never sent any account change notice. It argued that full responsibility for the misdirected payment rested with Company A for failing to fulfill its basic verification obligations, and demanded immediate payment of the service fees. Company A, however, refused to make a second payment on the grounds that Company B’s email had been spoofed and that Company B had failed to properly manage its information security.

Analysis of the Fraud Tactics
- Precise Timing: The hackers illegally monitored the email communications between the two parties and identified the exact timing of the upcoming payment.
- Identity Forgery: They registered a highly similar fake domain name and spoofed the sender’s email address.
- Information Tampering: After the genuine invoice had been issued but before the payment was executed, they sent a forged “account change” notice.
- Urgency Pressure: They used words such as “urgent” and “payment required today” to pressure the other party and leave no time for verification.
Key Risk Control Alerts
1.Secondary Verification Before Payment Is the Most Effective Safeguard Against This Type of Fraud
For critical information involving fund transfers, such as account change notices and payment instructions issued by a business partner, confirmation through a single email channel alone is strictly prohibited. A second verification must be conducted through the company’s official landline or other designated offline or independent online communication channels agreed upon by both parties. The payment process may only be initiated after the information has been confirmed as accurate.
2.Strengthen End-to-End Corporate Information Security Protection
Companies should enhance the security management of official email accounts, financial systems, and office systems by implementing strong login passwords and enabling two-factor authentication; conducting regular system vulnerability scans and version upgrades; and applying unified security controls to employee work devices to prevent phishing links and malware intrusion.
3.Improve Risk Control Clauses in Cooperation Agreements
When signing contracts with business partners, companies should clearly define the formal process for account changes. Any account change must be supported by an official written notice bearing the company’s official seal and must be signed and confirmed by the legal representatives of both parties or their duly authorized representatives.
Alert
Cyber fraud can penetrate every weak point, and a single lapse may result in irrecoverable financial loss. Please make “mandatory verification for any account change” a non-negotiable rule in business cooperation to ensure effective Risk Mitigation before problems arise.

Last
Loss Alert: A Bill of Lading Mistake in Cross-Border Logistics Led to Total Loss of Cargo and Payment | JCtrans Credit Risk Awareness Month – Risk Control Case Study
��Z�

Next
Core Risk in Cross-border Logistics: No Cargo Pickup at Destination, Escalating Charges and Liability Exposure — A Risk Control Guide for the Industry
��Z�




