Credential Phishing and Vendor Payment Fraud at a Regional Credit Union: A Threat Model, Control Selection, and Residual Risk
Student Name
College of Business and Information Technology, University of Phoenix
CMGT/433: Cyber Security
Instructor Name
Month Day, Year
The Organization and the Scope of This Analysis
Cascade Ridge Credit Union is a composite built for this paper and does not describe a real employer. It runs 11 branches in two states, employs 240 staff, and serves about 96,000 members. Email, files, and sign-in all sit in one cloud tenant. Accounts payable is three people who release roughly 640 vendor payments a month, 27 of which move by wire and average 48,000 dollars. Twelve of those wires go to construction and technology vendors whose banking details change often enough that a change request does not look strange when it arrives. Security staffing is two analysts inside a four-person help desk, and no one watches alerts overnight.
The scope here is narrow on purpose. This analysis covers one threat, the theft of employee sign-in credentials by email and the use of that access to redirect a vendor payment, and it stops at the edge of the payment process. Member-facing online banking fraud, card skimming, and branch physical security are all real exposures and none of them are treated here. The narrowing is a choice about evidence rather than convenience, because the credit union's own numbers point at this threat. In the last simulated phishing exercise, 34 of 240 employees opened the message and 10 typed credentials into the fake sign-in page, a 4 percent submission rate concentrated in branch operations and accounts payable.
Threat Model: Credential Phishing to Vendor Payment Redirection
The threat modelled here is business email compromise that starts with credential phishing. It was chosen because it is both frequent and expensive at this size of organization. The Internet Crime Complaint Center recorded 21,489 business email compromise complaints in 2023 with adjusted losses above 2.9 billion dollars, second only to investment fraud in the categories it tracks (Federal Bureau of Investigation, 2024). Breach data for the same period puts a human element in 68 percent of the breaches analyzed and measures the median time from opening a phishing message to typing data into it at under a minute (Verizon, 2024). A control that depends on employees slowing down to inspect a message is arguing against both of those figures.
The attack runs in five steps, and every step is a place it can be broken. First, a message arrives that imitates the tenant sign-in page, usually as a shared-document notice or a missed voicemail alert. Second, the employee signs in on the attacker's relay page, which passes the password and the one-time code through to the real service while the employee waits and captures the session cookie that comes back; a push approval or a six-digit code does not survive this step. Third, the attacker signs in with that session, creates a mailbox rule that files anything containing invoice, wire, or ACH into a folder nobody opens, and reads quietly for two or three weeks. Fourth, the attacker waits for a genuine invoice thread rather than starting one. Fifth, the attacker replies inside that real thread with new banking details and a reason for the change.
Impact is easy to size here. One redirected wire at the 48,000 dollar average is recoverable only if the fraud is reported inside the short window in which a recall still works, and reconciliation at this credit union runs weekly, so discovery would often fall outside it. Two redirected payments in one accounts payable cycle would cost more than the two analysts cost in a year. Likelihood is harder to state honestly, and this paper will not attach a percentage to it. With a 4 percent submission rate across 240 employees, an attacker who runs one convincing campaign a quarter needs no unusual skill to obtain a working session, so a mailbox compromise inside twelve months is treated here as likely rather than merely possible.
Controls and the Step Each One Counters
Control one is phishing-resistant multifactor authentication, issued as hardware security keys, for the 41 accounts that can approve a payment, change a vendor record, or administer the tenant. It counters step two. A hardware authenticator signs a challenge tied to the real sign-in address, so a relay page hosted somewhere else receives nothing it can replay, and that property is the reason the Cybersecurity and Infrastructure Security Agency (2022) separates this form of multifactor authentication from push prompts and one-time codes. Federal identity guidance draws the same line, treating resistance to impersonation as a property of the authenticator rather than of the user's attention (Grassi et al., 2017). The other 199 staff keep number-matching push while keys are phased in over two quarters.
Control two counters step five, the fraudulent instruction, and it assumes the mailbox is already lost. Any change to vendor banking details triggers a callback to a phone number that was already in the vendor record before the request arrived, made by someone other than the person who received the request, and every wire above 10,000 dollars needs a second approver. Control three counters step three, quiet persistence. Automatic forwarding to outside addresses is blocked at the tenant, and any new inbox rule that deletes messages or moves them out of the inbox raises an alert to the two analysts the same day. Published domain authentication set to reject removes the easy version of the spoofed sender, though not the harder version.
Control four is readiness rather than prevention. A written procedure names who kills active sessions, who freezes the payment queue, and who calls the receiving bank, and it is rehearsed twice a year against this exact scenario, following the preparation and detection phases of the federal incident handling guide (Cichonski et al., 2012). The four controls map to the govern, protect, and detect functions of the current cybersecurity framework, which is already the vocabulary the credit union's examiners use (National Institute of Standards and Technology, 2024). First-year cost is about 34,000 dollars: two keys each for 41 people at roughly 55 dollars a key, a security licensing tier that adds about 10 dollars per employee per month, and about 90 staff hours to write the callback procedure and run the rehearsal.
Residual Risk and What Would Change This Judgement
These controls do not remove the risk, and this analysis would be worth less if it claimed they did. Three gaps remain open. A compromised vendor is untouched by any of it: when the fraudulent instruction is sent from the vendor's own real mailbox, domain authentication passes, the thread is genuine, and only the callback stands between the request and the money. The callback itself fails if the attacker changed the stored phone number first, which is why the number has to be the one on file before the request arrived and why a phone number change is handled as a banking change. And 199 employees keep an authenticator a relay page can defeat, so the argument above holds for the payment path, not for every mailbox in the building.
Stated plainly, the residual position is this. Mailbox compromise stays possible and should be planned for rather than argued away. Compromise that reaches a completed fraudulent payment moves from likely to unlikely within twelve months, because completing it now requires either defeating a hardware authenticator or compromising a vendor and then surviving a callback to a number the attacker did not supply. Expected loss is not zero. A reasonable planning figure is one attempted redirection a year, a small chance that it completes, and roughly 48,000 dollars of exposure per event, which is the argument for keeping the wire recall procedure current instead of assuming it will never be used.
Three measurements would change this judgement rather than confirm it. If the credential submission rate in the next exercise does not fall below 2 percent, the human side of the plan is not working and the key rollout should cover more accounts sooner than planned. If more than one inbox rule alert a month turns out to be genuine, an attacker is already inside and the next dollar belongs in detection rather than in awareness. If accounts payable reports that callbacks get skipped under month-end pressure, the control exists on paper only, and the honest response is to change the payment schedule rather than to retrain the same three people again.
References
Cichonski, P., Millar, T., Grance, T., & Scarfone, K. (2012). Computer security incident handling guide (NIST Special Publication 800-61 Rev. 2). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-61r2
Cybersecurity and Infrastructure Security Agency. (2022). Implementing phishing-resistant MFA. U.S. Department of Homeland Security. https://www.cisa.gov/resources-tools/resources/implementing-phishing-resistant-mfa
Federal Bureau of Investigation. (2024). Internet crime report 2023. Internet Crime Complaint Center. https://www.ic3.gov/AnnualReport/Reports/2023_IC3Report.pdf
Grassi, P. A., Garcia, M. E., & Fenton, J. L. (2017). Digital identity guidelines (NIST Special Publication 800-63-3). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-63-3
National Institute of Standards and Technology. (2024). The NIST cybersecurity framework (CSF) 2.0 (NIST CSWP 29). https://doi.org/10.6028/NIST.CSWP.29
Verizon. (2024). 2024 data breach investigations report. https://www.verizon.com/business/resources/reports/dbir/
How this CMGT 433 Wk 4 example is structured
In many sections the CMGT/433 Wk 4 assignment asks for an analysis of one threat against one organization rather than a survey of attack types, and your classroom's instructions and rubric decide the exact form. By week four of a five-week course, University of Phoenix's undergraduate Cyber Security course has usually moved from vocabulary to application, so this example is built to be applied. The first section gives the organization and says what the analysis leaves out, because a scope sentence is what stops a short paper from becoming a survey. The second section models the attack as five numbered steps. The third recommends four controls and names the step each one breaks, which is the pairing readers check for. The last section states residual risk and the three measurements that would change the judgement.
CMGT/433 Wk 4 questions, answered
Does a CMGT/433 security paper have to use a real company?
No. A composite organization with realistic numbers usually works better, because you can give yourself the details the analysis needs: payment volumes, staffing, and a phishing exercise result. Say in the first sentence that the organization is invented. Sections differ on whether a supplied scenario, your own workplace, or a composite is expected, so follow the instructions your classroom posts.
How many controls should a week 4 security analysis recommend?
Three to five, each attached to a specific step in the attack you modelled. A long list of good practices reads as copied from a checklist and cannot be defended in discussion. The paper above recommends four, names the step each one breaks, and attaches a first-year cost, which is what makes the set arguable instead of decorative.
Will admitting that risk remains cost me points?
The opposite is more common. A paper that ends with the risk removed invites the reply that no control set does that, and a reader who stops believing the ending rereads the middle with suspicion. Name what the controls do not cover, size the exposure that is left, and state the measurement that would change your judgement.
Write yours, or have the desk draft it
This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.