How Expose Unmasked a Phishing Scheme That Fooled an Entire Company
A finance team nearly wired $480,000 to a stranger. Here's how one analyst used Expose to trace a spoofed email back to a real network of fraudsters - and stopped the payment with minutes to spare.

On this page
The email that almost cost half a million dollars
On a Tuesday morning in late autumn, Marcus, the financial controller at a mid-sized architecture firm, opened an email that looked entirely ordinary. It came from the address of the firm's managing partner, Diane. The signature block matched. The tone matched - clipped, a little impatient, the way Diane always wrote when she was traveling. The message said that a confidential acquisition was closing earlier than expected and that a deposit of $480,000 needed to be wired to the seller's escrow account before the end of the day to hold the deal. Attached were wiring instructions on what appeared to be the letterhead of a real law firm.
Marcus had wired large sums before. The firm bought property, settled with contractors, and occasionally fronted money for development partnerships. Nothing about $480,000 was, by itself, alarming. What gave him pause was a single sentence near the bottom: "Please keep this between us until the announcement - even the leadership team isn't read in yet." Diane was secretive about deals, but she had never asked him to hide a transaction from the rest of the partners. That small wrongness was the thread that, when pulled, unraveled everything.
Instead of replying to the email - which is exactly what the sender wanted - Marcus walked down the hall to Elena, the firm's operations lead, who had spent six years in corporate security before moving into facilities and IT. Elena read the email twice. Then she opened Expose.
Starting with the only solid clue: an address
The email appeared to be from Diane, but Elena knew that display names are trivial to forge. What mattered was the actual sending address buried in the message headers. When she expanded them, the truth was subtle but damning: the visible name read "Diane Crowell," but the underlying address was a near-perfect look-alike of the company domain - a single character swapped, the kind of substitution that slides past a tired eye in a hurry. The legitimate domain used a lowercase "L"; the fraudulent one used a capital "I". On most screens, in most fonts, they are indistinguishable.
This is the heart of a business email compromise, or BEC: a look-alike domain, a borrowed identity, and a manufactured sense of urgency. The FBI's Internet Crime Complaint Center has logged tens of billions of dollars in losses to this exact pattern. Most of those losses happen because the victim never pauses to ask a simple question: who actually sent this?
Elena started where any investigator starts - with the only piece of hard data she had. She took the fraudulent domain and ran it through Expose. Within seconds, the platform returned a registration footprint: the domain had been registered eleven days earlier through a privacy-shielded registrar, paid for in a way that obscured the buyer. Eleven days. The "acquisition" that supposedly required absolute secrecy was younger than a carton of milk.
One domain, a dozen siblings
A newly registered look-alike domain is suspicious on its own. But the real value of an OSINT platform is not confirming what you already suspect - it's revealing the structure you couldn't see. Elena asked Expose to map everything connected to the registration: the hosting infrastructure, the name servers, the mail configuration, and any other domains that shared the same fingerprints.
The results reframed the whole problem. The domain targeting her firm was not a one-off. It sat inside a cluster of fourteen other look-alike domains, all registered in the same narrow window, all imitating the names of small and mid-sized professional services firms - two more architecture practices, a handful of law offices, an engineering consultancy, a regional accounting group. They shared the same hosting provider, the same name-server pattern, and the same mail-routing setup. This wasn't a person who had taken a swing at one company. It was an operation, running an assembly line of impersonations, and Marcus's firm was simply that week's target.
"The moment I saw the other thirteen domains, the conversation changed," Elena said later. "It stopped being 'is this email real' and started being 'how many other people are about to lose money this week.'"From infrastructure to humans
Infrastructure tells you the scheme is organized. It doesn't, by itself, tell you who is behind it. The privacy shield on the registration hid the buyer's name - but privacy shields are leakier than the people who rely on them believe. Fraud operations are run by humans, and humans are creatures of convenience. They reuse email addresses. They forget to scrub an old registration. They link a throwaway account to a real one because logging in twice is annoying.
Elena pivoted Expose from the domains to the contact data threaded through them. One of the fourteen domains - registered slightly earlier, before whoever ran the operation had tightened their habits - carried an exposed registrant email in an archived record. It was a free-webmail address, the kind that feels anonymous and is anything but. She fed that address into Expose and asked the obvious question: where else does this exist?
The answer arrived as a connected web. The same webmail address had, over the years, been used to:
- register two more domains, one of which had been flagged in a public scam-reporting database a year earlier;
- sign up for a marketplace seller account that still showed a partial display name;
- appear in a years-old data breach corpus, alongside a recycled password and, crucially, a recovery phone number;
- link to a social profile that the owner had clearly forgotten was tied to the address.
None of these facts was secret. Each lived in a different corner of the public internet - a registration archive, a breach index, a marketplace, a social network. The trick that would have taken a human investigator days of tab-juggling and dead ends, Expose performed as a single correlated lookup. The platform didn't break into anything. It simply read what was already lying in the open and put the pieces on one table.
The name behind the mask
The recovery phone number was the hinge. Phone numbers are sticky - people keep them for years, attach them to real accounts, and hand them out to legitimate services that, in turn, leak them into the public record. Elena ran the number through Expose and watched the anonymity collapse.
The number resolved to a person - we'll call him by the alias the operation favored, "R. Mensah," though the records suggested at least three spellings of a real name underneath. It connected to a registered ride-share account, a couple of old classified listings, and a business registration for a "digital marketing consultancy" filed in a jurisdiction known for light-touch incorporation. That shell company shared a listed address with two of the other look-alike domains' contact details. The loop had closed. The infrastructure, the email, the breach data, and the phone all pointed at the same cluster of identities.
Elena was careful here, and this matters. OSINT surfaces leads; it does not deliver verdicts. She could not prove in that moment that "R. Mensah" personally wrote the email to Marcus. What she could prove, to a standard far beyond reasonable suspicion, was that the email originated from infrastructure tied to a coordinated, multi-victim impersonation operation - and that the "urgent acquisition" was a complete fabrication. For the decision in front of her - whether to wire $480,000 - that was more than enough.
How they knew so much
One question nagged at Marcus afterward: how had the fraudster known enough to be convincing? The email had used Diane's writing tics. It referenced the firm's habit of fronting money for development partnerships. It knew Marcus's name and role. This wasn't a spray-and-pray blast to a generic accounts@ inbox. It was tailored.
The answer, it turned out, was that almost none of it required inside access. Elena walked the trail backward through Expose and the firm's own public surface, and the reconstruction was sobering in its ordinariness. The firm's website listed its leadership, with Diane's title and a flattering bio written in roughly the cadence she actually used. A press release from a year earlier - the kind every growing company issues - had announced a development partnership and quoted Diane praising the firm's willingness to "move fast and fund early." A staffing directory, meant to help clients reach the right department, named Marcus as the finance contact. Diane's travel was no secret either; she had posted, publicly, about speaking at a conference that very week.
Stitch those fragments together and you have everything the email needed: the right boss, impersonated while conveniently out of the office; the right target, in finance; a plausible deal type the firm was known to do; and even a turn of phrase lifted from a real quote. The attacker hadn't breached anything. They had simply read the company the way the company invited the public to read it, and weaponized the result. The same open-source visibility that makes a firm findable to clients had made it legible to a fraudster.
This realization changed how Elena thought about the firm's public footprint - not as something to hide, but as something to be aware of. You cannot run a business invisibly, and you shouldn't try. But you can know what your own open-source shadow looks like, because that shadow is precisely what an attacker studies before they ever send the first email. Periodically running their own firm through Expose - seeing themselves as an adversary would - became part of the routine. It's hard to defend against a profile you've never looked at.
The sixty minutes that mattered
The whole investigation, from Marcus walking down the hall to Elena laying out the network on her screen, took less than forty minutes. That speed was the entire point. The fraudulent email had a built-in clock: wire it today, before the announcement. Urgency is not a side effect of these schemes; it is the mechanism. The fraudster needs the victim to act before they think, and certainly before they investigate. Expose's value wasn't only that it found the truth - it's that it found the truth faster than the deadline the criminal had set.
Elena and Marcus did three things in quick succession. First, they called Diane directly - on the phone number they already had for her, not any number in the email. Diane was in a conference session and knew nothing about any acquisition. That single call would have been enough to kill the payment, and in an ideal world it would have happened first. But the investigation gave them something the phone call alone could not: proof of intent and scale.
Second, they preserved everything. Elena exported a structured report from Expose - the domain cluster, the registration timeline, the shared infrastructure, the linked identities - and saved the original email with full headers intact. If this ever became a law-enforcement matter, the evidence would be clean and contemporaneous, not reconstructed from memory weeks later.
Third - and this is the part most companies skip - they looked outward. Elena had a list of thirteen other firms targeted by the same operation. She didn't have a duty to warn them, but she had the means. Through industry contacts and the public-facing addresses of two of the targeted law offices, she passed along a short, factual heads-up: a look-alike of your domain was registered on this date by infrastructure tied to a wire-fraud scheme; watch your finance team's inbox. At least one of those firms later confirmed it had received - and, thanks to the warning, ignored - its own version of the urgent-wire email.
What this looks like as a repeatable process
After the incident, Elena turned the ad-hoc scramble into a documented playbook, with Expose at its core. It's deliberately simple, because playbooks that require an expert don't get used:
- Any payment-related email gets its true sending address checked against the known-good domain, character by character. Look-alike substitutions are the single most common tell.
- Any unfamiliar domain in a financial request gets run through Expose for its registration age and infrastructure. A domain younger than the relationship it claims to represent is a red flag that needs no further argument.
- Any suspicious domain gets expanded into its neighborhood - shared hosting, name servers, and registrant data - to see whether it's a lone attempt or part of a cluster. Clusters change the severity and trigger outbound warnings.
- Any payment over a set threshold requires out-of-band confirmation - a phone call to a previously known number, never a number or link supplied in the email itself.
- Everything gets preserved in a structured export the moment fraud is suspected, before anyone has a chance to "clean up" the inbox.
The firm has run this playbook several times since. Most checks come back clean in under a minute and nobody thinks about them again - which is exactly how a good control should feel. Twice more, the check has caught a look-alike domain mid-attempt. Neither resulted in a loss.
The Bottom Line
The $480,000 stayed in the firm's account. The structured evidence went to a law-enforcement referral. And a habit - check first, verify fast, warn others - quietly became part of how an architecture firm in an unremarkable office park does business. The data that saved them had been public the entire time. The difference was simply the will to look, and a way to look quickly enough for it to count.
Could your team verify a suspicious email in under a minute?
Expose turns a single address, domain, or phone number into a connected intelligence picture - before the deadline a fraudster sets for you.