Fraud terminology is descriptive but imprecise. It blurs the channel with the method — “vishing” tells you a phone was involved, not what the fraudster did. You cannot build a control against a category that shifts underneath you.
So this taxonomy starts from what has to be true for a fraud to succeed: two methods, the typologies that realise them, and the reusable techniques that compose those. Below is one typology in full — everything a single record carries.
The typology
Business Email Compromise - Advanced
ATOAPPCorporate
The executive's real email is taken over (ATO) and used over time to send wire requests that finance authorizes (APP).
Cross-method: this one spans ATO + APP. Taking over a mailbox (ATO) is what makes the authorised payment (APP) possible — method is a property of the step, not a label on the whole fraud.
Worked example. A fraudster phishes the CEO's email password, takes over the account, and over a month sends wire requests matching the CEO's style; finance authorizes $2M.
Attack chain — 3 techniques · click any step for its detection signals and controls
1Spear PhishingSocial Engineering DeceptionAccessdetail ▾
Targeted, researched messages impersonating a trusted party to a specific individual.
Detection signals
- Unusual request from a seemingly known sender
- Lures referencing real projects, deals, or colleagues
- Reply-to address differs from the From address
Countermeasures / controls
- Targeted training for finance/executive staff
- Out-of-band verification of unusual requests
- Attachment sandboxing
- External-sender banners
2Email Account TakeoverTechnical CompromiseAccessdetail ▾
Full control of a mailbox, often with hidden forwarding or filtering rules.
Detection signals
- New inbox forwarding or filter rules
- Logins from a new geography
- Sent items the user did not send
Countermeasures / controls
- MFA on email accounts
- Alert on mailbox-rule changes
- Impossible-travel detection
3Wire-Authorization Process AbuseLegitimate Process AbuseExecutiondetail ▾
Exploiting legitimate authority and approval flows to push wire transfers.
Detection signals
- Authority used to override controls
- Rushed approvals
- Dual control bypassed
Countermeasures / controls
- Enforce dual approval
- Payment thresholds requiring extra sign-off
- Out-of-band confirmation of beneficiaries
Defender’s view — every control across this chain
- Targeted training for finance/executive staff
- Out-of-band verification of unusual requests
- Attachment sandboxing
- External-sender banners
- MFA on email accounts
- Alert on mailbox-rule changes
- Impossible-travel detection
- Enforce dual approval
- Payment thresholds requiring extra sign-off
- Out-of-band confirmation of beneficiaries
That was one record.
The library holds the rest — each technique carrying its own detection signals and controls, and mapped to every typology that uses it.
34more typologies
43more techniques
31precursor links
5technique categories
4kill-chain stages
Semper Clarus Risk Advisors · Richard A. Hamilton, Jr.