✅ The verified answer to this question is available below. Our community-reviewed solutions help you understand the material better.
Scenario: A creditors clerk receives an e-mail appearing to come from a long-standing supplier advising that its banking details have changed, with a letterhead attached. The clerk updates the masterfile and pays R1,4 million to the new account. The sender’s domain is “suppl1er.co.za”, not “supplier.co.za”.
What type of attack is this, and which control would BEST have prevented the loss?