Cedar IAM:

DEMO-C-BEC-ATTACK

PAYMENT HOLD

Vendor: Apex Logistics Corp (VEND-APEX-001) • Invoice Ref: INV-URGENT-999 • Rule Version: 2026-09-19.1

Export Dossier (JSON)
Disbursement Amount

USD 49,500.00

Associated PO
PO-2026-9901 (USD 14,500.00)
Vendor Phone / Contact
+1-212-555-0199 (Sarah Jenkins (Controller))
Audit Trail Chain
3 Events Tamper-Verified

Decision Outcome: PAYMENT_HOLD

Evaluated 18:13:12 UTC
LOOKALIKE_DOMAIN_SPOOFING NEW_ACCOUNT_AND_UNRECOGNIZED_SENDER

Mandatory Controls Checklist:

  • Freeze case; notify Infosec team of suspected BEC attack
  • Hold payment immediately; do not disburse to unauthorized beneficiary

NVIDIA Nemotron AI Semantic Analysis

Model: nvidia/nemotron-3-ultra-550b-a55b • Bounded Semantic Layer

Confidence: DETERMINISTIC
Executive Decision Brief:

Automated verification flagged 6 critical discrepancies. Primary risk: New/Unverified Beneficiary Account in Email. Please review findings before approval. (NVIDIA NIM API key not configured; running in deterministic mode).

Payment Change Request YES (Bank Change Claimed)
Claimed Urgency / Pressure NORMAL
Claimed Prior Approver None Claimed

Deterministic Rule Verification Findings

7 checks evaluated
Status Rule ID Severity Finding Title Explanation & Provenance
FAIL BENEFICIARY_001_NEW_ACCOUNT CRITICAL New/Unverified Beneficiary Account in Email

Account ending in '*ount' specified in Email does NOT match any verified baseline account for vendor 'Apex Logistics Corp'. Known accounts end in: *3210.

FAIL DOMAIN_001_UNRECOGNIZED_SENDER HIGH Unrecognized Email Sender Domain

Sender domain 'apexloglstics.com' does NOT match any authorized domain for vendor 'Apex Logistics Corp'. Authorized domains are: apexlogistics.com.

FAIL DOMAIN_002_LOOKALIKE CRITICAL Suspected Lookalike/Spoofed Domain: 'apexloglstics.com'

Email domain 'apexloglstics.com' closely mimics trusted vendor domain 'apexlogistics.com' (Levenshtein distance: 1). This strongly indicates a Business Email Compromise (BEC) impersonation attempt.

PASS INVOICE_001_DUPLICATE low Invoice Reference Unique

Invoice reference 'INV-URGENT-999' does not match any previously paid invoices in vendor history.

FAIL PO_001_MISMATCH HIGH Invoice Amount Exceeds PO PO-2026-9901

Invoice amount (USD 49500.00) exceeds Purchase Order authorized limit (USD 14500.00) by USD 35000.00 (241.4% over PO limit).

FAIL AMOUNT_001_OUTLIER HIGH Statistical Amount Outlier Detected

Invoice amount (USD 49500.00) is 3.7x the historical median (USD 13500.00, threshold 15250.00). This payment significantly exceeds typical disbursements for this vendor.

FAIL EVIDENCE_002_MISSING_VERIFICATION HIGH Independent Vendor Callback Verification Missing

Beneficiary bank account changed to '*ount'. Policy mandates an independent out-of-band phone verification using the trusted vendor contact (Sarah Jenkins (Controller) at +1-212-555-0199) before funds may be released.

Evidence Dossier Files

1 files

urgent_wire_demand.eml

SHA256: 8ff2a16d1c2eded0...

EMAIL_EML

Click to upload Invoice PDF, Email EML, or PO/Vendor CSV

Max 15MB • Hashes calculated automatically

Reviewer Controls Workbench

Cedar Enforced
Record Out-of-Band Callback
Approver Override Payment Hold

Requires Approver role and documented business rationale for audit trail.

Tamper-Evident Audit Event Trail

Cryptographic SHA256 Hash Chain Valid
CASE_CREATED Analyst by analyst

Hash: 65dca9f1ec6780d62fe5cd6c... • Prev: 5e3bcc22d3a2...

2026-09-19 18:13:12 UTC
EVIDENCE_INGESTED Analyst by analyst

Hash: d9c4118a119b36021c4db7d5... • Prev: 65dca9f1ec67...

2026-09-19 18:13:12 UTC
ANALYSIS_COMPLETED Analyst by analyst

Hash: c0106b0fd51c1eabc652b157... • Prev: d9c4118a119b...

2026-09-19 18:13:12 UTC