01 / Attack path
How the boundary is crossed
An invoice assistant changes a vendor account from the invoice master record to an account in an incoming email.
- 01Lower-trust input
- 02Attempted instruction
- 03Protected action
- 04Enforced decision
02 / Containment
Where bounded authority limits the effect
Bind payee, account, amount, invoice and reviewer approval; compare with trusted vendor data and use idempotency plus settlement reconciliation.
03 / Failure and evidence
The attacker’s opportunity and the defender’s record
A payment tool allowlist and generic approval permit a redirected beneficiary.
Retain canonical proposal, verified payee source, approval digest, bank transaction ID and settlement state.
04 / Canonical scope
Why this reference stands alone
Approval replay concerns reuse of consent; this page owns the complete payment abuse chain.
Protocol or attack trace
Beneficiary substitution
Email says invoice vendor changed bank account; agent proposes payment to new account.
Compare payee to trusted vendor registry and bind exact account, amount and invoice to approval.
Primary references