The most expensive failure in fund operations is not a mispriced NAV. It is an investor wiring a subscription to an account controlled by somebody else, because a convincing email told them to.
The attack is well understood and still works, because the defence is usually "we are careful".
How it actually happens
The pattern is almost always the same:
- An attacker gets read access to a mailbox, often the investor's, sometimes an intermediary's. No malware required; a reused password is enough.
- They watch, quietly, until a subscription or a capital call is in progress. They now know the amounts, the names and the tone.
- At the moment wire instructions are expected, they send them, from a lookalike domain, with correct context and a plausible reason the details have changed.
- The investor wires. The funds are gone within hours.
Notice what is not involved: no compromise of the fund's own systems, and no unusual behaviour the investor could reasonably have spotted. The email arrives when it is expected, saying what is expected.
Why emailing the instructions is the root cause
If wire details legitimately arrive by email, then a forged email is indistinguishable from a real one by the only test the investor has available: does this look normal.
Encrypting the attachment does not fix it. A PDF with a password sent in a second email is still an email, and the attacker who is reading the mailbox reads both.
The fix is structural: the fund never sends wire details, and every investor knows that. Details are retrieved by the investor, from an authenticated session on the fund's own domain, and nowhere else. Then a forged email is not a convincing forgery, it is an obvious one, because it is doing the thing the fund has never done.
What a safer release looks like
- Behind authentication. Details are visible only to a signed-in investor, never in an email, never at a shareable URL.
- Gated on acceptance. Visible only once the subscription is executed and the investor is accepted. An investor who has not been accepted has no reason to be looking at them.
- Scoped to the investor. The instructions carry a reference unique to that investor, so an incoming wire reconciles to a subscription without a phone call.
- Change-controlled. Any edit to bank details requires a second approver and is recorded with who, when and what changed. This is the control against an insider or a compromised admin account.
- Stated in every notification. The email that tells an investor to fund says: we will never send bank details by email; sign in to retrieve them. Repeated every time, so the absence is conspicuous.
Tell investors the rule, in advance and often
The control only works if investors know it exists. It belongs in the onboarding pack, in the portal, and in the footer of every operational email the fund sends. The one line that does the work: we will never email you bank details or ask you to change them by email.
That sentence turns your investors into the detection layer, which is the only place the attack is reliably visible.
If it happens anyway
Speed is the only thing that helps. Recall attempts have a realistic window measured in hours, not days. That means the investor needs a fast, obvious route to reach a real person at the fund, and the fund needs to know immediately which subscription is affected. Both are much easier when the subscription, the acceptance and the instructions are one record rather than a reconstruction across email.