Aging-Report BEC Scam Hits 42,000 Companies | Las Vegas

Cybersecurity Alert

The Aging-Report Scam: How a 3-Hour Attack Hit 42,000 Companies

A single automated campaign reached 67,000 people at 42,000 organizations in under three hours flat. No malware, no malicious links — just a well-timed email and a request that sounded routine. Las Vegas businesses without payment-verification controls are exactly the target it was built for.

Published by CMIT Solutions of Las Vegas · Cybersecurity · 7 min read

What Happened: A Business Email Compromise Campaign at Industrial Scale

On June 1, 2026, Microsoft’s Defender Research team caught something unusual moving through inboxes across the United States. Between 2:08 p.m. and 4:52 p.m. UTC — a window of less than three hours — an automated business email compromise (BEC) operation reached more than 67,000 people at over 42,000 organizations, almost entirely inside the U.S. There was no ransomware payload, no malicious attachment, and no link for a spam filter to flag. Just email, sent at a volume and speed that only automation can produce.

The targeting wasn’t limited to one industry. Retail and consumer goods companies made up 17% of the organizations hit, technology and software firms 15%, and financial services 14% — with the remainder spread across dozens of other sectors, including the professional services, hospitality, and healthcare businesses that make up much of the Las Vegas economy. The campaign used three lure types to open the conversation: impersonated executive messages, requests for an “aging report” (the internal finance document that lists which invoices are overdue and from whom), and payroll-diversion requests aimed at HR and finance staff.

By The Numbers
Microsoft logged 7.6 billion email-based phishing threats across Q2 2026 alone. The June 1 BEC blitz reached 42,000 organizations in under three hours — and unlike a typical phishing email, it carried no attachment or link for a security filter to catch.

This wasn’t an isolated blip. Microsoft’s own Q2 2026 threat report puts the June 1 blitz inside a much bigger pattern: 7.6 billion phishing emails detected across April, May, and June alone, with monthly volume actually declining slightly even as individual campaigns grow more automated and more convincing. In other words, attackers are sending fewer emails overall but engineering each wave to convert at a far higher rate — and a three-hour campaign that hits 42,000 organizations without tripping a single malware filter is exactly what that shift looks like in practice.

Why This Attack Works: Inside the Aging-Report Scam

Most email security tools are built to catch malware and malicious links. This campaign used neither. That’s what makes the aging-report angle so effective — it’s a social engineering play dressed up as a routine finance request, and it slides past the filters most Las Vegas businesses rely on as their only line of defense. The sender address is often a lookalike domain, one or two characters off from the real vendor or executive’s address, close enough that a busy accounts-payable clerk won’t catch it on a quick read.

  • Executive impersonation: The attacker spoofs or closely mimics a CEO, CFO, or owner’s display name and email address, then opens with a message that sounds like a normal request from leadership.
  • The aging-report request: The email asks accounting staff for the company’s accounts receivable aging report — a document that lists every customer with an open balance. Once the attacker has it, they know exactly which vendors and customers to impersonate next.
  • Payroll diversion: A separate version of the campaign goes straight to HR or payroll, requesting a “routine” update to an employee’s direct deposit information — redirecting a paycheck to an account the attacker controls.
  • Automated scale: Because the entire operation runs through scripted, automated sending infrastructure, one operator can hit tens of thousands of organizations in a single afternoon rather than hand-crafting a handful of targeted emails.
  • Wire transfers and ACH payments sent to a fraudulent account are almost never recoverable once they clear.
  • A diverted paycheck doesn’t just cost an employee their pay — it creates a payroll compliance and trust problem for the business.
  • Hospitality, gaming vendors, law firms, dental practices, and construction companies in Clark County all handle the exact mix of vendor payments and payroll requests this scam targets.
  • Cyber insurance carriers increasingly deny BEC-related claims when a business can’t show it had payment-verification controls in place.
  • Because no malware is involved, standard antivirus and spam filtering will not stop this attack on their own.

Verify Every Payment Change By Phone

The GapMost small businesses process vendor banking changes and payroll updates based on nothing more than an email that looks legitimate.

The FixRequire a callback to a phone number already on file — never a number listed in the email itself — before any banking or direct-deposit detail is changed.

Lock Down Executive Impersonation

The GapMany Las Vegas businesses have no email authentication in place, so a spoofed “CEO” message lands in the inbox looking completely normal.

The FixEnforce SPF, DKIM, and DMARC on your domain, and turn on external-sender warning banners so employees see at a glance when a message didn’t originate inside the company.

Build Dual-Authorization Into AP and Payroll

The GapA single employee can often approve a wire transfer or payroll change alone, with no second set of eyes required.

The FixRequire two-person approval for any banking or direct-deposit change above a set threshold, with the second approver working from a separate verification channel.

Las Vegas Businesses: Don’t Wait for the Wire to Clear.

A payment-verification review takes less time than recovering from one fraudulent transfer.

Get a Free Security Review

Defending Las Vegas with CMIT Solutions

CMIT Solutions of Las Vegas works with businesses across Clark County to close exactly this kind of gap — email authentication, verified payment workflows, and 24/7 monitoring that catches the request before the wire goes out. This attack didn’t need to breach a single firewall to succeed. It just needed one employee to trust a routine-sounding email. That’s a policy and process problem as much as a technology one, and it’s one we help local businesses fix every week.

Sources: Microsoft Security Blog, “Email threat landscape: Q2 2026 trends and insights” (microsoft.com); KnowBe4, “CyberheistNews Vol 16 #34 — Microsoft Observed 7.6 Billion Phishing Emails in Q2 2026” (knowbe4.com).

Protect Your Las Vegas Business Today

Payment-verification controls, email authentication, and 24/7 monitoring from a local team that answers the phone.

Schedule Your Security Review

Prefer to talk? Call (702) 725-2877 or email LVSales@cmitsolutions.com

Back to Blog

Share:

Related Posts

IT engineers providing on-site staff augmentation services for Las Vegas businesses

🥇 Best IT Services Company in Las Vegas (2025): Why CMIT Solutions Leads the Pack

Best IT Services Company in Las Vegas (2025): Why CMIT Solutions Ranks…

Read More
Las Vegas skyline — guide to choosing the best managed IT services in Las Vegas

Your 2025 Guide: Best Managed IT Services in Las Vegas | SMB Buyer’s Checklist

Your 2025 Guide: Choosing the Best Managed IT Services in Las Vegas…

Read More
From casino breaches to law firm hacks, here’s what 2025 looks like for Las Vegas cybersecurity — and how local SMBs can defend themselves.

Las Vegas Cybersecurity Threats in 2025

Las Vegas Cybersecurity Threats in 2025: What SMBs Must Know & How…

Read More