{"success":true,"data":{"id":"body-payment-details-override","label":"Bank/payment details claim to have changed (BEC fraud)","description":"Body contains a \"bank account / wire instructions / payment details / IBAN / routing number\" phrase AND a \"updated / changed / new / please note / disregard the previous\" change-announcement phrase within ~120 characters of each other. This is the canonical Business Email Compromise (BEC) vendor-fraud shape: the attacker impersonates a supplier and asks payment for a real invoice to go to a new account. The FBI IC3 reports BEC as the single highest-dollar-loss email-crime category — multi-billions in annual losses. The proximity requirement plus the change-announcement modifier keeps false-positives minimal: a neutral \"please wire payment to our bank account\" line on a real invoice is NOT an attack, but \"our bank details have been updated — please use the new IBAN below\" is. No legitimate vendor ever announces a banking change through email alone — real changes happen on letterhead and verified out-of-band channels precisely because of BEC.","tier":"danger","category":"body","isThin":false}}