The Forge — Armory Forge Systems
In February 2025, a staffer at the Democratic National Committee opened an email from their new boss.
It looked legitimate. It was signed by Chairman Ken Martin — the man who had been elected to lead the party just days earlier. The email asked the staffer to make a payment. The staffer did it.
The only problem? The email wasn't from Ken Martin. It was from a scammer who knew exactly what they were doing.
The result: the DNC lost $28,860.92 — and despite catching the fraud within minutes and reporting it to their bank, they recovered only $7,000 of it. The staffer no longer works there. A letter to the Federal Election Commission describes the loss as a "misdisbursement of Committee funds" caused by "fraudulent activity by an external third party."
This Isn't a Hack — It's a Con
Nobody broke into the DNC's servers. No malware was involved. No database was exfiltrated.
This attack used a technique called Business Email Compromise (BEC) — sometimes called CEO fraud or invoice fraud. An attacker impersonates someone with authority, creates urgency, and asks a trusted employee to move money. It's the oldest con in the book, delivered at the speed of email.
And it is devastatingly effective. The FBI's Internet Crime Complaint Center has reported that BEC scams have cost American organizations tens of billions of dollars over the last decade — more than any other type of cybercrime. The average BEC attack doesn't need to trick a security system. It just needs to trick one person, on the right day, with the right email.
The DNC is not alone. In 2020, the RNC lost $44,000 to fraudsters who drained campaign funds on a shopping spree. Since then, thieves have hit the campaigns and committees of Senators Schumer, Warner, Kaine, Moran, Booker, and Whitehouse, House Speaker Mike Johnson, Rep. Alexandria Ocasio-Cortez, and countless others — including a Michigan Senate candidate who lost $16,700 to a suspected cyberthief. Political committees, law firms, PACs, and small businesses are all getting hit, over and over, because the attack works.
Why the DNC Fell For It
The timing is the tell. Ken Martin had been chair for days. A staffer receives an email from the new boss with an urgent, plausible request. Challenging it feels awkward. Verifying it feels slow. And the scammer knows this.
That's the anatomy of every BEC attack:
- Impersonation. The sender address and signature mimic a real executive. Often the attacker registers a lookalike domain (think dnc.org vs. dnc-support.org) or spoofs the display name so it reads "Ken Martin."
- Authority. The request comes from the top. People are wired not to second-guess their boss.
- Urgency. "This needs to go out today." "I'm in meetings, handle this directly." Urgency short-circuits judgment.
- A payment or sensitive action. The payload is a wire transfer, a gift card purchase, a payroll change, or a document that contains everything the attacker needs for the next phase.
None of this requires technical sophistication. It requires context — knowing who's in charge, when they took office, and who handles the money. Attackers harvest that from press releases, LinkedIn, and public filings. The DNC published Ken Martin's victory; the scammer just read the news.
Why This Hits So Close to Home
You might be thinking: that's a national political committee — I'm a small business, nobody's impersonating my CEO.
That's exactly what every BEC victim thought before they got hit.
BEC is a numbers game. Attackers automate outreach to thousands of companies. They don't need your CEO to be famous — they need your accounts payable team to be busy. The FBI reports that small and mid-sized businesses are the most common BEC targets, precisely because they have real money moving and fewer security layers than a national committee. A $28,000 loss might dent the DNC's reputation; to a mid-size company, it can mean missed payroll.
And the economics are brutal: by the time fraud is detected, the money is usually gone. The DNC caught the scam within minutes — and still only clawed back a quarter of it. Wires move in seconds and hop through mule accounts. You don't get a do-over.
How to Stop It: Verification, Automation, and AI Threat Detection
The defense against BEC isn't a better firewall — it's making the con fail. Here's what works:
1. Make the request verifiable
Create a rule: any payment, vendor change, or credential request must be confirmed through a second channel. A phone call to a known number. A message in Slack or Teams to the person's verified account. A dual-approval step with a second manager. Scammers are experts at email — they're terrible at live phone calls from people who know the real boss's voice.
2. Lock down the email layer
Deploy SPF, DKIM, and DMARC so attackers can't easily spoof your domain. Set up lookalike-domain monitoring so you know the moment someone registers yourcompany-support.com. Configure external email banners so anything from outside your organization is visibly flagged before anyone reads it.
3. Put AI on the inbox
This is where intelligent threat detection changes the game. AI agents can be trained to:
- Flag emails that impersonate executives — matching display names, domains, and language patterns against known senders.
- Score every message for BEC signals: urgency language, payment requests, new-account requests, abnormal attachments.
- Hold suspicious payment instructions for human verification before they reach the person who can approve them.
- Detect anomalies in behavior — a vendor account changing its banking details, a "new" vendor appearing with a request to be paid immediately.
Humans miss patterns across thousands of emails; AI doesn't. The goal isn't to replace judgment — it's to make sure judgment gets a chance to be exercised.
4. Practice the drill
Run internal phishing simulations. Make the fake email a payment request from the CEO, because that's the one that actually hurts. Measure who clicks, retrain, repeat. And write the incident response plan before you need it — including who calls the bank, who contacts law enforcement, and how fast you can freeze a wire.
The Bottom Line
If an organization that employs dedicated security professionals — one that's been a target of nation-state hackers for a decade — can lose $29,000 to a single email, so can you. The only question is whether the con will reach a human, or get caught by the machine first.
The DNC spokesperson called it "a one-off mistake." It wasn't. It was a well-executed attack that exploited a gap every organization has: the moment between a plausible request and a payment. Intelligent threat detection closes that gap. Verification closes it. Training closes it. And unlike a wire transfer, none of those can be clawed back once they're in place.