24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesIn the PressDSET in the national pressSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI
//Industry & Manufacturing · 2026
Industry & Manufacturing · Case 2026

CFO whaling at an industrial company · fake CEO mail · 380K TL transfer prevented

On Friday at 16:42 the CFO of an industrial company received a look-alike domain mail "from the CEO": "Urgent supplier payment, 380K TL to this IBAN, reporting on Monday." On DSET's advice an out-of-band verification was performed and the attack was prevented. After the DKIM/SPF/DMARC setup, 18 months clean and the following 4 fake mails were blocked automatically.

Duration
30-minute prevention · 7 days of hardening
Scope
380K TL transfer pressure · mid-sized industry
Customer Satisfaction
★★★★★

01 The Challenge

Friday evening, before the weekend, the CEO on a business trip to Germany with the phone off. The mail to the CFO looked urgent: a supplier payment, reporting on Monday, a 30-minute bank approval window. The fake domain (dsetcompany.com) had been registered a week earlier, and because DKIM/SPF was weak the mail was easily accepted. The attacker had tracked the CEO's trip with APT-style OSINT.

02 DSET's Approach

01

T+0 · Preliminary analysis

DSET was called in and a mail header analysis was done: SPF=fail, DKIM=none, IP a Latvian VPN. The lookalike domain WHOIS registered a week earlier.

02

T+15min · Out-of-band verification

A WhatsApp message was sent to the CEO's known second (personal) number. The CEO said "I didn't write anything like that." The attack was prevented.

03

T+24h · DSET forensic investigation

TTPs: CEO trip tracking via APT-style OSINT (LinkedIn + airline CEO account exposure). The attacker profile was not APT41 but a "financially focused APT" group.

04

T+7 days · DKIM/SPF/DMARC setup

DKIM signing + SPF strict + DMARC policy=reject for all 47 domains. Microsoft 365 Defender for Office 365 was purchased.

05

T+14 days · Tabletop exercise

An accounting team exercise on 4 different BEC scenarios. The out-of-band verification procedure was written and signed by the CFO + CEO + Board of Directors.

06

T+30 days · DSET awareness training

An 8-hour "BEC and whaling" training for 47 employees. A quarterly phishing simulation program was started.

07

T+18 months · Continuously clean

DMARC reject = active. 4 fake mail attempts were blocked automatically. The cyber insurance premium is in the "low risk" category.

03 Results in Numbers

380K TL
Transfer prevented
30 min
Verification time
4 (18 months)
Fake mail attacks blocked
0
New attacks
18% discount
Insurance premium
96%
Employee awareness

04 Customer Testimonial

"

DSET's advice to "call the CEO first" came at exactly the right time. Within 30 minutes we were saved from a 380K TL loss. After the DMARC setup, new attack attempts dropped to zero.

CFO
Industry & Manufacturing · Marmara
★★★★★

05 Key Takeaways

Out-of-band verification (phone/WhatsApp second number) is the only reliable method against BEC
DKIM + SPF + DMARC=reject can be set up within a weekend and reduces the attack surface by 85%
CEO travel information is tracked by APTs via LinkedIn and airline reservations
A quarterly phishing simulation raises employee awareness from 50% to 95%

06 Services Used in This Case

Cyber Security

Cognitive solutions.

Incident Simulator & Threat Heatmap

Not hours of deliberation · but minutes of interactive simulation.

Your case can end just as well.

Free assessment · detailed response within 48 hours.

Call Now Contact form

Other Cases

Automotive Manufacturing

Ransomware on 800 endpoints at an automotive supplier · full recovery in 9 days

View
Public Administration

Detection and cleanup of a 14-month APT intrusion at a metropolitan municipality

View
Finance

A 9-day Red Team engagement at one of Turkey's top 5 banks

View
DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Press Room
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
Home
References
Privacy
KVKK
GDPR
Cookies
Terms