A Canadian mid-market construction firm engaged LeakTrace after a controller intercepted a subcontractor payment redirect attempt during the close-out phase of a large project. The audit identified the reconnaissance pattern the attempted fraud was built on and closed the exposure conditions that had enabled it.
Engagement origin
The firm operates a mid-market general contractor practice with approximately eighty staff serving commercial and institutional clients in one Canadian province. During the close-out phase of a large institutional project, the controller received a payment instruction claiming to originate from a subcontractor with a plausible pretext consistent with the close-out schedule. The controller identified an authentication inconsistency and escalated to the firm's Chief Financial Officer. The payment was not executed. The Chief Financial Officer engaged LeakTrace to identify the reconnaissance pattern and close the exposure conditions across the firm before the next project close-out cycle.
Discovery scope
LeakTrace conducted an external attack surface audit covering the firm's registered domain, controller and project manager email patterns, the firm's public web presence, and vendor mapping. Public procurement records associated with the specific project were reviewed to the extent they disclosed the close-out timeline the fraud attempt had referenced.
Findings summary
- Public procurement record disclosure. Institutional procurement records disclosed the project scope, subcontractor list, and close-out timeline that the fraud attempt had referenced. The disclosure was standard for institutional procurement but had been directly usable by the adversary.
- Controller email exposure. The controller's business email appeared in a monitored breach database, with the reuse pattern extending into the firm's accounts payable platform.
- Subcontractor identifier disclosure. Public procurement records disclosed subcontractor Business Numbers, banking domain patterns, and contact information that the fraud attempt had used to make the pretext internally consistent.
- Firm domain authentication. The firm's Sender Policy Framework configuration would have permitted spoofing attempts against subcontractor and client-facing recipients, elevating close-out fraud risk on subsequent projects.
Firm actions
The firm executed a remediation program in the two weeks following findings delivery. Controller and project manager credentials were rotated and multi-factor authentication was enforced on the accounts payable platform. Sender Policy Framework and Domain-based Message Authentication configurations were revised. Payment authorization workflow was formalized as requiring an out-of-band voice confirmation on any close-out payment above a defined threshold, using contact numbers held in the subcontractor intake record.
Outcome
The firm completed subsequent project close-outs across the following year without any documented incident against a subcontractor payment. Two intercepted payment redirect attempts were blocked at the revised authorization workflow. The firm retained LeakTrace for continuous monitoring on a quarterly cadence.
All findings were derived from public and monitored sources only. No portion of this engagement required access to the firm's internal systems, any subcontractor system, or coordination with any threat actor. Public procurement record analysis used only Canadian institutional procurement disclosures. This case file documents the pattern of post-attempt payment-redirect reconnaissance engagements LeakTrace conducts with Canadian construction firms, and is not attributed to the specific firm, subcontractor, or project referenced.