The purchasing manager of an aluminum extrusion firm received a revised proforma from the billet supplier they'd long worked with: "We've updated the price due to the latest LME move, and our accounting has switched to a new account — please route this lot there." The price update was consistent with that day's exchange move, the tonnage was right; a daily price change is normal in aluminum anyway. Two "changes" were packed into one email: one real (price), one fake (account). While purchasing was busy questioning the price, the account slipped by.
Aluminum is a cousin of iron & steel but carries its own risk profile: daily price volatility indexed to the LME, a strong export orientation (i.e. receivable risk), a long and international chain in billet/scrap/master-alloy supply, and deadline pressure from demanding automotive-construction-packaging customers. In this article we cover the sector's threat vectors and two-directional defense.
1. Why Does the Aluminum Workflow Produce a Distinct Surface?
- LME-indexed daily pricing: Aluminum's price is indexed to the London Metal Exchange and fluctuates daily. "Price updated per the LME" is legitimate every day — the attacker uses that legitimacy as cover for a fake account change.
- Two-way risk (both buyer and seller): Importing billet/raw material you're the paying side (proforma-fraud risk); exporting product you're the side waiting to be paid (receivable-redirection risk). Both directions are open at once.
- Long, international supply chain: Billet, scrap, master alloy, dies — many domestic/foreign suppliers. Every new supplier relationship is a fresh surface where identity verification is weak.
- Demanding customer deadlines: Automotive, construction profile, and packaging (foil/can stock) customers run tight JIT schedules. "Don't let the shipment slip" pressure weakens verification on both the supply and receivable sides.
2. The Four Threat Vectors We See in the Sector
2.1 An Account Change Disguised as an "LME Update"
The opening scenario. In a sector where the price is known to change anyway, the attacker attaches a fake account change alongside a real price update. Attention focuses on the price; the account slips through. This aluminum-specific "two changes in one" technique is a step up from iron & steel's spot pressure.
2.2 Export-Receivable Redirection
A firm exporting product (profile, sheet, foil) loses the receivable on the invoice it issued: the attacker announces a "new IBAN" to the customer via a look-alike domain or a compromised account. The same mechanism as in our machinery article — having your own domain's DMARC at reject is vital in this vector. (See our machinery article and DMARC setup guide.)
2.3 Proforma Fraud in Billet/Scrap Supply
Bank changes on high-value proformas from international billet and scrap suppliers. Foreign currency, cross-border, hard to recall. Deadline pressure ("if the billet doesn't arrive, the press stops") melts verification.
2.4 Account Takeover and Alloy/Recipe Leakage
A compromised sales/purchasing account opens the door to double-sided fraud and risks a sector-specific intellectual property: proprietary alloy recipes, heat-treatment parameters, customer-specific profile die designs. In a competitor's hands these are a direct competitive loss; DLP on outbound traffic is the antidote. (We'll cover the mechanics of ATO in depth in a separate article next week.)
3. Field Note: The "Price Changes Anyway" Reflex
The clear pattern we see in the aluminum field: teams accustomed to daily price changes become desensitized to the word "change." What "it must be paid today" is to iron & steel, "price/terms updated" is to aluminum — heard so often that telling the fake from the real gets hard. A second observation: most exporting extrusion and rolling mills sit at p=none or have no DMARC at all; so they're both open to receivable redirection and unable to let the customer verify whether an "LME update" email really came from them.
4. Defense: Two-Directional Protection
Process
Two rules together: (1) Inbound: any request containing a bank/IBAN change — even if it arrives in the same email as a price update — is not processed without a call-back to a registered number. The critical nuance: price confirmation and account confirmation are separate operations; one doesn't cover the other. (2) Outbound: add to your customer contracts and invoices the line "our account details change only via the official channel; confirm any email request by phone."
Technology
Check Point Harmony Email & Collaboration provides the following in aluminum scenarios:
- Closing your own impersonability: a managed transition from p=none to reject with DMARC Management.
- Correspondence-pattern learning — contextually flags the account part of a "price updated + account changed" combination; treats the price change as normal, the account change as suspicious.
- Look-alike and newly registered domain detection (impersonating your supplier or you).
- Sandboxing + click-time URL protection on proforma attachments.
- DLP for outbound alloy-recipe/die-design control and account-takeover protection.
People
Sector-specific simulations for purchasing and export/sales teams. The one-sentence rule to embed: "A price change is normal; an account change always requires confirmation — if both are in the same email, verify them separately."
Frequently Asked Questions
Our price changes every day anyway — how can the team question every email?
Not every email, only requests that change the direction of money movement: bank/IBAN changes and recipient-account changes. A price update flows freely; only an account change triggers the procedure. This distinction doesn't slow the team down.
We both import and export — which should we prioritize?
Both are open at once, but closing the outbound side is usually more urgent: taking your own domain's DMARC to reject ends your impersonability toward customers, and that's the fastest win under your control. The call-back rule for the import side runs in parallel.
Our alloy recipes are already limited to a few people — is DLP necessary?
Limiting access is necessary but not sufficient: if an authorized person's account is compromised or a file goes to an external address by mistake, access control doesn't kick in. DLP stops the movement at the point of egress.
Can we measure what our current protection misses in these scenarios?
Yes. In a 14-day monitor-mode trial, we report what's missed — supplier/customer impersonation, look-alike domains, and outbound data risks included — without touching your existing protection.
What Should You Do Now?
If you both import billet and export product, you're exposed in both directions. Start with two questions: (1) "Would our team separate an account change arriving in the same email as a price update?" (2) "If someone emailed our customer an account change in our name, would it be blocked?"
- Free Field Audit: Your own impersonability (DMARC), look-alike risks, and outbound data surface — reported.
- 14-Day Check Point Trial (monitor mode): Missed threats in inbound and outbound traffic, reported.
About this article: The seventh article of our Sector Series. Kinetik Bilişim is the Türkiye partner of Check Point Software Technologies at the Advanced Partner 2026 level, holding Email, Endpoint & Browser, Mobile, and SASE Solution Specialization accreditations. The author, Kemal Özleyen, is a cybersecurity engineer certified as a Check Point Workspace Security Expert. Field scenarios are shared in anonymized form.