The export team of a machinery manufacturer got a strange phone call from their German customer: "We sent the payment to your new account two weeks ago — which payment? The account change your accounting department notified us about." The manufacturer had notified no account change. The attacker had written to the customer from a domain one letter off from the manufacturer's, using the real invoice number and amount. What vanished was the manufacturer's receivable — the machine had been delivered, the money had gone elsewhere, and the customer was saying "we paid."
This case shows what sets machinery apart from other sectors: here the risk often sits not with the paying side, but with the side waiting to be paid. For export-driven machinery makers living on long sales cycles, proformas, and technical documents, email is the main artery carrying both receivables and intellectual property. In this article we cover the sector's four threat vectors and the path to defense.
1. Why Does the Machinery Workflow Produce a Different Risk Profile?
- Export weight = receivable risk: Türkiye's machinery sector is a strong exporter. Every invoice issued to a foreign customer is a "receivable redirection" opportunity for the attacker — and the redirected money is yours, not the customer's.
- Long sales cycle, many-touch correspondence: Quote → revision → order → LC/advance → production → shipment → commissioning → service. A chain spread over months has many points to slip into.
- Trade-fair culture: The sector lives on fairs; "new customer" emails after a fair are welcomed with enthusiasm. Attackers know this — fake RFQ (request-for-quotation) waves follow the fair calendar.
- Technical document value: Machine drawings, BOM lists, PLC programs — competitive advantage itself. Machinery's counterpart to automotive's design-leakage risk.
2. The Four Threat Vectors We See in the Sector
2.1 Receivable Redirection: The Fake "Our Account Has Changed" Sent to Your Customer
The opening scenario. The attacker deceives not you but your customer: writing to them in your name (from a look-alike domain or your compromised account), announcing a new IBAN with real invoice details. By the time it's noticed, the machine is delivered, the money is gone, and a commercial dispute is born ("we paid" / "we never received it"). In this vector, having your own domain's DMARC at reject is vital — it directly determines how impersonable you are. (Setup guide: our SPF/DKIM/DMARC article.)
2.2 Proforma Fraud — the Supply Side
The machinery version of the classic vector: bank changes on proformas from casting, sheet-metal, gearbox, and hydraulic-component suppliers. Production-deadline pressure ("if the component doesn't arrive, delivery slips and we pay penalties") weakens verification — the same mechanism as in our manufacturing article, specific to the component supply chain.
2.3 Fake RFQs and "New Customer" Lures
The "our request for quotation is attached" and "could you review the specification and quote" emails landing after a fair. The attachment is a "specification" carrying a malicious macro, or a link to a credential-harvesting portal. The sales team's natural reflex (don't lose the new customer) raises click rates. Some variants run the RFQ for real — the goal isn't an order but collecting technical documents through the correspondence.
2.4 Technical Document and Drawing Leakage
Via targeted phishing or account takeover: machine drawings, BOMs, and commissioning documents are exfiltrated. The result: a copied machine, a lost tender, years of R&D in a competitor's hands. DLP on outbound traffic (blocking drawing files from leaving toward non-policy domains) is this vector's direct antidote.
3. Field Note: The Fair Calendar = the Attack Calendar
The clear pattern we see in Türkiye's machinery field: fake RFQ waves follow major sector fairs with a 1–3 week delay. Exhibitor lists are public; the attacker opens with "we spoke at the fair," knowing you had a stand — that single line melts the suspicion normally reserved for unknown senders. A second observation: most exporters still have no DMARC on their own domains, or sit at p=none — meaning they are impersonable toward their customers and fully open to the receivable-redirection vector.
4. Defense: Two-Directional Protection
Process
Two rules: (1) On the inbound side, the classic rule — bank/IBAN changes and payments above a set amount are not processed without a call-back to a registered number. (2) On the outbound side, a proactive rule — write this line into your contracts and invoice templates: "Our bank account details change only via [official channel]; do not act on change requests received by email without confirming by phone." That single line stops a significant share of receivable-redirection cases on the customer's side.
Technology
Check Point Harmony Email & Collaboration provides the following in machinery scenarios:
- Closing your own impersonability: a managed transition from p=none to reject with DMARC Management — email can no longer be sent to your customers in your name.
- Attachment analysis on fake RFQ lures (macro/malware detection in sandbox) and click-time URL protection.
- Look-alike domain detection — flags newly registered domains impersonating your supplier or you.
- Outbound drawing/document control with DLP — blocks technical files from leaving toward non-policy domains.
- Account-takeover protection — catches the "account changed" email heading from your compromised account to your customers, in outbound traffic.
People
Fair-season-themed simulations for sales/export teams (a fake RFQ, the "we spoke at the fair" opener), proforma scenarios for accounting. The one-sentence rule: "New-customer excitement does not cancel attachment-and-link suspicion."
Frequently Asked Questions
The deceived party is the customer — why does the loss land on us?
The legal outcome varies by country and contract, but in practice the process turns into a long dispute and the commercial relationship suffers. And if the impersonation used your domain, the "could it have been prevented" question comes back to you — DMARC reject + the customer-notice line exist precisely to close that responsibility.
How do we tell a fake RFQ from a real one? We don't want to lose new customers.
Assign the distinction to a layer, not a person: attachments pass through sandboxing, links are scanned at click time — if clean, sales proceeds normally. A correct setup loses no new customers; it only loses the malicious attachment.
We already share drawings under NDA — why do we need DLP?
An NDA is legal deterrence, not technical control. An attachment to the wrong recipient, a file leaking from a compromised account, or a drawing forwarded to a personal address doesn't ask the NDA. DLP stops the movement regardless of intent.
Can we measure what our current protection misses in these scenarios?
Yes. In a 14-day monitor-mode trial, we report what's missed — fake RFQs, supplier impersonation, and outbound data risks included — without touching your existing protection.
What Should You Do Now?
If you issue export invoices, start with a single question: "If someone emailed our customer an account change in our name today, would it be technically blocked?" If the answer is "no" or "we don't know":
- Free Field Audit: Your own impersonability (DMARC posture), look-alike domain risks, and outbound data surface — reported.
- 14-Day Check Point Trial (monitor mode): Missed threats in inbound and outbound traffic, reported.
About this article: The sixth article of our Sector Series. Kinetik Bilişim is the Türkiye partner of Check Point Software Technologies at the Advanced Partner 2026 level, holding Email, Endpoint & Browser, Mobile, and SASE Solution Specialization accreditations. The author, Kemal Özleyen, is a cybersecurity engineer certified as a Check Point Workspace Security Expert. Field scenarios are shared in anonymized form.