MODULE 19🔊0:00SAFETY  50
AI Safety 101 by Mandrify

The Bank Detail Change

The vendor email looks routine. The new account belongs to the attacker.

15 minutes. Three decisions under pressure, a red-flag sort, and a verification drill you can use the same day.

Before you start

  • One real attack pattern, played as decisions - no slides, no lectures.
  • You make timed choices; your score changes with your decisions.
  • You get a safety score with feedback on every decision - never a leaderboard, never your name.
  • Your firm sees completion evidence - never your answers. Teammates never see your score.
  • Finish and you get a certificate with a unique ID anyone can verify.

Free for everyone. All drills are free - finish and you get a verifiable certificate.

Why this module exists - the normal request is the attack

$2.8 billion reported to the FBI in 2024. Sometimes all the attacker needs is a convincing request.

$2.77B
Reported US losses to Business Email Compromise - FBI IC3 2024 Internet Crime Report, 21,442 complaints.
$46.7M
Ubiquiti Networks' loss to employee impersonation and fraudulent requests targeting its finance department (SEC 8-K, 2015) - a documented example of BEC scale; the vendor-change pattern below is a separate common BEC play.

The common move is simple: get into a real email conversation - or fake one well enough. Wait until money is already supposed to move. Change where it goes.

The employee is not fooled by a strange request. The employee is fooled by a normal one. The FBI also notes chat generators can quickly produce official-sounding impersonation emails - more than $30 million in 2025 losses involved AI-assisted BEC. Not every BEC uses AI.

The muscle memory: A payment-instruction change requires independent verification - not confirmation from the same message or contact path that requested the change.

Sources: FBI IC3 2024 Internet Crime Report; FBI IC3 2025 Internet Crime Report; Ubiquiti Networks Form 8-K (Aug 2015).
Dramatized scenario - built from documented attack patterns

Tuesday, 1:17 PM. The invoice is due today.

You are Jordan Lee, operations associate at Aster Peak Advisors. Your firm uses Northstar Compliance Services for monthly reporting. Their invoice is due today, paid from the operating account.

INBOX - RE: INVOICE NS-44811:17 PM
FROM: Northstar Compliance Services <billing@northstarcompliance.com>
SUBJECT: RE: Invoice NS-4481 - updated wire instructions

Hi Jordan,

Quick update before today's payment: our bank is transitioning accounts this week.

Please use the updated wire instructions on the attached notice for Invoice NS-4481. The invoice amount and services are unchanged.

Please confirm once the wire is sent so today's payment can post to the correct account.

Thanks,
Dana - Northstar Billing

Attached: Northstar_Updated_Wire_Notice.pdf

The thread includes last month's real invoice. The amount matches what finance expected. The sender address looks right. Only the destination changed.

Simulated scenario. Aster Peak and Northstar are fictional.
Decision 1 of 3 - the change request

1:17 PM. Open the notice and pay? Verify first? You have 20 seconds.

Decision 2 of 3 - the pressure reply

You called the saved number. The real Dana says Northstar did not change banks - she sent nothing. While you're on the phone, a follow-up lands in the thread: "I am with our controller now. We need the wire confirmed by 2:00 PM." It is 1:31 PM.

Decision 3 of 3 - the queued wire

The vendor record was changed at 12:58 PM. A wire for $7,850 is queued for 2:00 PM. Your colleague Priya: "I already made the vendor change because the notice matched the invoice. The wire is queued. Can you approve it so we don't miss the deadline?"

The rule that matters

A real invoice does not prove a real destination.

The request can come from a fake lookalike address, a real mailbox the attacker controls, a copied thread, a compromised vendor, a compromised coworker. The answer is the same:

Verify payment changes outside the channel that requested them.

Use the contact path you already trust. Put the money on hold. Get an independent approval based on verified evidence. Preserve the evidence.

Red-flag sort - what actually proves safety?

Sort each card.

1 / 10
The control sequence - 5 lines

Complete each line of the rule.

1 / 5
Verification sprint - choose the trusted path

Pick the safest verification path.

1 / 6
Knowledge check - 5 questions
Module complete

0

Decisions-
Red-flag sort-
Control sequence-
Verification sprint-
Knowledge check-
AI Safety 101 by Mandrify - Official Certificate
AIS
101

This certifies that

has completed Module 19 - The Bank Detail Change: verify before money moves on with a safety score of /100 in of active time.

Safety score - payment verification: how your decisions held up, graded 0-100.

Objective: Identify payment-instruction fraud, verify vendor changes out-of-band, use payment holds and independent approval, preserve evidence, and report attempted Business Email Compromise.

Seat time ~15-18 minutes. Verify this certificate at aisafety101.com/verify.

Evidence on record: module completion, seat time, final score, and certificate ID. This certificate ID verifies in your firm's admin report.

The safest question is not "Does this invoice look right?" It is "Did the destination change?" If it changed, verify outside the thread before money moves.