A breach at the Adaptavist Group led to impersonation emails aimed at its customers. It’s a pattern we see again and again: attackers use the trust and context stolen in one breach to launch convincing phishing against everyone in that orbit.
What it means for you
Impersonation works because it borrows legitimacy — a real supplier name, a real project, a plausible request. Generic “spot the dodgy email” advice struggles against messages that look genuinely like a company you already work with.
The defences are layered: strong email security and authentication (SPF, DKIM, DMARC), phishing-resistant MFA, and staff who are trained to verify unusual requests through a second channel. We set all of this up for clients and run regular awareness training to keep it sharp.
Why impersonation works so well
Impersonation attacks succeed because they borrow legitimacy that has already been established. Armed with details taken from a breach — a genuine supplier name, a live project, a plausible reference — an attacker can craft a message that looks exactly like correspondence from a company you really do work with. Generic “spot the suspicious email” advice struggles here, because on the surface there is nothing suspicious; this is the essence of business email compromise, and it is one of the costliest forms of fraud precisely because it targets trust rather than technology.
Layered defences
Countering it takes several layers working together. Email authentication — SPF, DKIM and DMARC — makes it harder for attackers to spoof trusted domains, while anti-impersonation controls flag lookalike senders. Phishing-resistant multi-factor authentication limits the damage if a credential is captured, and, most importantly, a simple habit of verifying any unusual or financial request through a separate, known channel defeats even a convincing message. We configure all of this for clients and run regular awareness training so the human layer stays sharp.
Source: The Register, 21 April 2026.