

The “Mark” Who Calls
Business Account Takeover and How the Social Engineering Actually Works
Robert Villanueva & Jessica Kelley, with the U.S. Secret Service Cyber Fraud Task Force
Tuesday, October 6, 2026 · 11:00 a.m. ET

Your customer says “Mark from IT” told them to send the payment, share the code, install the update. There is no Mark in IT. “Mark” is a threat actor, and he bought everything he needed for the job on the dark web.
From the first message to the wire, we walk through how business account takeover actually works: what a compromised business account sells for relative to a consumer one, what an OTP bot service costs, and where the human step in the attack sits.
You’ll walk away with:
- How a business account takeover unfolds, from first contact to the wire
- What compromised business accounts and OTP bot services cost on the dark web
- Where the social engineering step sits, and where your team can interrupt it
REGISTER FOR THE WEBINAR
One registration covers both live sessions, October 6 and October 22.