{
  "slug": "dual-control-both-phished",
  "title": "Dual control is not dual when both approvers are behind the same phishing kit.",
  "summary": "Dual approval assumes two independent approvals. One adversary in the middle kit steals both sessions and the control collapses to one. What restores independence.",
  "lede": "Two approvers on every large payment is the oldest control in finance and one of the best. It works because the two approvals are independent events. Session theft quietly removed the independence about four years ago, and most treasury teams have not noticed, because the audit log still shows two names.",
  "date": "2026-09-04",
  "reading_time": "15 min read",
  "category": "Payments",
  "tags": [
    "dual control",
    "maker checker",
    "AiTM phishing",
    "wire fraud",
    "segregation of duties",
    "treasury security",
    "PCI DSS"
  ],
  "image": "https://cdn.twc.sh/images/igcache/Dual%20Control%20Failure/1200_630/blog.jpg",
  "url": "/blog/dual-control-both-phished.html",
  "wordcount": 4273,
  "related": [
    "session-theft-aitm",
    "deepfake-cfo-wire-fraud",
    "vendor-bank-change-fraud"
  ],
  "schema": "Article"
}