Business Email Compromise (BEC) attacks are a major threat, costing business nearly three billion dollars a year.
This form of attack primarily targets the C-Suite in order to impersonate them.
In the world of BEC attacks, those that employ requests for wire transfers are almost devastatingly effective.
Asaf Cidon, the Vice President of Content Security at Barracuda Networks, explains why:
“Criminals use business email compromise attacks to obtain access to a business email account and imitate the owner’s identity, in order to defraud the company and its employees, customers, or partners. In most cases, scammers focus efforts on employees with access to company finances or payroll data and other personally identifiable information.”
The attack unfolds when the hacker, pretending to be a company CEO or other high-ranking official requests immediate payment, usually via wire transfer.
Again, per Asaf Cidon:
“The sense of urgency, a request for action, or a financial implication used in BEC schemes tricks targets into falling for the trap. For example, an accountant may receive a fraudulent email request for a wire transfer from the company CEO, which includes a spoofed version of the CEO’s email address and even the CEO’s own email signature.”
According to a 2016 report published by Trend Micro, a successful BEC attack nets the hacker an average of $140,000. Given how easy they are to pull off (and how low-tech), don’t expect this type of attack to show any signs of decline in the foreseeable future.
What makes BEC attacks even more troublesome is the fact that law enforcement officials believe that few attacks of this type are ever reported, and that the losses to business could be up to four times the figure we cited earlier.
Worst of all, these types of attacks appear to be increasing in their frequency. Unfortunately, C-Suite employees are notoriously resistant to basic security training, meaning that there are no easy solutions to this large and growing problem.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
2017 was “The Year of Ransomware.” It saw an incredible number of ransomware attacks and infections, paired with a tremendous number of innovations.
A new study recently published by Sitchfast Technologies paints a grim picture of the threat landscape for small and medium-sized business. Their key finding? A staggering 60 percent of small businesses that suffer a data breach of any magnitude go out of business within six months. Worse, one business owner in three does not have a plan or safeguards in place to prevent a breach.
Researchers operating out of the University of Florida, Stony Brook University and Samsung Research America have made a disturbing discovery. Millions of Android smartphones manufactured by eleven different OEMs (Original Equipment Manufacturers) were found to be vulnerable to attack via AT Commands.
Quick question – how much do the world’s cyber criminals make every sixty seconds?
It may sound like something straight out of a science fiction movie, but recently, researchers have made a disturbing discovery. Using nothing more than an off-the-shelf microphone, it’s possible for an attacker to determine what content you’re viewing on your computer monitor.
Telecommunications giant T-Mobile is the latest victim of a large-scale data breach, with personal data belonging to more than two million of its customers having been leaked. The exposed information included customer name, phone number, email address, billing zip code, account number and whether the account was pre-paid or post-paid.
Android users have a new threat to contend with, according to a sixteen-page whitepaper outlining a new malware strain.
Google has introduced a new Gmail feature called “Confidential Mode,” which seeks to make sending and receiving important or sensitive emails more secure. Unfortunately, it may have inadvertently created as many problems as it solves.
Do you use Photoshop? Does anyone who works for you use it? If so, you’ll want to apply the latest security patch immediately.