Business email compromise (BEC) schemes
Estimated reading time: 7 minutes
Over the years, scammers have stolen millions of dollars from businesses by compromising their official email accounts and using them to request fraudulent wire transfers . Technically these schemes, which are in effect scams, are called Business Email Compromise .
There has been an increase in cyber intrusions related to Business Email Compromise schemes, involving scammers posing as executives . Contact is made by sending phishing e-mails from seemingly legitimate sources and then wire transfers to fraudulent accounts are requested. These methods ultimately lead to intrusion and unrestricted access to their victims’ credentials.
What is meant by Business Email Compromise?
The FBI defines Business Email Compromise (BEC) as a sophisticated scam that targets companies that work with foreign suppliers and companies that regularly make payments by wire transfer. Formerly known as Man-in-the-Email scams, these schemes compromise official corporate email accounts to conduct unauthorized funds transfers.
According to the FBI, victims lost more than $ 750 million and affected more than 7,000 people between October 2013 and August 2015. Globally, cybercriminals defrauded more than $ 50 million from victims in non-American countries.
How does it work?
BEC scams often start with an attacker compromising a business executive’s email account or any publicly listed business email. This is usually done using a keylogger or phishing methods , where attackers create a domain that is similar to the corporate one they are targeting. In other cases, a spoofed email tricking the target into providing account details is sufficient.
After monitoring the compromised email account, the scammer will try to determine who initiates the wire transfers and who requests them . Scammers often carry out a fair amount of research, looking for a company that has had a leadership change in the financial function management, where executives are on the road, or conducts conference calls for investors. Attackers use these as opportunities to execute the pattern.
At this point, the attack can be done in several ways.
Version 1: The bogus invoice
This release, which has also been called “ The Bogus Invoice Scheme “, “ The Supplier Swindle “, and “ Invoice Modification Scheme “usually involves a company that has a stable relationship with a supplier . The scammer asks to transfer the funds for the payment of the bill to an alternative and fraudulent account by e-mail, telephone or fax.
Version 2: CEO Fraud
In this version, scammers identify themselves as senior executives (CFO, CEO, CTO, etc.), lawyers or other types of legal representatives and claim to handle confidential matters or urgent and require you to make a wire transfer to an account they control. In some cases, the fraudulent wire transfer request is sent directly to the financial institution with instructions to urgently send the funds to another institution. This scam is also known as “ CEO Fraud “, “ Business Executive Scam “, “ Masquerading “, and “ Financial Industry Wire Frauds “.
Version 3: Account Compromise
Similar to the other two versions, an employee email account is hacked and then used to make requests for payment of bills to bank accounts controlled by scammers . Messages are sent to multiple vendors identified from the employee’s contact list. The company may not be aware of the scheme until their suppliers perform checks on the invoice payment status.
Version 4: The fake lawyer
In this version, the cybercriminal contacts employees and / or the CEO of the company and identifies himself as a lawyer or representative of a law firm, claiming to handle confidential and urgent matters. This contact, typically made by phone or email, prompts the contacted party to act quickly or covertly in handling the transfer of funds.
This type of Business Email Compromise pattern can be scheduled to occur at the end of the day or work week, when employees are preparing to quit and therefore are particularly sensitive to a situation. emergency.
Version 5: Data theft
This scheme involves emails from employees with specific roles in the company used to send requests . This time, however, the requests are not for transfers of funds but for personally identifiable information of other employees and executives . This variant can therefore serve as a starting point for more elaborate and malicious BEC attacks against the company.
The scam is primarily social engineering and generally does not need sophisticated system penetration . Unlike phishing scams, emails used in BEC scams are not sent in bulk to avoid being reported as spam . Victims are tricked into making transfers, usually instructed to act quickly and confidentially when transferring funds.
Some known cases
In March 2016, an increasing number of companies and businesses suffered damage from BEC schemes. Companies like Seagate and Snapchat have been among the victims of email scams using the same modus operandi . At the end of the same month, San Francisco-based Pivotal Software was hacked through a phishing scheme that leaked an unknown amount of employee tax information .
The breach was initiated by an email that appeared to come from company CEO Rob Mee, requesting information about the company’s personnel. This resulted in the delivery of the employee information W-2 . This information included addresses, previous year’s income details, social security numbers and individual taxpayer identification numbers. The recipient of the data, needless to say, was not authorized to request or receive data of this nature.
Not long after this incident, similar schemes were used to obtain personal information in the education sector. W-2 information of 3,000 employees at Tidewater Community College, Virginia was leaked. The event was sparked by a request message from the principal of Kentucky State University, received by one of the school staff members. The request prompted staff to forward a list of employees and students along with W-2 information.
Scams involving the theft of personal information via phishing emails have proven to be an inexhaustible source of data. The stolen data could be sold and also used to stage future attacks or identity theft. As seen in recent and previous tax scams, email scams have become one of the fastest ways to fool unwitting users.
How to defend yourself?
The advice is always the same: stay vigilant and educate employees on how to avoid being victims of BEC scams and other phishing attacks .
It’s important to know that cybercriminals don’t care about the size of your company. Indeed, usually, the more victims there are, the better. These types of scammers don’t need to be highly technical as they can find tools and services that meet all levels of technical proficiency in the deep web . As the world relies more and more on cloud services and in general linked to each other, a single compromised account is all it takes to obtain large amounts of money or data from a company .
- Review all emails carefully. Be wary of emails sent by company executives, as they are often used to trick employees into taking urgent action. Review emails requesting funds transfer to determine if requests are irregular.
- Educate and train employees . While employees are a company’s greatest asset, they are usually also the weakest link when it comes to security . Make a commitment to train employees according to the best practices of the company. Remind them that adhering to company policies is one thing, but developing good safety habits is another. For this we offer a ethical phishing service geared towards education against Business Email Compromise schemes and phishing in general.
- Stay up to date with customer habits , including details and reasons for payments.
- If you suspect that you have been the victim of a BEC email, < strong> immediately report the incident to the police. Also, alert your company so they can raise their guard and tighten controls.
SOD can help you train your employees. Find out how by contacting us, we will be happy to answer any questions.
- The SOAR benefits: simplifying investigation and response
- Security Code Review: How the service works
- Integration of the automated response: the automations in SOCaaS
- Coordination between CTI and SOC: how to further raise the defenses
- New Cloud Server: redundant internet
- Quality certificate for the SOCaaS of SOD
- Managed Detection and Response: a new preventive approach
- CLUSIT: our collaboration for better services
- Backup as a Service (17)
- Cloud Conference (3)
- Cloud CRM (1)
- Cloud Server/VPS (22)
- Conferenza Cloud (4)
- ICT Monitoring (5)
- Log Management (2)
- News (21)
- ownCloud (4)
- Privacy (7)
- Secure Online Desktop (15)
- Security (170)
- Web Hosting (15)
- Bumblebee Malware Loader's Payloads Significantly Vary by Victim System October 3, 2022On some systems the malware drops infostealers and banking Trojans; on others it installs sophisticated post-compromise tools, new analysis shows.
- First 72 Hours of Incident Response Critical to Taming Cyberattack Chaos October 3, 2022Responding to cyberattacks is extraordinarily stressful, but better planning, frequent practice, and the availability of mental health services can help IR professionals, a survey finds.
- Vice Society Publishes LA Public School Student Data, Psych Evals October 3, 2022After a flat refusal to pay the ransom, Los Angeles Unified School District's stolen data has been dumped on the Dark Web by a ransomware gang.
- Name That Edge Toon: Mumbo Dumbo October 3, 2022Come up with a clever caption, and our panel of experts will reward the winner with a $25 Amazon gift card.
- How AWS, Cisco, Netflix & SAP Are Approaching Cybersecurity Awareness Month October 3, 2022This year's theme is "See Yourself in Cyber," and these security folks are using the month to reflect on the personal factor in cybersecurity.
- Worried About the Exchange Zero-Day? Here's What to Do September 30, 2022While organizations wait for an official patch for the two zero-day flaws in Microsoft Exchange, they should scan their networks for signs of exploitation and apply these mitigations.
- LA School District Ransomware Attackers Now Threaten to Leak Stolen Data September 30, 2022Weeks after it breached the Los Angeles Unified School District, the Vice Society ransomware group is threatening to leak the stolen data, unless they get paid.
- The Top 4 Mistakes in Security Programs to Avoid September 30, 2022Overlooking even just a single security threat can severely erode a company’s community and consumer confidence, tarnish reputation and brand, negatively impact corporate valuations, provide competitors with an advantage, and create unwanted scrutiny.
- Reshaping the Threat Landscape: Deepfake Cyberattacks Are Here September 30, 2022It's time to dispel notions of deepfakes as an emergent threat. All the pieces for widespread attacks are in place and readily available to cybercriminals, even unsophisticated ones.
- Cybercriminals See Allure in BEC Attacks Over Ransomware September 30, 2022While ransomware seems stalled, business email compromise (BEC) attacks continue to make profits from the ProxyShell and Log4j vulnerabilities, nearly doubling in the latest quarter.
- Backdoor.Win32.Delf.eg / Unauthenticated Remote Command Execution October 3, 2022Posted by malvuln on Oct 03Discovery / credits: Malvuln (John Page aka hyp3rlinx) (c) 2022 Original source: https://malvuln.com/advisory/de6220a8e8fcbbee9763fb10e0ca23d7.txt Contact: malvuln13 () gmail com Media: twitter.com/malvuln Threat: Backdoor.Win32.Delf.eg Vulnerability: Unauthenticated Remote Command Execution Description: The malware listens on TCP port 7401. Third-party adversarys who can reach infected systems can issue commands made available by the...
- Backdoor.Win32.NTRC / Weak Hardcoded Credentials October 3, 2022Posted by malvuln on Oct 03Discovery / credits: Malvuln (John Page aka hyp3rlinx) (c) 2022 Original source: https://malvuln.com/advisory/273fd3f33279cc9c0378a49cf63d7a06.txt Contact: malvuln13 () gmail com Media: twitter.com/malvuln Threat: Backdoor.Win32.NTRC Vulnerability: Weak Hardcoded Credentials Family: NTRC Type: PE32 MD5: 273fd3f33279cc9c0378a49cf63d7a06 Vuln ID: MVID-2022-0646 Disclosure: 10/02/2022 Description: The malware listens on TCP port 6767....
- Wordpress plugin - WPvivid Backup - CVE-2022-2863. October 3, 2022Posted by Rodolfo Tavares via Fulldisclosure on Oct 03=====[ Tempest Security Intelligence - ADV-15/2022 ]========================== Wordpress plugin - WPvivid Backup - Version < 0.9.76 Author: Rodolfo Tavares Tempest Security Intelligence - Recife, Pernambuco - Brazil =====[ Table of Contents]================================================== * Overview * Detailed description * Timeline of disclosure * Thanks & Acknowledgements * References =====[ […]
- ZKBioSecurity 3.0.5- Privilege Escalation to Admin (CVE-2022-36634) October 1, 2022Posted by Caio B on Sep 30#######################ADVISORY INFORMATION####################### Product: ZKSecurity BIO Vendor: ZKTeco Version Affected: 18.104.22.168_R CVE: CVE-2022-36634 Vulnerability: User privilege escalation #######################CREDIT####################### This vulnerability was discovered and researched by Caio Burgardt and Silton Santos. #######################INTRODUCTION####################### Based on the hybrid biometric technology and...
- ZKBiosecurity - Authenticated SQL Injection resulting in RCE (CVE-2022-36635) October 1, 2022Posted by Caio B on Sep 30#######################ADVISORY INFORMATION####################### Product: ZKSecurity BIO Vendor: ZKTeco ( https://www.zkteco.com/en/ZKBiosecurity/ZKBioSecurity_V5000_4.1.2) Version Affected: 4.1.2 CVE: CVE-2022-36635 Vulnerability: SQL Injection (with a plus: RCE) #######################CREDIT####################### This vulnerability was discovered and researched by Caio Burgardt and Silton Santos....
- Backdoor.Win32.Augudor.b / Remote File Write Code Execution September 27, 2022Posted by malvuln on Sep 27Discovery / credits: Malvuln (John Page aka hyp3rlinx) (c) 2022 Original source: https://malvuln.com/advisory/94ccd337cbdd4efbbcc0a6c888abb87d.txt Contact: malvuln13 () gmail com Media: twitter.com/malvuln Threat: Backdoor.Win32.Augudor.b Vulnerability: Remote File Write Code Execution Description: The malware drops an empty file named "zy.exe" and listens on TCP port 810. Third-party adversaries who can reach the infected […]
- Backdoor.Win32.Psychward.b / Weak Hardcoded Credentials September 27, 2022Posted by malvuln on Sep 27Discovery / credits: Malvuln (John Page aka hyp3rlinx) (c) 2022 Original source: https://malvuln.com/advisory/0b8cf90ab9820cb3fcb7f1d1b45e4e57.txt Contact: malvuln13 () gmail com Media: twitter.com/malvuln Threat: Backdoor.Win32.Psychward.b Vulnerability: Weak Hardcoded Credentials Description: The malware listens on TCP port 8888 and requires authentication. However, the password "4174" is weak and hardcoded in cleartext within the PE...
- Backdoor.Win32.Bingle.b / Weak Hardcoded Credentials September 27, 2022Posted by malvuln on Sep 27Discovery / credits: Malvuln (John Page aka hyp3rlinx) (c) 2022 Original source: https://malvuln.com/advisory/eacaa12336f50f1c395663fba92a4d32.txt Contact: malvuln13 () gmail com Media: twitter.com/malvuln Threat: Backdoor.Win32.Bingle.b Vulnerability: Weak Hardcoded Credentials Description: The malware is packed using ASPack 2.11, listens on TCP port 22 and requires authentication. However, the password "let me in" is weak […]
- SEC Consult SA-20220923-0 :: Multiple Memory Corruption Vulnerabilities in COVESA (Connected Vehicle Systems Alliance) DLT daemon September 27, 2022Posted by SEC Consult Vulnerability Lab, Research via Fulldisclosure on Sep 27SEC Consult Vulnerability Lab Security Advisory < 20220923-0 > ======================================================================= title: Multiple Memory Corruption Vulnerabilities product: COVESA DLT daemon (Diagnostic Log and Trace) Connected Vehicle Systems Alliance (COVESA), formerly GENIVI vulnerable version:
- Backdoor.Win32.Hellza.120 / Authentication Bypass September 20, 2022Posted by malvuln on Sep 19Discovery / credits: Malvuln (John Page aka hyp3rlinx) (c) 2022 Original source: https://malvuln.com/advisory/2cbd0fcf4d5fd5fb6c8014390efb0b21_B.txt Contact: malvuln13 () gmail com Media: twitter.com/malvuln Threat: Backdoor.Win32.Hellza.120 Vulnerability: Authentication Bypass Description: The malware listens on TCP ports 12122, 21. Third-party adversarys who can reach infected systems can logon using any username/password combination....
Estimated reading time: 6 minutes L'impatto crescente delle minacce informatiche, su sistemi operativi privati op… https://t.co/FimxTS4o9G
Estimated reading time: 6 minutes The growing impact of cyber threats, on private or corporate operating systems… https://t.co/y6G6RYA9n1
Tempo di lettura stimato: 6 minuti Today we are talking about the CTI update of our services. Data security is… https://t.co/YAZkn7iFqa
Estimated reading time: 6 minutes Il tema della sicurezza delle informazioni è di grande attualità in questo peri… https://t.co/tfve5Kzr09
Estimated reading time: 6 minutes The issue of information security is very topical in this historical period ch… https://t.co/TP8gvdRcrF