Business Email Compromise schemes, or BEC scams, have grown by more than 270% since the beginning of last year according to the FBI. At their last reporting, more than 7,000 businesses have lost more than $1.2 billion in just two years.
Luckily, this sort of an indiscriminate and devastating fraud can be combated with IT risk management. Such services monitor, assess, and evaluate threats to your network no matter where they come from, giving you the peace of mind to concentrate on your business itself.
On the facade, BEC scams seem less impressive than thefts perpetrated by sophisticated malware that target banks and other large institutions. However, BEC attacks can avoid the basic security steps taken by both businesses and individuals, making them more versatile, and more vicious.
A BEC scam targets people instead of machines, using more conventional methods of deception. In short, criminals convince their victims to hand company money over to them directly, and so far, they’ve been very successful. The FBI warms that “[t]he scam has been reported in all 50 states and in 79 countries. Fraudulent transfers have been reported going to 72 countries; however, the majority of the transfers are going to Asian banks located within China and Hong Kong.”
Criminals perpetrate BEC scams in two stages. The first phase, reconnaissance, involves a traditional email phishing scam. Once the criminals have access to an employee’s email account, they monitor the account for an extended period of time, sometimes up to several months. During this time, they familiarize themselves with the financial processes of the target business. They learn if wire transfers are used, who initiates them, and who typically requests them. They search emails for key terms like invoice, deposit, president, and transfer. The fraudsters study the target business’ activities, organizational relationships, interests, travel, and purchasing plans—anything that might give them an inside advantage.
The second phase of the fraud comes in two versions. The first is known as a CEO Phishing Scam. Crooks create a domain name that is nearly identical to the company’s, and send a spoof email that appears to be from the CEO or other high-ranking executive. This email will appear completely legitimate, and only a careful reading will give the targeted employee a chance of detecting something “phishy.” The impersonator requests a monetary transfer, and if the employee remains oblivious to the scam, she carries out the instructions. The time and effort spent on the reconnaissance phase often allows the criminals to create an utterly convincing fund request. Before anyone realizes what has happened, the company money is out the door.
In the other iteration of phase two, criminals take over the email of someone within the targeted company who is responsible for billing and invoicing. They use that account to send out seemingly legitimate invoices, instructing wire payments to a newly designated bank account. Again, it would take intense scrutiny to notice anything wrong with the phony invoice.
Spam traps are very unlikely to catch BEC scams as the latter are targeted attacks and not mass emails. These nefarious scams continue to evolve as time goes by, so it is important to be vigilant. The FBI has urged businesses to adopt the following processes to protect themselves:
Dynamic Quest can monitor your business and help you secure your company against BEC scams and other forms of IT fraud. With expertise and resources to help defend you against any and all cybercriminal activity, we help keep businesses safe and company money where it belongs. Don’t go at it alone.
Curious to learn more? Contact your managed IT service provider today!
The cost of cybercrime is predicted to hit $10.5 trillion by 2025, according to the latest version of the Cisco/Cybersecurity Ventures “2022 Cybersecurity Almanac.”.
Forty-three percent of attacks are aimed at SMBs, but only 14% are prepared to defend themselves (Accenture).
The three sectors with the biggest spending on cybersecurity are banking, manufacturing, and the central/federal government, accounting for 30% of overall spending (IDC).
It takes an average of 287 days for security teams to identify and contain a data breach, according to the “Cost of a Data Breach 2021” report released by IBM and Ponemon Institute.
40% of businesses will incorporate the anywhere operations model to accommodate the physical and digital experiences of both customers and employees (Techvera).
More than 33 billion records will be stolen by cybercriminals by 2023, an increase of 175% from 2018.
The average cost of a data breach in the United States is $8.64 million, which is the highest in the world, while the most expensive sector for data breach costs is the healthcare industry, with an average of $7.13 million (IBM).
The internal team was energized. With the Level 1 work off its plate, the team turned its attention to the work that fueled company growth and gave them job satisfaction.
We did a proof of concept that met every requirement that our customer might have. In fact, we saw a substantial improvement.
We did everything that we needed to do, financially speaking. We got our invoices out to customers, we deposited checks, all the things we needed to do to keep our business running, and our customers had no idea about the tragedy. It didn’t impact them at all.
“We believe our success is due to the strength of our team, the breadth of our services, our flexibility in responding to clients, and our focus on strategic support.”