Business Email Compromise Scams a growing Cybersecurity threat

29 Jun 2016

Business Email Compromise Scams a growing Cybersec...

Instances of Business Email Compromise scams have increased dramatically over the past few months, but what are they and how can you mitigate the threat?

Quite simply, official business email accounts are compromised to conduct unauthorised fund transfers. BEC scams often begin with an attacker compromising a business executive’s email account. This is usually done using keylogger malware or phishing methods, where attackers create a domain that’s similar to the company they’re targeting or a spoofed email that tricks the target into providing account details. Upon monitoring the compromised email account, the fraudster will try to determine who initiates transfers and who requests them. The perpetrators often perform a fair amount of research, looking for a company that has had a change in leadership in the finance function, or companies where executives are travelling. BEC scams have three versions:

The Bogus Invoice Scheme - usually involves a business that has an established relationship with a supplier. The fraudster asks to transfer funds for invoice payment to an alternate, fraudulent account via spoofed email, telephone, or fax.

CEO Fraud - Fraudsters identify themselves as high-level executives purporting to be handling confidential or time-sensitive matters and initiate a transfer to an account they control. This scam is also known as “Business Executive Scam”, “Masquerading”, and “Financial Industry Wire Frauds”.

“Employee Hack” - An email account of an employee is hacked and then used to make requests for invoice payments to fraudster-controlled bank accounts. Messages are sent to multiple vendors identified from the employee’s contact list. The business may not become aware of the scheme until their vendors follow up to check on the status of the invoice payment.

How to Mitigate the Threat

Share this article


Your free global geopolitical
risk dashboard

PGI’s Risk Portal tool provides daily intelligence feeds, country threat assessments and analytical insights, enabling clients to track, understand and navigate geopolitical threats.

The Risk Portal gives users up-to-date information and analysis on global affairs.

The Risk Portal allows users to visualise information in a unique and instantly understandable way. Mapping filters enable the visualisation of incidents by threat category, time period, perpetrator and target type.

Risk Portal users can upgrade their accounts to include the Report Builder and Country Profile Generator features. The Report Builder allows users to select information, data and images from the Risk Portal and create bespoke reports and emails.

Subscribers to PGI’s Bespoke services receive tailored analysis on specific sectors and geographies of interest, delivered at a frequency they determine.

Visit the Risk Portal

Subscribe to our Cyber Bytes Newsletter

Keep yourself in the loop with PGI by signing up to our Monthly Cyber Bytes email. You will receive updates, tips and narrative around what has been happening in the world of information security.

Get in touch today

For more information on how we can help you or your business, please contact us via:

Related News

CISMP, CISSP and CISM - what's in an acronym?

20 Mar 2017

There is a wide range of different security courses available, and a mind-boggling array of certific...

Read news article

International Womens Day - Pioneering Women in Tec...

08 Mar 2017

Pioneering Women in Technology – Katherine JohnsonThe Oscar season has been and gone. The...

Read news article

Law Firms and why they need cyber security

06 Mar 2017

Suffering a data breach can be devastating for any company but for law firms the impacts can be part...

Read news article
Back to the News Hub

Follow us

+44 (0)207 887 2699
©2017 PGI - Protection Group International Ltd. All rights reserved.
PGI - Protection Group International Ltd is registered in England & Wales, reg. no. 07967865
Registered address: Cascades 1, 1190 Park Avenue, Aztec W, Almondsbury, Bristol BS32 4FP