What is Business Email Compromise (BEC) and how to stop it
Watch video here
Business Email Compromise (BEC), the biggest Cyber security threat for SMEs. As the FBI reported it costs businesses $12bn between December 2016 and May 2018 alone. The impact could have been much higher when you think about the many businesses that don’t come out and say they were impacted.
What is Business Email Compromise?
As the name suggests it is an email compromise. An attacker would compromise an email account within a business, usually of an executive team. Sometimes, the attackers spoof the executive’s email account to send emails. Once the email account is compromised they will monitor the activity and send the emails to the finance team asking for funds transfer. There are a few variations of these attacks.
- CEO Fraud
- Supply chain fraud
- Vendor email compromise
As described above, CEO fraud is straightforward. CEO’s email gets compromised or spoofed and they will send the emails to the finance department asking for funds transfer.
Supply chain fraud is where a supplier’s email account gets compromised, the activity being monitored and the attacker sends an email at the time of funds transfer asking for the funds to be transferred to a new bank. They usually send an email to recipient saying that they just changed the bank details. There have been numerous businesses suffered from this.
Another example of Supply chain fraud is between a solicitor and the consumer. Solicitors email accounts get compromised, the attacker waits for the right time and asks the consumer to transfer money into a different bank. Imagine losing all your life savings because your solicitor’s email account got compromised.
Now you might ask, how do they compromise the email accounts? The answer is a sophisticated phishing attack. They send Phishing emails asking the recipient to reset their office 365 password, Login to LinkedIn, PayPal, etc… Most people use the same password across multiple services you see. Once they compromise the account they usually create forwarding rules so that the recipient doesn’t see the responses.
There are many examples for Supply chain fraud and I will finish off with this unique example. Imagine an employee’s email account gets compromised, the attacker sends HR an email a day before payday saying that they changed the bank details and deposit the payment into the new bank.
Vendor email compromise is similar but once the email is compromised the attacker will send a fake invoice to everyone in their contacts hoping someone will clear the invoice. Guess what, there are businesses that do.
How do you avoid being a victim of Business Email Compromise (BEC)?
There are a few simple steps you can take to avoid BEC in most cases. They are:
- User education: Train your users (you can find out more here)
- Business Process for Payments
- Basic email security controls
User education is the key. Make sure your users are aware of these threats and make sure they double check the emails especially when it is a request for payment. There are a number of Security Awareness Platforms available to help you. We have other resources on these so please check them out here or give us a call and we are happy to help point you in the right direction.
Business process for payments: Any payment request or the bank details update request should be authorised by at least two people in the business. Large companies are usually good with this but SMEs struggle the most.
Basic email security controls should be enabled. It will make it easier to stop these attacks and also for users to detect these emails easier. Some of the controls include:
- Enable two-factor authentication
- Encourage strong passwords
- Enable anti-spoofing
- Deploy a spam filtering solution
- Append the subject of all external emails with a tag ‘[EXTERNAL]’ (Watch the video below with some tips on how to do this)
- Create an alert for when users create a forward rule on their mailbox
We hope the above article has been informative. If you need help with tightening your security and protect your business please use the chat box below or give us a call on 01224 516181 to speak to one of our experts.
- How to apply for the Cyber Essentials Voucher Scheme
- 5 things to consider when selecting a Security Awareness Training (SAT) platform
- 2 Years, Marmite and £600,000
- Everything you need to know about Cyber Essentials
- Cyber Essentials Demystified
- How to pick the best Antivirus software for your business
- 6 Quick and Easy Email Security Tips for Dummies
- How to carry out a baseline email phishing test
- Hackers On Tour
- How to share passwords safely in your Small Business
- In the news - Warning. North Sea firms likely already attacked
- 10 Steps to Cyber Security
- 5 Reasons why you should consider having two monitors
- What is Email phishing & why you need security awareness training in your business
- 6 Top Tips to Prevent Cyber Attacks
- How to choose the right IT Service Provider for your business
- How to choose the best Antivirus software for your business
How to apply for the Cyber Essentials Voucher Scheme
The Scottish Government is very aware of the threat Cyber Attacks have and is encouraging businesses to go through Cyber Essentials certification and is offering up to a £1,000 voucher per business. This is how to claim it.More
5 things to consider when selecting a Security Awareness Training (SAT) platform
No matter what technology you have in place your weakest link is your employees and their lack of awareness. To build a great human firewall you will need a decent Security Awareness Training programme.More
2 Years, Marmite and £600,000
Either people love my approach or hate it. There's no in-between and I am fine with that. Over the last two years, I came Face to Face with a few haters but for every hater, I met 10s of people that supported me.More
Everything you need to know about Cyber Essentials
You've heard of Cyber Essentials but not sure if you need it for your business? Here are 15 things you should know about it.More
FOR LATEST UPDATES SUBSCRIBE HERE: