You can’t ignore the growing threat of business email compromise (BEC), given the rapid increase in cybercrime. Specifically, this cybercrime can severely affect your business and its stakeholders. So, it’s crucial to have the knowledge and skills to prevent business email compromise.
The best defence against fraud and manipulation is vigilance. We have to be less trusting.
What is a BEC?
BEC is a type of cybercrime that targets businesses through email. This scam involves tricking a person within the organisation into sharing sensitive information or completing fraudulent financial transactions. This cybercrime often involves intercepting a legitimate email, replacing it with a seemingly legitimate one, or simply copying a colleague’s familiar name. This scam can play out in different ways. Sensitive information, such as an ID number, address, and financial information, can be collected and used for another crime, such as identity theft. One way perpetrators use this information is by posing as customers and altering bank details to transfer money into their own accounts.
Who is often targeted?
BEC attacks often target businesses that handle large amounts of money or sensitive information, such as law firms, real estate companies, financial institutions, medical companies, and ECSPs. The attacker will use the compromised email account to request funds transfers, steal sensitive information, or spread malware.
How does it work?
There are several ways that a BEC attack can play out, including:
- Email spoofing: In this scenario, the cybercriminal creates a fake email address that appears to be from a trusted sender, such as an executive or vendor. The cybercriminal then uses the fake email to request sensitive information or payment from the victim. See Hawarden v ENS.
- Spear phishing: This involves the cybercriminal using personalised information to trick the victim into thinking the email is legitimate. For example, a cybercriminal may use the victim’s name, job title, or other personal information to gain the victim’s trust. See Gerber v PSG Wealth Financial Planning.
- Account compromise: In this scenario, the cybercriminals gain access to a legitimate email account and use it to request sensitive information or payment from the victim’s contacts.
- Invoice fraud: The cybercriminal creates a fake invoice that appears to be from a legitimate vendor and requests payment from the victim. The victim unknowingly pays the fake invoice, leading to a financial loss.
- CEO fraud: This involves the cybercriminal posing as a high-level executive, such as a CEO or CFO, to request payment or sensitive information from an employee. The cybercriminal may use a sense of urgency or authority to pressure the employee into complying with their request. See S v Phungula.
It’s essential to be vigilant and take precautionary measures to protect against these and other BEC tactics.
The risks to your business
- Financial loss. BEC attacks often involve tricking people into making unauthorised financial transfers, resulting in significant financial losses for the business. The most obvious loss occurs when money is transferred to the wrong bank account.
- Reputational damage. The fact that you’ve experienced a BEC can damage your business’s reputation, as customers and other stakeholders may question your information security. Businesses, especially those that offer professional services, could lose trust among clients and colleagues.
- Legal liability. If a BEC results in an unauthorised funds transfer, you may face legal action from the affected parties. This point is demonstrated in Harwardien v ENS, ENS v Harwardien and Intengo Imoto v Zoutpansberg Motor Wholesalers.
- Disruption of operations. It can disrupt your normal operations. How? Your personnel would be forced to devote time and resources to resolving the issue and recovering from the attack.
- Loss of sensitive information. BEC attacks often involve the theft of sensitive information, such as confidential business data or employees’ and customers’ personal information. The theft can severely affect the privacy and security of individuals and businesses.
- Identity-theft loss. The cybercriminal could pose as the person whose information was stolen. The cybercriminal could use this identity to open accounts and apply for loans in the name of the person whose information was stolen.
- Business interruption losses. A successful BEC attack can cause significant disruption to a business’s operations, including downtime, data loss, and delays in critical processes. This disruption can lead to additional financial and reputational damage.
Preventing business email compromise
There are many actions individuals and organisations can take to prevent BECs. Individuals must practice good cybersecurity hygiene and verify, verify, verify.
Verify, verify, verify.
Organisations can take a number of steps to prevent BECs and to ensure that, if one occurs, the organisation does not suffer financial loss. If an organisation’s actions are not interdisciplinary, success will be limited. It is a social engineering crime first and foremost. This tells us to concentrate on people.
If an organisation’s actions are not interdisciplinary, success will be limited.
By taking these steps, you can reduce the risks of BEC and minimise the impact of an attack once it occurs. Being proactive about information security is essential, as BEC attacks are becoming increasingly common and sophisticated.
Actions you can take next
- Learn more about BECs by attending a webinar on Practical Tips to Deal with Business Email Compromise.
- Raise awareness of BECs within your organisation by asking Michalsons to provide learning services. We can provide you with infographics, digital content to distribute electronically, and live awareness sessions tailored to your organisation.
- Empower yourself to take action by joining a Michalsons programme on working through the module on Dealing with Business Email Compromise (BEC) or the module on Protecting Suppliers during Procurement. Know how to get this right by working through the programmes yourself.
- Take action by asking Michasons to actually put the controls in place for you. If you don’t have time to take the necessary action yourself, you can ask Michalsons to do it for you.
- Limit the risks associated with email by asking Michalsons to provide you with an email disclaimer.
