BOOK AN APPOINTMENT WITH AN IT SPECIALIST TODAY

Hackers Access CEO Email to Steal Company Money

BEC Scam Helps Hackers Steal Over $46M from Company

How fast could your company lose $46M? BEC Scams do it in minutes. Find out how criminals hack CEO emails to earn themselves a huge payday at your expense.  

Business Email Compromise

Sometimes criminals hide in the shadows and sometimes they hide behind technology, waiting, ready to strike at the most vulnerable. You know this, so you’ve invested in employee education. Employees are aware of common cybersecurity threats and email scams. But the BEC scam turns everything on its head.

It does so by hijacking the CEO’s most important business communication tool, email.

What Is a BEC Scam?

A cybersecurity-aware employee would always check to see where an email is coming from if that email asks them to do something like send millions to a strange account. But what if that email looks like it comes from you?

A Business Email Compromise (BEC) scam is conducted via your CEO’s own business email account. The hackers monitor your email for days or months undetected before sending an email from you to one or more of your employees, asking them to do something like:

  • Wire money from the company accounts
  • Share their login to company programs

If an employee got an email from you, would they question it? In a modern workplace, you’ve built a team around you who would ask “why”. But what if the person receiving the email is not in your trusted circle?

Scammers often target those who report to them, and don’t know you as well, instead.

Hackers take it a step further. They use automation tools found on your email account to instantly identify and delete any emails questioning your instructions or warning you that you’ve been hacked.

Real World BEC Attacks

This attack isn’t uncommon and the results are costly. Here are just a few medium-sized businesses that paid the price.

  • Xoom Corporation – BEC scammers emailed an employee from the CEO’s account and convinced them to wire $30M to a business overseas under the disguise of a business deal
  • Scoular Corporation – Employees wired an undisclosed amount to China for a fake acquisition deal. The email said, “We need the company to be funded properly and to show sufficient strength to the Chinese… I will not forget your professionalism in this deal, and I will show you my appreciation very shortly.”
  • Ubiquiti Networks – This San Jose company’s employee wired $46M at the “CEO’s” instruction. They were only able to recover $8M.

How to Protect Your Company from BEC Cybersecurity Threats

First of all, know that the CEO may not be the only target. It could be the CFO, CMO or even middle management.

They often attack companies using Office 365, which is relatively easy to breach if extra precautions aren’t taken. They gain access to your email via simple tricks like getting you to share your password on a spoofed 365 website.

Deploy education and technology to both prevent someone hacking a CEO email and to quickly identify when you or someone in the company has been compromised. This might include:

  • Powerful spam filters
  • Monitoring software
  • Malware protection and firewall
  • Security awareness training
  • Other customized solutions to maximize security

Above all, stay informed. Follow our blog to learn more about keeping your company safe from very real and sneaky cybersecurity threats like these.

More Like This

A Quintessential Guide to Windows 11 Tips and News

A Quintessential Guide to Windows 11 Tips and News Windows 11 introduces a wide selection of interesting new features capable of transforming the user experience. In addition, the operating system comes with a streamlined design, Android apps integration capabilities, a built-in Microsoft Teams conferencing application, and other notable features. Examples of features that you can …

A Quintessential Guide to Windows 11 Tips and News Read More »

Read More

AA21-291A: BlackMatter Ransomware

Original release date: October 18, 2021 Summary Actions You Can Take Now to Protect Against BlackMatter Ransomware • Implement and enforce backup and restoration policies and procedures. • Use strong, unique passwords. • Use multi-factor authentication. • Implement network segmentation and traversal monitoring. Note: this advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) …

AA21-291A: BlackMatter Ransomware Read More »

Read More

Outages Result of DDoS Attack” Confirms Bandwidth CEO

Outages Result of DDoS Attack” Confirms Bandwidth CEO David Morken, CEO of Bandwidth.com, has confirmed that a DDoS attack was responsible for recent outages reported on the site on September 27th. Citing that “a number of critical communications service providers have been targeted by a rolling DDoS attack” in a recent statement, Morken also apologized …

Outages Result of DDoS Attack” Confirms Bandwidth CEO Read More »

Read More

AA21-287A: Ongoing Cyber Threats to U.S. Water and Wastewater Systems

Original release date: October 14, 2021 Summary Immediate Actions WWS Facilities Can Take Now to Protect Against Malicious Cyber Activity • Do not click on suspicious links. • If you use RDP, secure and monitor it. • Use strong passwords. • Use multi-factor authentication. Note: This Alert uses the MITRE Adversarial Tactics, Techniques, and Common …

AA21-287A: Ongoing Cyber Threats to U.S. Water and Wastewater Systems Read More »

Read More

What You Need To Know About The Facebook Outage

What You Need To Know About The Facebook Outage Facebook and its associated services experienced a six-hour outage on Monday. Facebook, Instagram, WhatsApp, and Oculus suffered a major outage over the course of Monday, Oct. 4. Beginning just before noon EST, the outage lasted six hours, preventing users from accessing their social media profiles, messaging …

What You Need To Know About The Facebook Outage Read More »

Read More

Are You Ready For Windows 11 Official Release on October 5, 2021?

Are You Ready For Windows 11 Official Release on October 5, 2021? As the official release date for the free upgrade to Windows 11 nears, it is time to prepare for the new Windows experience. You can upgrade to the new operating system, depending on the eligibility of your Windows 7 or 10 PC. Microsoft …

Are You Ready For Windows 11 Official Release on October 5, 2021? Read More »

Read More