What is a Business Email Compromise (BEC)? Any recent YouTube search about scams is likely to include a video or two about this rising type of fraud. The most well-known exposed business email compromise scammer and Instagram influencer was hushpuppi. However, many more organized and highly sophisticated cybercriminals operate behind the scenes, not flaunting their ill-gotten gains. So, what exactly is a business email compromise or BEC? BEC is a kind of email scam where cybercriminals target a business to defraud the company.
A BEC attack is designed to gain access to critical business information or extract money. BEC depends on employees trusting emails that appear to come from trusted business associates, such as managers, directors, vice presidents, or C-level executives. These compromised or spoofed emails may also appear to come from business vendors or financial institutions. These emails aim to attempt to convince an employee to reveal critical business or financial information or process a legitimate-looking payment request.
So how does cybercriminal find their targets? Well, cybercriminals can obtain their target list by mining LinkedIn profiles and corporate websites, sifting through compromised business email databases, and posting those very popular Facebook questionnaires. Additionally, these sophisticated cybercriminals will conduct extensive research on corporate officers and executives before launching their attacks.
In 2019, the FBI reported BEC attacks led to losses of approximately 1.7 billion dollars. The last published report mentioned that in the first quarter of 2020, there were over 30,700 organizations targeted. We suspect this type of fraud has surpassed this number in 2021, especially with the increase in work-from-home employees.
Types of Business Email Compromise
C-Level or CEO Fraud: In this type of attack, attackers impersonate a CEO or other executive and typically email a finance department member requesting funds be transferred to an account controlled by the attacker. The request will contain a slight variation of their legitimate email address, such as [email protected], versus [email protected] to fool the victim into believing the request is authentic.
Account Compromise: Through spear phishing, an employee’s email account is hacked, and a message is sent to a targeted victim to trick them into revealing sensitive information. The cybercriminal could use this account and information to request payments to vendors. The request will usually state that the vendor is changing their payment method or account and include a new routing and account number. The payments will be sent to fraudulent bank accounts owned by the cybercriminal.
False Invoice Scheme: Attackers commonly target foreign suppliers through this tactic. The scammer impersonates the supplier and requests that wire payments be redirected to fraudulent accounts. The invoices will appear legitimate and quite convincing, with the only alteration being the fraudulent bank account. They may also create a lookalike domain (LAD) to impersonate the victim’s legitimate vendor. Lookalike Domain Names use character replacements to make them look as close as possible to the domain of a business, brand, or government agency.
Attorney Impersonation: This occurs when an attacker impersonates a lawyer or legal representative, either within or outside the organization. Subordinate employees are commonly targeted through these types of attacks since they are less likely to question the validity of the request.
Data Theft: These attacks typically target human resources employees to obtain personal or sensitive information about individuals within the company, such as CEOs, executives, finance, or procurement personnel. This data can then be leveraged for future attacks, such as C-Level or wire transfer fraud. This method of fraud is also used to obtain sensitive information on other employees, such as copies of their W-2 forms, Social Security Numbers, and home addresses, which can be used for tax identity fraud and other forms of identity theft.