04.10.2022
Blog
Cyber Security

Phishing prevention: Preventing Business Email Compromise

Whether for personal or business purposes, emails are now an integral part of everyday life. Unfortunately, however, they also present a major target for potential fraudsters. Find out more about Business Email Compromise (BEC) and how you can protect yourself.

Thorsten Kuhles
Cyber Security Incident Manager

We receive and send emails every day. Invitations, holiday greetings and business documents are also sent electronically, and it feels as though it has always been this way. According to the Radicati Group’s Email Statistics Report, the number of emails sent and received has risen from 269 billion in 2017 to around 320 billion in 2021. These figures show just how important the exchange of information via email has been, is, and will certainly continue to be.

This trend has not gone unnoticed by those who see it as a major opportunity to make money through dubious and illegal means. This is particularly true in the corporate environment: fraud via Business Email Compromise (BEC) is becoming increasingly popular amongst potential attackers. BEC does not require a high level of technical sophistication – the ‘technique’ is based on manipulating human behaviour. It is a combination of knowledge that a potential attacker has acquired through a wide variety of channels, and psychological tricks.

To gather clues about potential victims, potential attackers scour publicly available information. Often, no lengthy search or use of ‘social engineering’ is necessary, as data is made publicly available for certain business relationships, such as in the case of public tenders. This data frequently includes contact details, organisation names and, in some cases, employee identities.

In the second step, the contacts identified during the research are contacted via email, using sender addresses that closely resemble the genuine and recognised addresses of a colleague, customer, partner or manager. For example, instead of the well-known and legitimate email address [email protected], the email address [email protected] is used. If the doctored email also contains researched specialist terminology or abbreviations common to the sector, the fake communication can only be recognised by a very close and careful examination of the email address.

Once the fraudster has successfully established contact with one party in the targeted business relationship – and, for example, managed to arrange for an invoice to be resent – they use this new information to establish contact with the actual business partner of the initial contact. Communication can now take place with both parties without the other party being aware of it, as it appears to be a legitimate exchange to the two previous communication partners. This is how the classic man-in-the-middle attack is established, and shortly afterwards the fraudster sends the crucial email containing the original invoice and a reference to the changed bank details. The attack is usually over at this point. It generally lasts no longer than 20 to 30 days, as otherwise the risk of the ‘man-in-the-middle’ situation being discovered by the regular business partners is too high for the attacker and would quickly thwart their intentions.

The FBI has categorised BEC cases into five main types of fraud, which have proven to be highly effective. According to the FBI’s analysis, these types of fraud resulted in losses of around 40 billion US dollars last year. The actual figure is likely to be considerably higher.

(How) Can you recognise a BEC?

Spotting a BEC is not easy and requires extra vigilance. Regular awareness training for a company’s staff can reduce the risk of BEC. The following indicators can help identify a potential attack.

  1. Time pressure is applied: “Pay within the next 24 hours” or “If you do not pay, we will take legal action”…
  2. The bank account for the transfer has suddenly been changed.
  3. The sender’s email address is unknown or differs from the usual format.
  4. Phrases and abbreviations are used that are not normally employed.

However, there are also technical solutions that compare incoming emails with the names and address details of the company’s users. This can, for example, reduce the risk of CEO fraud.

Stay alert and always remember: “The first line of defence is YOU”.

Thorsten Kuhles
Cyber Security Incident Manager

Thorsten Kuhles verantwortet als Cyber Security Incident Manager bei Materna die interne und externe Vorfallsbearbeitung. Zuvor war er langjährig u.a. im Bereich Pentesting und IT-Forensik bei der Bundeswehr sowie in Führungspositionen im Bereich Cyber Security bei namhaften Unternehmen tätig.