3

FBI warns business email compromise attacks are now targeting commodities

 1 year ago
source link: https://siliconangle.com/2023/03/27/fbi-warns-business-email-compromise-attacks-now-targeting-commodities/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

FBI warns business email compromise attacks are now targeting commodities

50733064333_06c82e175c_c.jpg
SECURITY

The U.S. Federal Bureau of Investigation warns that criminal actors are using business email compromise schemes to facilitate the acquisition of a wide range of commodities.

BEC attacks, an attack method that involves fraud enabled by social engineering, are not new. A report in September found that one-third of all cyberattacks now involve BEC, but typically, such attacks aim to steal money. The FBI warning details that those behind the attacks are now also targeting tangible goods.

According to a March 24 announcement by the FBI, criminal actors are impersonating the email domains of legitimate companies to initiate the bulk purchase of goods from vendors across the U.S. The email messages sent to vendors appear to come from known sources of business, which vendors assume are legitimate business transactions, so they fulfill the purchase orders for distribution.

Randomly buying goods would typically cause a nonpayment alert, but those behind the BEC attacks exploit commercial credit repayment terms such as Net-30 and Net-60, meaning they are not required to pay immediately for goods purchased. The criminals behind the attacks also provide vendors with fake credit references and fraudulent W-9 forms to appear more legitimate.

Companies that have been targeted apparently discover the fraud only after attempts to collect payment are unsuccessful or after contacting the company they believed had initially placed the purchase order, only to be notified that the source of the emails was fraudulent.

The types of tangible goods targeted are also surprisingly specific, with the FBI saying that attacks have targeted construction materials, agricultural supplies, computer technology hardware and solar energy products. The goods tend to have a high value and are presumably easy to sell under the radar.

The FBI is warning all businesses to verify the source of any email order by directly calling a business’s main phone line to confirm the employment status of the email originator. Companies should also ensure that the email domain address is associated with the business it claims to be from and that employees should not click on any links provided in emails.

“The FBI’s warning emphasizes the need for continued vigilance and improved cybersecurity measures, particularly for businesses that regularly transfer large sums of money,” James McQuiggan, security awareness advocate at security awareness training company KnowBe4 Inc., told SiliconANGLE. “With increased awareness of these types of attacks for users responsible for transferring funds, they need to be aware of the tactics used by cybercriminals and learn to verify the authenticity of any request for funds or sensitive information.”

Preventing this type of fraud requires a comprehensive approach involving both technological and human elements, McQuiggan added. “Organizations must implement technical safeguards, such as two-factor authentication and encryption while prioritizing employee education and training to increase awareness of the tactics used by cybercriminals,” he said.

Photo: Mayland GovPics/Flickr

A message from John Furrier, co-founder of SiliconANGLE:

Show your support for our mission by joining our Cube Club and Cube Event Community of experts. Join the community that includes Amazon Web Services and Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger and many more luminaries and experts.

Join Our Community 

Click here to join the free and open Startup Showcase event.

“TheCUBE is part of re:Invent, you know, you guys really are a part of the event and we really appreciate your coming here and I know people appreciate the content you create as well” – Andy Jassy

We really want to hear from you, and we’re looking forward to seeing you at the event and in theCUBE Club.

Click here to join the free and open Startup Showcase event.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK