Oakmere Road: Business Email Compromise – Top Phishing Attacks of 2016

In this series of blog posts we examine the most common forms of phishing attacks and appropriate countermeasures to protect both individuals and organizations – in this post we explore Business Email Compromise and the potential fall-out for executives.

Business Email Compromise

At the start of 2016, the FBI warned that it had seen a 270% increase in CEO scams, also known as Business Email Compromise (BEC) scams.

With these scams, savvy cyber criminals are taking the time to harvest personal information and learn the processes within a company. Once armed with this information, they target carefully selected employees with a spear phishing email designed to get access to confidential business information or transfer money into an unknown account.

Companies that have recently fallen victim to this kind of criminal fraud include:

  • Ubiquiti Networks – the finance department was targeted by a fraudulent request from an outside entity that resulted in $46.7 million being transferred to an overseas account held by external third parties after an employee was impersonated.
  • Mattel – a finance executive wired more than $3 million to the Bank of Wenzhou after the ‘new CEO’ requested a vendor payment. According to reports, Mattel quickly realized that it had been victim of a fraudulent request and worked with Chinese authorities to get the money back.
  • FACC – the Austrian aircraft parts maker, whose customers included Airbus, Boeing and Rolls-Royce, reported that they had fired their chief executive after cyber criminals stole €50 million ($55.7 million) in an email scam.

Agari research found that more than 85% of spear phishing attacks are enabled by legitimate cloud services, and the majority do not contain a malicious link or attachment, which make them a lot harder to detect.

BEC Countermeasures

A multi-pronged approach is required to counter these types of targeted attacks:
1. Strengthen Internal Processes – To counter the threat of this type of attack, organizations must introduce policies that ensure that no one person or single email can authorize transactions. Instead, there needs to be a mixture of communication channels verifying any request for confidential or financial information.
2. Multi-Layered Approach – There is not a single solution available that can solve the breadth of the email security problem. What’s needed is multiple controls – a cocktail of complementary solutions that provides a multi-layered approach to cyber security where prevention, early detection, attack containment, and recovery measures are considered collectively.
3. Establish Per-message Authenticity – Organizations need a solution that considers sophisticated data science and email security intelligence in order to reinstill trust into the email ecosystem and establish the ‘true’ identity of an email’s sender.

Download Agari’s executive brief on the Top Phishing Attacks of 2016 to learn more about best practices to stopping phishing attacks.

You can also check out the other posts in the Top Phishing Scams series:

  • Ransomware
  • Data Breach of Employee Information
  • Consumer Email Fraud
  • Hacktivism

Career Advancement Opportunities

April 2024 Consulting

  • Bain & Company 99.4%
  • McKinsey and Co 98.9%
  • Boston Consulting Group (BCG) 98.3%
  • Oliver Wyman 97.7%
  • LEK Consulting 97.2%

Overall Employee Satisfaction

April 2024 Consulting

  • Bain & Company 99.4%
  • Cornerstone Research 98.9%
  • Boston Consulting Group (BCG) 98.3%
  • McKinsey and Co 97.7%
  • Oliver Wyman 97.2%

Professional Growth Opportunities

April 2024 Consulting

  • Bain & Company 99.4%
  • McKinsey and Co 98.9%
  • Boston Consulting Group (BCG) 98.3%
  • Oliver Wyman 97.7%
  • LEK Consulting 97.2%

Total Avg Compensation

April 2024 Consulting

  • Partner (4) $368
  • Principal (25) $277
  • Director/MD (55) $270
  • Vice President (47) $246
  • Engagement Manager (99) $225
  • Manager (152) $170
  • 2nd Year Associate (158) $140
  • Senior Consultant (331) $130
  • 3rd+ Year Associate (108) $130
  • Consultant (587) $119
  • 1st Year Associate (538) $119
  • NA (15) $119
  • 3rd+ Year Analyst (146) $115
  • Engineer (6) $114
  • 2nd Year Analyst (344) $103
  • Associate Consultant (166) $98
  • 1st Year Analyst (1048) $87
  • Intern/Summer Associate (188) $84
  • Intern/Summer Analyst (549) $67
notes
16 IB Interviews Notes

“... there’s no excuse to not take advantage of the resources out there available to you. Best value for your $ are the...”

Leaderboard

1
redever's picture
redever
99.2
2
BankonBanking's picture
BankonBanking
99.0
3
Secyh62's picture
Secyh62
99.0
4
Betsy Massar's picture
Betsy Massar
99.0
5
dosk17's picture
dosk17
98.9
6
kanon's picture
kanon
98.9
7
GameTheory's picture
GameTheory
98.9
8
CompBanker's picture
CompBanker
98.9
9
bolo up's picture
bolo up
98.8
10
numi's picture
numi
98.8
success
From 10 rejections to 1 dream investment banking internship

“... I believe it was the single biggest reason why I ended up with an offer...”