Skip to content

The Brutal Truth About Business Email Compromise – Why You Can’t Afford to Ignore it

Digital technology has evolved dramatically in recent decades, but there’s one communication method that has remained steadfast in its popularity: email! According to recent findings, the average full-time office worker in the UK receives 32 emails per day: that equates to a staggering 160 per week, or around 640 per month. This illustrates the continued importance of email as a leading communication channel in modern business, and demonstrates why cybercriminals so often use it to launch their devastating attacks.

The UK Government’s Cyber Breaches showcases the sheer scale of the email-based cyber threats. In its findings, it highlighted phishing attacks as the most commonly encountered threat type by far, with 79% of businesses that identified attacks last year, citing phishing among those identified. It therefore pays to invest in email security, and encourage staff to be vigilant in the face of crafty cybercriminals that are continuously adapting their techniques to evade detection.

 

Here at Computing Dynamics, we help businesses across Oxford, Brackley, Buckingham, Northampton and the wider region reap the benefits of secure, reliable and optimised IT. In today’s hostile digital landscape businesses need to prioritise robust cyber security measures in order to stay secure, which is why we offer a comprehensive range of managed cyber security services, and take a security-first approach in every IT solution we deliver.

Taking proactive measures to protect your business starts with awareness of the online threats that seek to imperil your operations, and compromise your sensitive data. One of the most pressing cyber threats facing businesses today, is business email compromise, often abbreviated to BEC. So what is BEC? What techniques do BEC attacks leverage? And, why is it important to take targeted action to defend yourself against the BEC threat?

In this piece we aim to answer these questions, before we explain in our forthcoming article, the steps you can take to mitigate the threat.

What is Business Email Compromise (BEC)?

Business email compromise (BEC) is a form of cyber-attack whereby a criminal infiltrates a corporate email system in order to defraud the company or its partners, or steal/corrupt sensitive information. BEC is a type of social engineering or ‘phishing’ attack. However, unlike more mainstream phishing scams which are indiscriminate, and target both businesses and individuals, BEC has a specific target in mind, and the scammer usually undertakes extensive background research in order to deceive the victim.

How do BC Attacks work?

BEC attacks use the art of deception to fool the target into disclosing sensitive information or making a fraudulent payment. Deception is common to many types of online scams; here are some of the characteristics unique to BEC:

BEC Attackers Imitate Someone Close to, or Trusted by the Victim

BEC attacks can feature an extensive amount of background research into the target organisation, including its workflows, billing structures, corporate practices, and the habits of employees and executives. This allows the attacker to imitate someone within the corporate network convincingly, usually someone in a position of authority, such as a senior executive. By imitating someone in a trusted, authoritative position, the attacker stands the greatest chance of convincing a less senior target to comply with their requests.

BEC Attacks Often Involve Malware

BEC attacks can involve malware, particularly spyware, which may be launched onto the victim’s system for information gathering purposes. Spyware could be used to glean information about previous financial transactions, for example. This information could then be used in the eventual BEC attack, as a way to heighten credibility and improve the chances of success.

BEC Attacks Utilise “Email Spoofing”

The success of BEC attacks relies on the attacker’s email appearing as credible as possible. To do this, attackers will often doctor the domain name in the sender field of an email to match that of the corporate email service. This is known as ‘email spoofing,’ and it’s a remarkably easy process for someone with malicious intent. There are even automated tools available to hackers, which allow them to manipulate various aspects of the email header.

Alternatively, attackers will register a rogue email address that closely matches that of the person they’re trying to imitate, but with a slight variation that they hope will go unnoticed:

Genuine Address: Rob.Smith77@fakecompany.com Illegitimate Address: Rob.Smith77@_fakecompany.com

 

What Do BEC Attacks Seek to Achieve?

BEC attackers typically seek direct financial reward, or access to compromising information that they can leverage for future attacks against the target. Some of the common formats of BEC attacks include:

CEO Fraud

CEO fraud is a well-documented form of BEC attack, whereby a criminal impersonates the CEO or another member of a company’s senior management team. The goal of CEO fraud is usually to convince finance staff to make a wire transfer to the hacker’s account.

Account Compromise

The hacker will do research on a business’s customers or vendors, and use a hacked email account to send bogus payment requests to them. The payments will of course end up in the attacker’s account.

Data Theft

Data theft campaigns will often be conducted in preparation for a more lucrative attack in the future. Attackers will often target HR or accounting staff, with the hope of acquiring sensitive insider information about company execs, or other employees in positions of authority.

 

The Consequences of BEC Attacks

BEC attacks can have far-reaching consequences for the businesses afflicted, so it’s vital that you do all you can to prevent them to preserve the interests of your business. The fallout from a BEC attack varies depending on the nature of the breach, and the individuals affected. Some of the most damaging consequences include:

Direct Financial Loss

If an unauthorized transfer is made, there is often no way to recover the losses. According to the National Economic Crime Centre (NECC) the average amount lost in a BEC attack is around £30,000.

Reputational Harm

If your business suffers a BEC attack, you may be required by law to inform your customers or partners, particularly if their data has been put at risk. This could irredeemably harm your business’s reputation, leading to loss of revenue and stunted future growth.

Operational Disruption

If the BEC attack causes your business-critical system to be compromised, or loss of access to important data, you could find you suffer severe operational disruption. This could have an immediate impact on your business’s revenue streams, and leave you with a hefty recovery bill.

Legal and Regulatory Repercussions

If the BEC attack results in a data breach, you could find your business facing severe regulatory penalties, as well as legal ramifications. This could be particularly serious if it’s found you haven’t taken adequate steps to mitigate against online risk, and protect the data in your possession.

 

In Summary

Email-based security threats are on the rise, and represent the majority of identifiable cyber threats facing UK businesses today. BEC attacks hijack corporate email services, and prey on staff that lack the security awareness to discern the fraudulent actors, from legitimate email messages. In our next blog, we’ll explain some of the defensive measures you can take to minimise the threat of BEC to your business, so that your business’s data and finances remain out of the cybercriminal’s reach.

Don’t wait for disaster to strike. Secure your business with managed 360° protection

With cybercrime on the rise, leaving digital security to chance could spell disaster for your business. With managed security services from Computing Dynamics, your sensitive data will be robustly defended against a variety of online threats, thanks to 360° protections that cover every attack surface in your IT environment. We’ll proactively monitor, manage and maintain your environment against security risks, so that you can focus on running your business. Contact Computing Dynamics today, to book a meeting or have a friendly, no-obligation chat about your IT requirements. We’d love to hear from you.

Back To Top