fbpx
Sherpa Digital News
Business Email Compromise Jumped 81% Last Year! Learn How to Fight It
Business Email Compromise Jumped 81% Last Year! Learn How to Fight It
By James Sharpe
Business Email Compromise Jumped 81% Last Year! Learn How to Fight It

In recent years, electronic mail (email for short) has become an essential part of our daily lives. Many people use it for various purposes, including business transactions. With the increasing dependence on digital technology, cybercrime has grown. A significant cyber threat facing businesses today is Business Email Compromise (BEC).

Why is it important to pay particular attention to BEC attacks? Because they’ve been on the rise. BEC attacks jumped 81% in 2022, and as many as 98% of employees fail to report the threat.

What is Business Email Compromise (BEC)?

Business Email Compromise (BEC) is a type of scam in which criminals use email fraud to target victims. These victims include both businesses and individuals. They especially target those who perform wire transfer payments.

The scammer pretends to be a high-level executive or business partner. Scammers send emails to employees, customers, or vendors. These emails request them to make payments or transfer funds in some form.

According to the FBI, BEC scams cost businesses around $1.8 billion in 2020. That figure increased to $2.4 billion in 2021. These scams can cause severe financial damage to businesses and individuals. They can also harm their reputations.

How Does BEC Work?

BEC attacks are usually well-crafted and sophisticated, making it difficult to identify them. The attacker first researches the target organization and its employees. They gain knowledge about the company’s operations, suppliers, customers, and business partners.

Much of this information is freely available online. Scammers can find it on sites like LinkedIn, Facebook, and organizations’ websites. Once the attacker has enough information, they can craft a convincing email. It’s designed to appear to come from a high-level executive or a business partner.

The email will request the recipient to make a payment or transfer funds. It usually emphasizes the request being for an urgent and confidential matter. For example, a new business opportunity, a vendor payment, or a foreign tax payment.

The email will often contain a sense of urgency, compelling the recipient to act quickly. The attacker may also use social engineering tactics. Such as posing as a trusted contact or creating a fake website that mimics the company’s site. These tactics make the email seem more legitimate.

If the recipient falls for the scam and makes the payment, the attacker will make off with the funds. In their wake, they leave the victim with financial losses.

How to Fight Business Email Compromise

BEC scams can be challenging to prevent. But there are measures businesses and individuals can take to cut the risk of falling victim to them.

Educate Employees

Organizations should educate their employees about the risks of BEC. This includes providing training on how to identify and avoid these scams. Employees should be aware of the tactics used by scammers. For example, urgent requests, social engineering, and fake websites.

Training should also include email account security, including:

  • Checking their sent folder regularly for any strange messages
  • Using a strong email password with at least 12 characters
  • Changing their email password regularly
  • Storing their email password in a secure manner
  • Notifying an IT contact if they suspect a phishing email

Enable Email Authentication

Organizations should implement email authentication protocols.

This includes:

  • Domain-based Message Authentication, Reporting, and Conformance (DMARC)
  • Sender Policy Framework (SPF)
  • DomainKeys Identified Mail (DKIM)

These protocols help verify the authenticity of the sender’s email address. They also reduce the risk of email spoofing. Another benefit is to keep your emails from ending up in junk mail folders.

Deploy a Payment Verification Processes

Organizations should deploy payment verification processes, such as two-factor authentication. Another protocol is confirmation from multiple parties. This ensures that all wire transfer requests are legitimate. It’s always better to have more than one person verify a financial payment request.

Check Financial Transactions

Organizations should check all financial transactions. Look for irregularities, such as unexpected wire transfers or changes in payment instructions.

If you don’t perform these according to a schedule, it is easy for them to get forgotten. Set up a calendar item for the review of financial transactions. Use a schedule that makes sense for your business and transaction volume.

Establish a Response Plan

Organizations should establish a response plan for BEC incidents. This includes procedures for reporting the incident. As well as freezing the transfer and notifying law enforcement.

Use Anti-phishing Software

Businesses and individuals can use anti-phishing software to detect and block fraudulent emails. As AI and machine learning gain widespread use, these tools become more effective.

The use of AI in phishing technology continues to increase. Businesses must be vigilant and take steps to protect themselves.

Need Help with Email Security Solutions?

It only takes a moment for money to leave your account and be unrecoverable. Don’t leave your business emails unprotected. Give us a call today to discuss our email security solutions.


Featured Image Credit

This Article has been Republished with Permission from The Technology Press.

Send a quick message

Looking for help on your next project?  Send us a message for a no hassle chat.

Sherpa Digital are a leading Website Design and Management business in Melbourne.  We specialise in developing websites for small and medium sized businesses, as well as providing WordPress Maintenance plans and hosting, SEO, Email Marketing and Automation, as well as IT Services for Small and Medium Businesses.

What Our Clients Think

We are very fortunate to have formed excellent partnerships with many of our clients. Here’s what they’re saying about us.

Melanie PayetMelanie Payet
01:41 28 Feb 22
I cant thank James from Sherpa Digital for creating my business website. Not only does it look amazing, James service was 100% fantastic. If your looking for a professional website, look no further and give James a call, you wont be disappointed. Not only is James prompt to replying,he is an easy down to earth guy to work with.
Paula DunnPaula Dunn
01:25 11 Oct 21
There are many in the digital space who claim to be experienced, quality driven professionals, and then there are those who are truly professional, approachable and solution driven. My experience with Sherpa Digital is that of quality, perseverance and solutions that have been tailored to my needs. I highly recommend Sherpa Digital and will continue to use them for all of my digital development needs going forward.
Philippa YoungPhilippa Young
23:18 10 Oct 21
Working with James at Sherpa Digital has been a fantastic experience. Starting with a clear plan and quote, through to the final product it was a smooth and streamlined project. James was always available to discuss any questions, and nothing was too much trouble. James was professional, knowledgeable, flexible and solution focused. I would strongly recommend James for your website and IT needs.
Ness JollyNess Jolly
22:38 24 Jun 21
Thanks for your great work James.I have to say that your professionalism, punctuality and responsiveness to meet our needs is a breath of fresh air.
Elysia ElElysia El
01:18 11 Mar 21
If I could give James six stars I would. I needed some help on a tricky website over the Christmas break and he was helpful, friendly, supportive and responsive – he was happy to explain anything that I didn't understand well (in a non-geeky way). Beyond the knowledge and skills, his interpersonal skills and rapport is great.
js_loader

Call us today on 1300 868 174 for a quick and easy chat about your website or IT needs, or drop us a message through our online enquiry form