Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

11/21/2019
09:00 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Anatomy of a BEC Scam

A look at the characteristics of real-world business email compromise attacks - and what makes them tick.

They typically land in no more than 25 inboxes in an organization — on a weekday first thing in the morning, posing as an urgent or time-sensitive email from a co-worker or executive. Business email compromise (BEC) scams represent just a small fraction of spear-phishing attacks overall, but these lucrative campaigns contain a few telltale traits.

Barracuda Networks analyzed the characteristics and trends of 1.5 million spear-phishing emails — of which just BEC made up just 7% — to determine the key methods scammers are using in their BEC campaigns. Don't let the tiny percentage fool you: BEC scams caused $26 billion in losses to businesses in the past four years, according to the FBI.

Some 91% of BEC attacks occur on weekdays, a tactic to blend in with the workday and appear more legitimate, the Barracuda study found. Attackers, on average, target up to six employees, and some 94.5% of all BEC attacks target less than 25 people in an organization. They do their homework on their targets, too, using real names of human resources, finance, and other executives as well as of the targeted employees.

The BEC emails often are written with a sense of urgency in order to rush the recipient into doing the attacker's bidding, with 85% marked as urgent, 59% requesting help, and 26% inquiring about availability, according to Barracuda's findings. And while users click on one in 10 spear-phishing emails, BEC emails are three times more likely to be opened. That doesn't necessarily mean the target fell for the message or followed the scammer's request, though, notes Asaf Cidon, a Barracuda adviser and professor of electrical engineering and computer science at Columbia University.

"We can't tell whether they went into a website and gave up their credentials," he says, or took other actions. The bottom line is when attackers impersonate someone in a position of authority or who appears legitimate, they get three times the click rate on the email, he says. 

Cidon says some attackers are making an extra effort to create very personalized messages, unlike mass phishing email campaigns. "BECs are probably going after larger amounts of money, not just trying to compromise single credentials. They are trying to extract a wire transfer out of an organization, [for example], so they are willing to do more research and spend more time" on their targets, he says.

Barracuda's study jibes with what other researchers have found in their BEC studies. "Successful BEC attacks are usually quite simple and mimic requests that could be reasonably expected to come from an employee’s executive or supervisor," notes Crane Hassold, head of Agari's cyber intelligence division.

He says wire transfer or payroll attacks usually target just one or two employees, typically in the finance or human resources department. But gift card BEC scams, where the attacker poses as a supervisor requesting the victim purchase and send him or her gift cards, often are sent to dozens of employees in an organization, he notes.

Barracuda saw the most BECs on Mondays, and Agari saw the most on Tuesdays (one out of four), with scams dwindling for the rest of the week. The emails most often arrive in the morning, with 9 a.m. as the bewitching hour since that's when most employees are first getting to their desks. Some 47% of BEC attacks are sent from Gmail accounts, and just 3% of BEC attacks come with a rigged URL or attachment. About 8% of BEC scams involve payroll requests, according to the security firm's report.

While most of the attacks originate from Nigeria, they now also come out of Ghana, Malaysia, and the United Arab Emirates, notes Agari's Hassold. 

The best way to beat back BECs: multifactor authentication to protect user credentials that get stolen and the usual mantra of educating users about the scams and how to spot one, including confirming an email address. Barracuda also recommends setting specific policies for financial transactions, banning email requests for any financial transactions, and adopting DMARC authentication, as well as machine learning technology, to protect the organization's domain from being spoofed.

But even with all of the best practices, there's no way to guarantee a user won't get duped by a BEC email. "There's no single silver bullet," Cidon says.

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "What's in a WAF?"

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
AnnaS.
50%
50%
AnnaS.,
User Rank: Apprentice
4/17/2020 | 8:36:45 AM
Great!
Thanks for sharing this article, great information and very informative. Kirk
Christopher_Kenessey
50%
50%
Christopher_Kenessey,
User Rank: Author
11/22/2019 | 3:18:48 PM
Good anti-phishing advice
These phishing emails can be especially hard to catch when employees access their emails on mobile devices, especially when the attacker has included accurate details like employee names! Absolutely agree with the recommendations to use MFA and to educate employees. Using instant-chat apps like Slack or Teams can help as well, since they cut down on the amount of email and can make phishing messages "stand out" a bit more. If an organization has a large number of remote employees, it may be worth having IT limit the devices and applications that can be used for work email (without adding an extra burden to those workers).
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/9/2020
Omdia Research Launches Page on Dark Reading
Tim Wilson, Editor in Chief, Dark Reading 7/9/2020
4 Security Tips as the July 15 Tax-Day Extension Draws Near
Shane Buckley, President & Chief Operating Officer, Gigamon,  7/10/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15105
PUBLISHED: 2020-07-10
Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded). The password is stored in the session when the user submits their username and password, and is removed once they complete authentication by entering a two-factor authenticati...
CVE-2020-11061
PUBLISHED: 2020-07-10
In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mitigates the problem. This issue is also patched in...
CVE-2020-4042
PUBLISHED: 2020-07-10
Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client itself. The malicious client can replay the Bareos director's cram-md5 challenge to...
CVE-2020-11081
PUBLISHED: 2020-07-10
osquery before version 4.4.0 enables a priviledge escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables l...
CVE-2020-6114
PUBLISHED: 2020-07-10
An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerabi...