FBI: SMBs Losing Millions To Cybercrooks
Cybercrooks may have tried to nab as much as $100 million from small and midsized U.S. businesses in payroll scams over he last year. Now the FBI is talking about how to protect yourself from this automated threat.
Cybercrooks may have tried to nab as much as $100 million from small and midsized U.S. businesses in payroll scams over he last year. Now the FBI is talking about how to protect yourself from this automated threat.The automated clearinghouse (ACV) con as described by the FBI hits small and midsized businesses, as well as school, local governments and other organizations where they live -- in their bank accounts, and particularly their payroll accounts.
Noting "a significant increase" in ACH fraud targeting small and midsized bsuinesses recently, the FBI says the ripoff typically begins with a spear phishing expedition that delivers malware via either e-mail or a link to the business's computers.
Once the malware takes up residence, a keylogger harvests the company's financial information.
Armed with legitimate banking credentials, the crooks establish new payroll accounts, the recipients being themselves of course, and authorize transfers of thousands of dollars, often using work-at-home processing services (who think they're working for legitimate businesses) to bank the booty, then wire it to the overseas criminals.
ACH is growing as a cybercrime target for the same reason it's growing as a business subject: convenience.
Because the payroll withdrawals are kept under $10,000, they don't set off currency transaction alarms that would, at the least, slow down the automated process.
Using work-at-home transaction processors (money mules) keeps the process, and the cash, flowing.
Working with the National Cyber-Forensics and Training Alliance (NCFTA), the Bureau is issuing strong warnings about the scam, which we can expect to continue picking up steam.
An in-depth picture of how the con works is offered by the FBI here.
If your business has experienced an unauthorized transfer of funds, you can report it here.
About the Author
You May Also Like
A Cyber Pros' Guide to Navigating Emerging Privacy Regulation
Dec 10, 2024Identifying the Cybersecurity Metrics that Actually Matter
Dec 11, 2024The Current State of AI Adoption in Cybersecurity, Including its Opportunities
Dec 12, 2024Cybersecurity Day: How to Automate Security Analytics with AI and ML
Dec 17, 2024The Dirt on ROT Data
Dec 18, 2024