Monday, March 8, 2021
  • Setup menu at Appearance » Menus and assign menu to Top Bar Navigation
Advertisement
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
No Result
View All Result
Home Internet Security

Phishing scams: The new hotspots for fraud gangs

October 14, 2020
in Internet Security
Phishing scams: The new hotspots for fraud gangs
586
SHARES
3.3k
VIEWS
Share on FacebookShare on Twitter

Business email compromise (BEC) phishing scams are one of the most common forms of cybercrime – and new fraud gangs are appearing across the globe to trick firms into handing over money, according to an investigation by cybersecurity researchers.

A number of these scams have in the past been operated out of Nigeria, which is where about half of BEC scams still originate, according to an analysis by researchers at security company Agari. But a quarter of BEC phishing scams operate from within the US.

You might also like

Maza Russian cybercriminal forum suffers data breach

Okta and Auth0: A $6.5 billion bet that identity will warrant its own cloud

CISA issues emergency directive to agencies: Deal with Microsoft Exchange zero-days now

In total, Agari identified BEC attacks originating from 50 countries around the world and identified South Africa and the UK as high-ranking regions of BEC activity. The UK, for example, is home to a prolific BEC outfit known as London Blue.

SEE: A winning strategy for cybersecurity (ZDNet special report) | Download the report as a PDF (TechRepublic) 

The research also identifies Eastern Europe and Russia as a region with a growing number of BEC scammers. Traditionally home to trojan malware and ransomware groups, the emergence of BEC groups in the region suggests the cyber-threat landscape could be changing as corporate phishing scams become more lucrative.

“While we knew there were some BEC actors operating out of the US, the fact they comprised a quarter of all global BEC actors was a surprise,” Crane Hassold, senior director of threat research at Agari, told ZDNet.

Nearly half the BEC scammers in the US are based in five states: California, Georgia, Florida, Texas, and New York, although evidence of people operating BEC attacks has been detected in 45 states in total.

The goal of a BEC attack is to trick an employee of an organisation into transferring a large sum of corporate funds – the average loss is $80,000, but some attacks can cost millions – into a bank account owned by the scammer.

Often these phishing attacks will take the form of a phoney email sent in the name of a real exec or supplier, asking the victim to transfer funds as a matter of urgency to secure a business deal or contract. In some cases, it’s known for BEC scammers to compromise legitimate email accounts of real contacts known to the target and use an established level of trust to help push the transfer through.

By the time someone realises the transfer was fraudulent, it’s already too late as the money is already in the hands of attackers. The FBI says almost half of reported financial losses to cybercrime in 2019 were lost to BEC scams.

Another element of these campaigns also has a significant footprint in the US; researchers collected information about 2,900 money mule accounts run by people whose job it is to transfer stolen funds and found that 80% of these were also based in the US. That’s mostly because businesses in the US have historically been the primary targets of BEC attacks and most of these attacks ask victims to send money to accounts in the same country, said Hassold.

However, while money mules are helping with criminal activity, in many cases the people involved don’t know that’s what they’re doing, having been scammed into providing their aid via social engineering, romance scams or work-from-home scams.

“Like a lot of other types of criminal activity, it’s a numbers game. There are a lot of cyber criminals involved in BEC campaigns, both in the US and internationally, and there are only so many arrests law enforcement can make,” said Hassold.

SEE: My stolen credit card details were used 4,500 miles away. I tried to find out how it happened

While BEC attacks can result in significant financial losses for businesses, it is possible to protect against them.

“Organisations first need to make sure they’re using an email defense that can protect against these types of basic social engineering attacks,” said Hassold.

“Additionally, to verify a payment request is legitimate, organizations should have policies in place that require out-of-band confirmation with the person requesting a payment,” he added.

MORE ON CYBERSECURITY

Credit: Zdnet

Previous Post

Google boosts BI chops with new Looker features, roadmap

Next Post

How marketers can get the highest ROI out of podcasts

Related Posts

Maza Russian cybercriminal forum suffers data breach
Internet Security

Maza Russian cybercriminal forum suffers data breach

March 7, 2021
Okta and Auth0: A $6.5 billion bet that identity will warrant its own cloud
Internet Security

Okta and Auth0: A $6.5 billion bet that identity will warrant its own cloud

March 7, 2021
CISA issues emergency directive to agencies: Deal with Microsoft Exchange zero-days now
Internet Security

CISA issues emergency directive to agencies: Deal with Microsoft Exchange zero-days now

March 7, 2021
Linux distributions: All the talent and hard work that goes into building a good one
Internet Security

Linux distributions: All the talent and hard work that goes into building a good one

March 7, 2021
Check to see if you’re vulnerable to Microsoft Exchange Server zero-days using this tool
Internet Security

Check to see if you’re vulnerable to Microsoft Exchange Server zero-days using this tool

March 7, 2021
Next Post
How marketers can get the highest ROI out of podcasts

How marketers can get the highest ROI out of podcasts

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

January 6, 2019
Microsoft, Google Use Artificial Intelligence to Fight Hackers

Microsoft, Google Use Artificial Intelligence to Fight Hackers

January 6, 2019

Categories

  • Artificial Intelligence
  • Big Data
  • Blockchain
  • Crypto News
  • Data Science
  • Digital Marketing
  • Internet Privacy
  • Internet Security
  • Learn to Code
  • Machine Learning
  • Marketing Technology
  • Neural Networks
  • Technology Companies

Don't miss it

How Machine Learning Is Changing Influencer Marketing
Machine Learning

How Machine Learning Is Changing Influencer Marketing

March 8, 2021
Video Highlights: Deep Learning for Probabilistic Time Series Forecasting
Machine Learning

Video Highlights: Deep Learning for Probabilistic Time Series Forecasting

March 7, 2021
Machine Learning Market Expansion Projected to Gain an Uptick During 2021-2027
Machine Learning

Machine Learning Market Expansion Projected to Gain an Uptick During 2021-2027

March 7, 2021
Maza Russian cybercriminal forum suffers data breach
Internet Security

Maza Russian cybercriminal forum suffers data breach

March 7, 2021
Clinical presentation of COVID-19 – a model derived by a machine learning algorithm
Machine Learning

Clinical presentation of COVID-19 – a model derived by a machine learning algorithm

March 7, 2021
Okta and Auth0: A $6.5 billion bet that identity will warrant its own cloud
Internet Security

Okta and Auth0: A $6.5 billion bet that identity will warrant its own cloud

March 7, 2021
NikolaNews

NikolaNews.com is an online News Portal which aims to share news about blockchain, AI, Big Data, and Data Privacy and more!

What’s New Here?

  • How Machine Learning Is Changing Influencer Marketing March 8, 2021
  • Video Highlights: Deep Learning for Probabilistic Time Series Forecasting March 7, 2021
  • Machine Learning Market Expansion Projected to Gain an Uptick During 2021-2027 March 7, 2021
  • Maza Russian cybercriminal forum suffers data breach March 7, 2021

Subscribe to get more!

© 2019 NikolaNews.com - Global Tech Updates

No Result
View All Result
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News

© 2019 NikolaNews.com - Global Tech Updates