Business Email Compromise (BEC) is a sophisticated form of cybercrime that targets organisations through email fraud. By impersonating executives or trusted partners, attackers can orchestrate wire fraud, manipulate invoices, and ultimately steal significant sums of money. The severity of BEC is classified as critical due to its potential for substantial financial loss and reputational damage. Security teams must be vigilant, as the consequences of BEC can be devastating, affecting not only financial stability but also trust in the organisation.
How It Works
BEC attacks typically exploit social engineering tactics and technical vulnerabilities. The most common methods include:
-
Impersonation: Attackers often impersonate high-ranking officials within the organisation or trusted partners. This is typically achieved through email spoofing, where the sender's address appears legitimate but is actually a malicious actor.
-
Compromised Accounts: Attackers may gain access to executive or finance team accounts through phishing or credential stuffing attacks. Once inside, they can set up mailbox rules to forward emails to external addresses or delete sent items, making detection more challenging.
-
Urgent Payment Requests: Attackers craft emails that create a sense of urgency, often requesting payments that deviate from established approval workflows. This urgency can pressure employees into bypassing standard protocols.
-
T1534 Techniques: Attackers may use T1534 (Internal Spear Phishing) to target specific individuals within the organisation, utilising information gleaned from social media or previous interactions to make their communications more convincing.
Detection
Identifying BEC threats requires vigilant monitoring of email traffic and user behaviour. Key indicators include:
-
Unusual Login Events: Monitor for login attempts from unusual locations or devices, particularly for accounts belonging to executives and finance personnel. Sudden changes in login patterns can signify a compromised account.
-
Mailbox Rules: Regularly audit mailbox rules for any unauthorised forwarding to external addresses or rules that delete sent items. This can indicate that an attacker is attempting to cover their tracks.
-
Urgent Payment Requests: Be alert for payment requests that deviate from established workflows, particularly those that create a sense of urgency. Cross-reference such requests with the established approval processes.
-
Email Headers: Examine email headers for signs of spoofing, such as discrepancies in the sender’s domain or authentication failures in SPF, DKIM, or DMARC checks.
Mitigation
To defend against BEC attacks, organisations should implement a multi-layered security approach:
-
Enforce DMARC Policy: Implement a DMARC policy at p=reject for all organisational domains. This will help prevent email spoofing by rejecting unauthenticated emails that appear to come from your domain.
-
Dual-Authorisation for Transfers: Establish mandatory dual-authorisation for all wire transfers above a specified threshold. This requires two individuals to approve a transaction, reducing the risk of unauthorised payments.
-
Advanced Email Security Solutions: Deploy advanced email security solutions that include impersonation detection and AI analysis. These tools can identify suspicious patterns and flag potential BEC attempts in real-time.
-
User Training and Awareness: Conduct regular training sessions for employees to raise awareness of BEC tactics. Educate them on recognising suspicious emails and the importance of verifying requests through alternative communication channels.
-
Incident Response Plan: Develop and maintain an incident response plan specifically for BEC incidents. This should include predefined steps for reporting suspicious emails and procedures for investigating potential compromises.
Recommended Actions
To effectively respond to a suspected BEC incident, security teams should follow this step-by-step response plan:
-
Initial Assessment: Upon receiving a report of a suspicious email or transaction, conduct an immediate assessment to determine the legitimacy of the request.
-
Isolate Compromised Accounts: If an account is suspected to be compromised, immediately isolate it by changing passwords and enabling multi-factor authentication (MFA).
-
Investigate Logs: Review email logs and user activity to identify any unusual patterns, including login events from unusual locations and any mailbox rules that may have been set up.
-
Notify Affected Parties: Inform all parties involved in the transaction about the potential compromise and advise them to halt any payments until further notice.
-
Engage Law Enforcement: If financial loss has occurred, engage local law enforcement and report the incident to the relevant authorities. This can aid in the investigation and recovery of funds.
-
Post-Incident Review: After addressing the immediate threat, conduct a post-incident review to identify gaps in your security posture and update your policies and training accordingly.
-
Continuous Monitoring: Implement continuous monitoring of email traffic and user behaviour to detect any future BEC attempts swiftly.
By adopting these measures, organisations can significantly reduce their risk of falling victim to Business Email Compromise attacks.
In conclusion, the threat of Business Email Compromise is real and growing. Security teams must take proactive steps to detect, defend against, and mitigate this critical threat. CyberZonic offers expert consultancy services to help organisations strengthen their cybersecurity posture against BEC and other evolving threats. Contact us today to learn more about how we can assist you in safeguarding your business.


