# The rise of sophisticated BEC scams in the finance industry
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2019-02-19
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: Mitigating BEC Attacks: A Growing Threat in Finance
Meta Description: Mark Nicholls, Redscan director of cybersecurity, highlights the growing threat of Business Email Compromise attacks in the finance industry. Learn about a
URL: https://financedigest.com/rise-sophisticated-bec-scams-finance-industryhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/img1887-2149-1736839158563-compressed.jpg)

_**Mark Nicholls**, [Redscan](https://www.redscan.com/) director of cybersecurity_

For all the talk of insider threats, cryptojacking and ransomware, I believe that one of the biggest cyber security challenges facing the finance industry in 2019 will be mitigating the elevated risk of Business Email Compromise (BEC) attacks. These attacks involve cybercriminals imitating known contacts, usually C-level executives, in order to trick individuals into wiring payments and funds into alternate bank accounts.

BEC scams are rife in finance due to the high frequency and large sums of money transferred between organisations. They’re also popular because the [returns are often much higher](https://www.financedigest.com/boohoo-warns-on-outlook-blaming-higher-returns-and-pandemic-costs.html "Boohoo warns on outlook, blaming higher returns and pandemic costs") than that of typical email phishing scams.

Modern BEC attacks are incredibly effective, [since hackers are getting better at creating more elaborate campaigns and covering their tracks](https://www.financedigest.com/dollar-on-track-for-best-month-since-2015.html "Dollar on track for best month since 2015") to evade detection. To improve the effectiveness of their communications, cybercriminals will meticulously research [supply chains](https://www.financedigest.com/eliminating-payment-barriers-the-future-of-supply-chain-payments-is-digitization.html "Eliminating Payment Barriers: The Future of Supply Chain Payments is Digitization"), follow company news and events, track social media channels, and even learn employee routines.

Worse still, these types of attacks commonly go unreported, which [means many businesses don’t](https://www.financedigest.com/spiralling-azure-costs-dont-necessarily-mean-your-cloud-strategy-is-off-course.html "Spiralling Azure costs don’t necessarily mean your cloud strategy is off course") realise the full scale of the problem. The truth is that they are quickly becoming ubiquitous.

**[Case study:](https://www.financedigest.com/demand-from-retail-food-and-beverages-sector-to-account-for-over-70-of-refrigerated-display-cases-sales-study.html "Demand from Retail Food and Beverages Sector to Account for over 70% of Refrigerated Display Cases Sales: Study") Specialist M&A insurance broker the target of £300k email fraud**

![Mark Nicholls](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/mark-450x974-1736839158527-compressed.jpeg)

Mark Nicholls

The Redscan team recently uncovered a good example of a particularly sophisticated BEC; an insurance company specialising in high value business mergers and acquisitions had been the victim of a [data breach](https://www.financedigest.com/how-financial-organisations-can-stay-protected-from-financial-data-breaches.html "How Financial Organisations can Stay Protected from Financial Data Breaches ") and asked us to investigate.

Despite conducting regular [staff training](https://www.financedigest.com/why-training-staff-on-new-technology-should-not-be-overlooked.html "Why training staff on new technology should not be overlooked") and maintaining a high level of preventative security controls, the firm nearly found itself as the conduit for sophisticated scam. The attack sought to trick one of its clients into paying £300,000, owed in relation to two outstanding invoices, into a substitute [bank account](https://www.financedigest.com/scams-avoided-how-to-prevent-bank-account-scams-in-2023.html "Scams Avoided: How to Prevent Bank Account Scams in 2023").

Fortunately, the attack was foiled before any payments were made -a vigilant staff member from the [client company](https://www.financedigest.com/impact-com-appoints-a-raft-of-new-business-development-representatives-as-the-technology-companys-client-roster-grows-by-more-than-50.html "impact.com appoints a raft of new Business Development Representatives as the technology company’s client roster grows by more than 50%") had insisted on seeking verbal verification of the substitute banking details supplied -the firm was keen to understand the extent of the compromise and how to safeguard against similar threats. It consequently sought the help of a specialist [cyber security](https://www.financedigest.com/transport-operator-go-ahead-flags-cyber-security-breach.html "Transport operator Go-Ahead flags cyber security breach") company to conduct a full forensic investigation and provide remediation support.

**Tracing the source and ‘kill chain’ of the attack**

The initial focus of the [cyber investigation](https://www.financedigest.com/lloyds-of-london-investigates-possible-cyber-attack.html "Lloyd’s of London investigates possible cyber attack") was email logs relating to the Office 365 account suspected as being used to instigate the fraud. The team quickly identified that six weeks prior to the BEC attack, a senior member of staff had had their corporate account compromised after receiving an email, purporting to be an [official security](https://www.financedigest.com/u-s-russian-officials-set-for-security-talks-on-january-10-u-s-official.html "U.S., Russian officials set for security talks on January 10 – U.S. official") alert from Microsoft, which requested that the user login to their account to review suspicious login activity.

Subsequent analysis revealed that, following the original phishing attack, hundreds of Office account login attempts were initiated from a range of malicious IP addresses originating from Nigeria, China and the UAE, from where a number of successful logins were made.

With full access to the user’s Office account, the attacker created mailbox rules designed to scan all incoming emails for keywords, moving interesting items to a hidden folder within Outlook, from where they were promptly deleted. The team later discovered that the attacker had also set up an email rule to auto-forward all incoming and outgoing [emails to an external Gmail address](https://www.financedigest.com/how-to-create-a-professional-email-address.html "How to Create a Professional Email Address").

Over the course of a week following detection of the attack, the email forward had delivered more than 280 emails to these fraudulent accounts, resulting in the unauthorised disclosure of highly confidential client details and payment information.

One email thread to capture the attention of the attacker was related to the billing of two high value invoices, which had been raised by the [insurance firm](https://www.financedigest.com/digital-marketing-for-finance-and-insurance-firms-is-changing-are-you-ready.html "Digital marketing for finance and insurance firms is changing — Are you ready?") to its client. With a target identified, the attacker set about sending a chain of spoof emails, which requested payment of the invoices to an alternate bank account. In one of the emails, the attacker offered to call the client to provide additional verification. The source of the spoofed emails was a domain set up to closely resemble that of the insurance firm.

**How to respond and mitigate BEC attacks**

This [case study](https://www.financedigest.com/case-handling-machines-market-global-size-growth-opportunities-industry-potential-segmentation-overview-trends-and-forecast-studies-2028.html "Case Handling Machines Market Global Size, Growth Opportunities, Industry Potential, Segmentation Overview, Trends And Forecast Studies 2028") is a great demonstration of how far cybercriminals will go to deceive their targets. The BEC attack was very close to achieving its objectives and would have done so had it not been for a diligent employee insisting on [seeking telephone approval prior to processing payments](https://www.financedigest.com/ukraine-seeks-debt-payment-freeze-as-war-ravages-economy.html "Ukraine seeks debt payment freeze as war ravages economy").

Verbal authorisation might seem like an obvious mitigating control, but it’s not one enforced by many companies. One of the most famous financial [sector](https://www.financedigest.com/is-automation-key-to-esg-success-in-the-banking-and-finance-sector.html "Is automation key to ESG success in the banking and finance sector?") breaches in recent years, the $1bn Bangladesh Bank cyber heist, was due in part to the fact sufficient protocols for checking payment transfers were not in place.

To [mitigate the risk](https://www.financedigest.com/new-isla-standards-provide-the-foundation-for-resource-optimisation-efficiency-and-risk-mitigation.html "New ISLA Standards Provide the Foundation for Resource Optimisation, Efficiency and Risk Mitigation") of BEC attacks, firms should implement a range of controls and processes to not only prevent these types of scams, but also detect and respond to them as quickly as possible. In the wake of the attack, the M&A firm’s IT team was advised to enforce multi-factor authentication across all user accounts as well as activate full mailbox audit logging in Office 365 to increase visibility of anomalous activity such as failed sign in attempts and policy violations. A review of the company’s security training programme was also recommended.

For organisations that want to further reduce security risk, SIEM (Security Information and Event Management) and EDR (Endpoint Detection and Response) tools are highly recommended to help improve threat visibility across on-premise and [cloud environments](https://www.financedigest.com/how-to-manage-identity-in-a-hybrid-cloud-environment.html "How to manage identity in a hybrid cloud environment").

Following recent news from the FCA that a third of finance firms do not conduct regular security assessments such as [penetration testing](https://www.financedigest.com/penetration-testing-market-to-register-an-impressive-cagr-of-13-9-during-2017-2027-ibm-corporation-rapid7-inc-microfocus-qualys-inc-synopsys-inc.html "Penetration Testing Market to Register an Impressive CAGR of 13.9% During 2017 – 2027 |IBM Corporation, Rapid7, Inc., Microfocus, Qualys, Inc., Synopsys Inc"), more must also be done to regularly evaluate the effectiveness of security controls and identify security vulnerabilities in response to common attack scenarios. Simulated engagements can also help to raise employee [cyber awareness](https://www.financedigest.com/selfie-awareness-the-cyber-risk-going-undetected-in-banks.html "Selfie-awareness: the cyber risk going undetected in banks").

Every [year seems to bring new security risks for finance](https://www.financedigest.com/is-2022-the-year-green-finance-incorporates-climate-risk.html "Is 2022 the year green finance incorporates climate risk?") firms. You can bet that 2019 will be more of the same, and that [mitigating the risk](https://www.financedigest.com/ai-holds-the-key-for-both-competitive-advantage-and-risk-mitigation-in-2022.html "AI holds the key for both competitive advantage and risk mitigation in 2022") of BEC attacks will continue to pose significant challenges.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

