Admin

New Scam Alert: BEC Attackers Spoof CC'd Execs to Force Payment

InfoSecurity reported:

Security researchers have uncovered another new development in business email compromise (BEC) designed to increase pressure on the recipient to pay a fake invoice.

The fraudster will send an invoice request to a target – potentially working in the finance team of the victim organization – but crucially also copies in (cc) the target’s boss, or rather a spoofed email domain resembling the boss’s email.

“Without proper hindsight, this email replay looks like a legitimate response coming from his or her trusted executive or manager. This only adds to the sense of urgency to pay the invoice, and increases the risk of financial loss for the organization upon compliance with this request.”

With both supplier and now their boss urging prompt payment, it’s more likely that the victim will go ahead and process the transfer, the security vendor argued.

Find the original article and read more here.

Enroll in Training Sessions:  Last Thursday of Every Month is Training on Frauds and New Scam Alerts and How to Combat