What is a Business Email Compromise (BEC)?
Business Email Compromise (BEC) is a type of scam in which criminals use email fraud to target victims. These victims include both businesses in and around Staffordshire and individuals. They especially target those who perform BACS transfer payments.
The scammer pretends to be a director of the business in Staffordshire. It is easily obtained from Linkedin who the Directors or key people are within a business. Scammers then send emails to employees, customers, or vendors. These emails request them to make payments or transfer funds in some form.
According to the FBI, business email compromise scams cost businesses around $1.8 billion in 2020. That figure increased to $2.4 billion in 2021. These scams can cause severe financial damage to businesses in and around Staffordshire and individuals. They can also harm their reputations of companies that have been built for many years.
How Does Business Email Compromise Work in Staffordshire businesses ?
Business email compromise attacks are usually well-crafted and sophisticated, making it difficult to identify them. The attacker first researches the target organisation and its employees in Staffordshire. They gain the knowledge about the company’s operations, suppliers, customers, and business partners.
Much of this information is freely available online. Scammers can find it on sites like LinkedIn, Facebook, and organisations’ websites. Once the attacker has enough information, they can craft a very convincing email. It’s designed to appear to come from a director or a business partner.
The email will request the recipient to make a payment or transfer funds. It usually emphasizes the request being for an urgent and of a confidential matter. For example, a new business opportunity, a vendor payment, or a foreign tax payment.
The email will often contain a sense of urgency, compelling the Staffordshire recipient to act quickly. The attacker may also use social engineering tactics. Such as posing as a trusted contact or creating a fake website that mimics the company’s site. These tactics make the email seem more legitimate.
If the recipient falls for the scam and makes the payment, the attacker will make off with the funds. In their wake, they leave the Staffordshire business with financial losses that may not be covered by their Cyber Liability insurance policy.
How Staffordshire Businesses Fight Business Email Compromise
Business email compromise scams can be challenging to prevent. But there are measures Staffordshire businesses and individuals can take to cut the risk of falling victim to them.
Organisations in Staffordshire should educate their employees about the risks of business email compromise. This includes providing training on how to identify and avoid these scams. Employees should be aware of the tactics used by scammers. For example, urgent requests, social engineering, and fake websites.
Training should also include email account security, including:
- Checking their sent folder regularly for any strange messages
- Using a strong email password with at least 12 characters
- Changing their email password regularly
- Storing their email password in a secure manner
- Notifying an IT contact if they suspect a phishing email
Enable Email Authentication
Organisations in Staffordshire should implement email authentication protocols.
- Domain-based Message Authentication, Reporting, and Conformance (DMARC)
- Sender Policy Framework (SPF)
- DomainKeys Identified Mail (DKIM)
These protocols help verify the authenticity of the sender’s email address. They also reduce the risk of email spoofing. Another benefit is to keep your emails from ending up in junk mail folders. If your unsure if you have a valid SPF or DMARC record you can check your domain here
Deploy a Payment Verification Process
Staffordshire businesses should deploy payment verification processes, such as two-factor authentication. Another protocol is confirmation from multiple parties. This ensures that all BACS transfer requests are legitimate. It’s always better to have more than one person verify a financial payment request.
Establish a Response Plan
Staffordshire businesses should establish a response plan for business email compromise incidents. This includes procedures for reporting the incident. As well as freezing the transfer and notifying the police.+
Use Anti-phishing Software
Staffordshire businesses and individuals can use anti-phishing software to detect and block fraudulent emails. As AI and machine learning gain widespread use, these tools become more effective.
The use of AI in phishing technology continues to increase. Businesses must be vigilant and take steps to protect themselves.
Does your Staffordshire Business Need Help with Email Security Solutions?
It only takes a moment for money to leave your account and be unrecoverable. Don’t leave your Staffordshire business emails unprotected. Give our Newcastle Under Lyme head office call today to discuss our email security solutions. Or fill in our contact form to discuss how we can secure your email.