BSN 8 24 2020 png

Impersonation Nation

BSN 8 24 2020 png

Business Email Compromise (BEC) is not a new term. BEC scams have been growing in popularity for some time now. If you’re not familiar with BEC, it’s when a fraudulent email is sent to a company or individual, and the email appears to be from a legitimate business resource or person, often varying from the legitimate email address by just a letter or two. There may be instructions within the scam email for the recipient to transfer money, purchase gift cards, click on a malicious link, or perform some other activity at the behest of the sender. Unfortunately, BEC scams often put the recipient at a disadvantage because they see the name or title of the sender and react quickly, or are hesitant to question authority.

So, what’s the secret sauce that cybercriminals use across the board when launching their attacks on unsuspecting victims? According to a recent report from Barracuda, it’s surprisingly simple and straightforward: legitimate email accounts.

Let’s elaborate on that. Barracuda found that hackers launched 100,000 BEC attacks on over 6,000 organizations by using 6,170 legitimate email accounts (which of course, were created with malicious intent). We’re talking Gmail, AOL, and other verified email services.

The report further outlines the details of the attacks, identifying that 45% of the BEC attacks since April of 2020 were carried out with these email accounts. It appears that Gmail is the platform of choice with 59% of the accounts originating there. This may be a result of the cost to create an account (it is free), the ease of registration of a new account, and the solid reputation that a company like Google carries – meaning it is much more likely to pass through security filters.

Change in Identity

While the email account will remain the same, the sender name does get updated from time to time by the cybercriminal in order to go unnoticed by the recipient. These accounts are not often used for more than a 24-hour period and then will go dormant for a while to lessen suspicion or if it has been flagged already, to reduce the likelihood of being detected by another server. That doesn’t mean it goes away forever. Like your MySpace account, it stays out there in cyberspace waiting to be revisited.

Phishing for…Anything

Again, BEC scams are not new and they are just a small ‘subdivision’ of the much bigger issue of phishing – the single most used point of entry to a company in order to breach the data contained within the business infrastructure. And with the cost being minimal (basically it is free to do) and return on investment being potentially huge, the risk far outweighs the benefits.

Ongoing training is one of the best ways to arm employees and clients with the right tools to catch the phish.

badge w light burst white (1)
Exclusively for Our MSP Partners

Now Available: Gen AI Certification From BSN

Lead Strategic AI Conversations with Confidence

Breach Secure Now’s Generative AI Certification helps MSPs simplify the AI conversation, enabling clients to unlock the value of gen AI for their business, build trust, and drive growth – positioning you as a leader in the AI space.

More on blogs

AI Isn’t Replacing Humans. It’s Making Great Employees Even Better.

As concerns about AI replacing jobs continue to grow, many organizations are discovering a different reality: AI works best as a tool that enhances human

The Hidden Cost of Context Switching in the Age of AI

As AI tools accelerate the pace of work, employees are juggling more tasks than ever—leading to constant context switching, burnout, and increased cyber risk. Learn

From Risk to Adoption: Why AI Success Starts with Leadership

AI adoption is accelerating across every industry, but many organizations still lack the training, governance, and leadership needed to use it effectively. Learn why AI
Take the First Step

Experience Training That Makes a Difference

during the demo you’ll:

Take the First Step

Experience Training That Makes a Difference

During the demo you’ll:
situs toto toto toto togel sesetoto desa wisata pujon kidul 13 situs toto toto slot toto slot toto slot toto slot toto slot akuntoto slot gacor slot gacor toto togel toto slot toto slot toto slot toto togel situs toto situs toto https://www.timexplywoodanddoors.com/clients/ toto slot toto slot toto togel toto slot slot hoki99 toto slot gacor bwo303 bwo99 toto slot bwo99 toto slot situs togel toto slot toto slot toto slot online pewe4d slot 4d bwo99 AMANAHTOTO AMANAHTOTO toto togel slot toto https://saint-mathieu.com/spcaroussillon/ slot 4d toto slot slot 4d toto slot toto slot togel slot situs indobet akuntoto slot toto slot 4d babeh188 situs toto agb99 toto toto slot toto slot 4d slot depo 10k situs toto toto togel situs toto toto slot toto togel toto slot toto slot toto toto situs toto toto slot 8kuda4d toto slot judi bola toto situs toto link slot situs toto situs toto toto toto slot situs toto slot toto toto togel situs toto eropa99 login logototo RTP toto slot leon188 situs toto 8kuda4d situs slot gacor situs toto situs toto situs toto situs toto situs toto ilmutoto panen100 mix parlay toto slot toto slot situs toto situs toto situs toto situs toto situs toto toto slot situs toto agen toto togel mawar800 situs toto situs toto titi4d titi4d mataramtoto rtp slot slot gacor slot gacor slot gacor toto mataramtoto pascol4d resmi https://titi4dofficial.com/ toto toto slot gacor mataramtoto toto https://ilmutoto001.com/ PASCOL4D Toto slot 5000 bobatoto ltdtoto sontogel akuntoto ketuatoto bejototo logototo amavi5d sesetoto kientoto ComfortbetGroup slot gacor toto SlotPoker188 popo togel mataramtoto mataramtoto