FBI — business email compromises is one of the biggest threats your firm faces right now

best free email services
Best Free Email Services (Image credit: Image by Gerd Altmann from Pixabay)

A business doesn’t have to wire money to a fraudster’s account to be a victim of a Business Email Compromise (BEC) attack, as hackers are using known tactics to steal goods and commodities, too, a new FBI alert has warned.

The US law enforcement agency released a public service announcement recently, warning businesses of an ongoing BEC campaign that does just that. 

The fraudsters would impersonate current, or former, employees of existing, legitimate US-based businesses. In some cases, the two firms work together (or have done so in the past).

Rising popularity of BEC

The attackers would then initiate a purchase of certain commodities, tricking the victim into shipping them out to a physical address under the fraudsters’ control. The victims would only realize they were defrauded when they sought to collect payment.

In some cases, that wouldn’t happen for the next couple of months, as the fraudsters would often apply, and be granted, credit repayment terms known as Net-30 and Net-60. They would provide fake credit references and fraudulent W-9 forms which would allow them to initiate additional purchase orders without paying for them upfront. 

While this type of attack is low-complexity and doesn’t require any specific technical knowledge or expertise, it does require insights into how business payments usually work, which would mean the attackers did their homework.

In fact, BEC is so easy to pull off, that it recently surpassed ransomware to become the number one most popular type of cybercrime in the world. According to a recent report from cybersecurity experts Secureworks the number of BEC incidents doubled in the past year, to become the most common type of attack.

The fraudsters are after a wide variety of commodities, the FBI claims, including construction materials, agricultural supplies, computer technology hardware, or solar energy products.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Close up of a person touching an email icon.
Top US mineral firm hit by cyberattack that saw thieves steal $500,000
Representational image of a hacker
Email scams vs Phishing - is there a difference?
Shopping scams
New wave of sextortion scams uses personal details and images to intimidate targets while bypassing traditional security measures
Phishing
Corporate executives are being increasingly targeted by AI phishing scams
Red padlock open on electric circuits network dark red background
Aviation firms hit by devious new polyglot malware
Hacker silhouette working on a laptop with North Korean flag on the background
FBI claims North Korean workers are hacking the US companies which hired them
Latest in Security
A TV remote pointing at YouTube logo
YouTube warns of phishing video using its CEO as bait
China
Microsoft says Chinese Silk Typhoon hackers are targeting cloud and IT apps to steal business data
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
BadBox malware hit after infecting over 500,000 Android devices
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Latest in News
An Nvidia GeForce RTX 5080 resting on an RTX 5090 on a gray crafting mat.
Corsair tells us only one of its prebuilt PCs with an RTX 5000 GPU has suffered from chip-level fault, suggesting it’s as rare as Nvidia claimed
ChatGPT WhatsApp
New survey suggests the vast majority of iPhone and Samsung Galaxy users find AI useless – and to be honest, I’m not surprised
A hunter holds up a Grav Bowfin and smiles
How to catch a Gravid Bowfin in Monster Hunter Wilds
Fujfilm GFX 50R
First Fujifilm GFX100RF images leaked in build-up to expected reveal – here’s what they tell us about the unique premium compact camera
Samsung Galaxy Z Flip 6 in blue
The Samsung Galaxy Z Flip 7 could have a Motorola Razr-style full-sized cover screen – and I think it’s about time
Spotify logo on a mobile device
Had Spotify problems recently? It's clamped down on Premium APK 'modded' apps – here's what's happening