Hackers are now targeting food supplies in BEC scams, FBI warns

spam
Image Credit: Evannovostro / Shutterstock (Image credit: Evannovostro / Shutterstock)

Threat actors are transforming business email compromise (BEC) attacks to steal more than just money, experts have warned.

In a joint warning published by multiple US law enforcement agencies, BEC attacks were found to now being against food companies to steal deliveries.

A joint cybersecurity advisory published by the Department of Justice (DoJ), the Food and Drug Administration Office of Criminal Investigations (FDA OCI), and the Federal Bureau of Investigation (FBI) claims hackers are stealing “large shipments of food products and ingredients”, whose market price often reaches “hundreds of thousands of dollars”.

Sending food shipments

The strategy is the same as with any other BEC attack - the hackers would compromise an executive’s email account, and then use it to send fraudulent orders, or would simply imitate an order from a third-party email provider. Whatever the case may be, the result is the same - food companies sending out shipments of food products that never get paid for.

The attackers don’t eat the food, though. They resell it on the black market, which is a risk in itself, as they disregard food safety regulations and sanitation practices, the advisory reads. People that end up eating that food are at risk of various diseases. 

"Companies in all sectors—both buyers and suppliers—should consider taking steps to protect their brand and reputation from scammers who use their name, image, and likeness to commit fraud and steal products," the advisory says.

To protect against these attacks, the organizations say, businesses should educate their employees on the dangers of business email compromise attacks, as well as phishing attacks. 

They should also run frequent training, as means of raising awareness about the risks of clicking on suspicious links or downloading suspicious attachments. Finally, they should regularly scan the internet to see if anyone’s stealing their identity or abusing their image in any way. 

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A graphic showing someone on a tablet working through a supply chain.
How phishing attacks are hitting the supply chain – and how to fight back
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Red padlock open on electric circuits network dark red background
Aviation firms hit by devious new polyglot malware
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Shutterstock.com / kanlaya wanon
Microsoft Teams abused in Russian email bombing ransomware campaign
Phishing
Corporate executives are being increasingly targeted by AI phishing scams
Latest in Security
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Latest in News
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Millwall FC The Den
The UK's first football club mobile network is here - but you probably won't guess which team has launched it
Android Auto
Android Auto 14.0 is rolling out now – and it'll soon swap Google Assistant for the smarter Gemini
The Witcher 4
You're probably not playing The Witcher 4 until 2027 at the earliest, per CD Projekt's latest financial update