Your boss isn't really emailing you - it's a scam

A hand typing on a laptop with email illustrations covering the keyboard
(Image credit: Shutterstock/Billion Photos)

A new and particularly sneaky business email compromise (BEC) campaign has been  spotted that sees victims forwarded an email chain, seemingly coming from their boss, instructing them to send on funds.

Cybersecurity researchers from Abnormal Security explained how the victim usually works in their organization’s finance department, or is otherwise capable of making wire transfers. 

In the email, the attackers assume the identity of a company boss, and forward an earlier email thread with either a partner company, a client, or an organization in the supply chain, and ask the victim to make a payment to those organizations. The entire email thread, designed to give the campaign much-needed legitimacy, is obviously a scam, and the company receiving the transfer belongs to the scammers. 

Bypassing protection

What makes business email compromise attacks so devastating is the fact that these emails usually don’t carry viruses, malware, or malicious links, and as such usually bypass email and endpoint protection services with ease.

"Like all BEC attacks, the reason traditional email defenses have a difficult time detecting them is because they don't contain any of the static indicators most defenses look out for, like malicious links or attachments,” Crane Hassold, director of threat intelligence at Abnormal Security, told ZDNET.

“Most BEC attacks are nothing more than pure, text-based social engineering that traditional email defenses are not well-equipped to detect." 

Abnormal Security analyzed the attacks and believes the campaign originated in Turkey, from a threat actor known as Cobalt Terrapin. The campaign started in July this year.

Although not as popular as ransomware, for example, business email compromise is equally devastating. In fact, last summer the FBI said BEC grew into a $43 billion industry. 

In a recent FBI report, between July 2019 and December 2021, the number of identified global losses, due to business email scams, grew by almost two-thirds (65%). 

The figures are based on incidents that have been reported to the Internet Crime Complaint Center (IC3), and mean that BEC attacks are now more lucrative than the likes of the global tuna industry, or the global used-clothes industry.

Via: ZDNet

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Shopping scams
New wave of sextortion scams uses personal details and images to intimidate targets while bypassing traditional security measures
Red padlock open on electric circuits network dark red background
Aviation firms hit by devious new polyglot malware
linkedin
Watch out - that LinkedIn email could be a fake, laden with malware
Phishing
Corporate executives are being increasingly targeted by AI phishing scams
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Shutterstock.com / kanlaya wanon
Microsoft Teams abused in Russian email bombing ransomware campaign
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand