$2.3 billion has been lost over the past 2.5 years to Business Email Fraud or Whaling Attacks. Let’s take a closer look at what this type of attack involves and how it is successfully exploited by cybercriminals.[su_spacer size=”10″]
The so-called BEC (Business Email Compromise) scams, also known as “whaling attacks” or “CEO scams”, are based on sending fake messages, which appear to have been sent by senior executives of the victims' company and request information regarding a bank account or financial data of any kind.
The seemingly authentic emails are intended to trick employees into transferring funds to the criminals' account.
These attacks have seen a rapid increase in recent years, with the FBI now issuing another statement, warning US businesses.
The Secret Service's warning comes just eight months after an announcement it issued last August. The FBI reported at the time that between October 2013 and August 2015, businesses around the world lost more than $1.2 billion (€1,070,000,000) to whaling attacks.
Companies lost an additional $1.1 billion in the last eight months
The FBI is now updating its data, saying that between October 2013 and February 2016, businesses from 50 US states and 79 other countries reported losses of $2.3 billion, based on 17,642 reports.
This means that between August 2015 and February 2016, companies lost an additional $1.1 billion. Furthermore, between January 2015 and February 2016, the number of BEC scam victims increased by 270 percent.
A similar increase was recorded by third-party observers, such as cybersecurity firm Mimecast, which reported a 55% increase in whaling attacks in Q4 2015, as well as a 67% increase in Q1 2016.
[su_button url=”https://www.secnews.gr/99699/whaling-%ce%bb%ce%ac%ce%b2%ce%b1%cf%84%ce%b5-%ce%bc%ce%ae%ce%bd%cf%85%ce%bc%ce%b1-%ce%b1%cf%80%cf%8c-%ce%b1%cf%86%ce%b5%ce%bd%cf%84%ce%b9%ce%ba%cf%8c-%cf%83%ce%b1%cf%82-%ce%bc%ce%b7%ce%bd-%ce%b5/” target=”blank” style=”glass6″ wide=”yes” center=”yes”]Whaling: Did you get a message from your boss? Don't be so sure![/su_button]
BEC scams are particularly popular as they are easy to carry out, do not require advanced technical knowledge, and allow fraudsters to defraud their victims of significant amounts of money.
Compared to the alternative of using banking trojan botnets, DDoS botnets, or ransomware, fraudsters do not need high-level programming skills or huge server infrastructures, resulting in criminal organizations increasingly turning to this type of fraud.

