HomeSecurityDIE: man in the middle attacks and reliable information

DIE: man-in-the-middle attacks and reliable information

How new is the man in the middle method? The Directorate for the Prosecution of Electronic Crime, in a press release, informs professionals about fraud incidents through the violation of the communication flow of e-mail messages. The service also mentions the method used by fraudsters (man in the middle) to intervene in online financial transactions and convince victims to deposit money into their own account.man in the middle

So somewhere here the rumors begin: We read on a large and "reliable" site of a well-known journalism house that the man in the middle method is new....man in the middle

We will not comment further because the fact itself means a lot to those who know, while those who do not know are very happy that DIE discovered the new man in the middle. Let's not spoil it...

Here is the Press Release:

The Hellenic Police's Cybercrime Prosecution Directorate, as part of its preventive actions, informs professionals about the prevention and avoidance of fraud from the constantly changing forms of fraud via the internet.

Specifically, in recent times, fraudsters, using the "man in the middle" method, have been interfering in parts of the communication between professionals and traders dealing with foreign businesses and convincing them to deposit money into bank accounts other than those initially agreed upon.

More specifically, the method of action for this specific form of fraud (man in the middle) is as follows:

  • The professional communicates via email with his supplier company abroad and agrees to carry out a transaction (placing an order and paying via bank account).
  • At the same time, the perpetrator intercepts, through the use of malicious software or other specialized techniques (e.g. recording communication data via insecure internet connections or capturing access details to the email account using "phishing" techniques), the content of the email conversations between the merchant and the supplier.
  • Subsequently, the perpetrator, pretending to be the supplier, sends an email to the merchant, using an email address that is similar, but not identical, to the one used by the supplier (e.g. promitheftiss@email.com instead of promitheftis@email.com ), demanding, for various reasons, that payment for the order be made to a different bank account than the one initially agreed upon.
  • The merchant is convinced and deposits the money into the new bank account, which belongs to the perpetrator.

It is noted that if the merchant does not realize the fraud in time, the perpetrator may request, under various pretexts, the payment of additional money into his account.

Following the above, the Cybercrime Prosecution Directorate asks professionals to be particularly careful in the event that they encounter such incidents, to avoid possible financial fraud.

In particular, it is recommended that professionals:

  • when they are asked to pay money to a different bank account than the one they usually use, to verify the request, through telephone or other communication with the supplier,
  • to regularly change their email passwords and use two-step verification techniques to log into their email,
  • to use anti-malware programs, both on their computers and on mobile devices (smartphones, tablets), which they should update regularly,
  • to install the available upgrades and security updates/fixes for their operating system and the programs and applications they use,
  • not to open links contained in emails or text messages (sms) from strangers, as these links may refer to malicious websites and/or cause the installation of malicious software,
  • avoid installing programs and applications from unsafe sources,
  • avoid connecting to unsecured free Wi-Fi networks, through which their communication data can be intercepted,
  • use secure and encrypted communication channels and
  • not to respond to emails asking them to reveal their access details (username & password) to their electronic accounts (« phishing » method).

More protection tips and informational material are available on the website http://cyberalert.gr/feelsafe

It is recalled that, for similar incidents, citizens can contact the Cybercrime Prosecution Directorate at the following contact details:

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS