The FBI is warning corporate users about BEC attacksthat exploit Microsoft Office 365 and Google G Suite.
“The scams are launched through specially designed phish kits that mimic cloud-based email services to compromise corporate accounts and request or transfer funds,” the FBI said a few days ago.
“From January 2014 to October 2019, the Internet Crime Complaint Center (IC3) received complaints of over $2.1 billion in losses from BEC scams targeting Microsoft Office 365 and Google G Suite.”
BEC scammers in the cloud
Cybercriminals have begun targeting cloud-based email services as more and more companies turn to the cloud.
Victims are redirected to phishing kits, which are used as part of these BEC attacks through phishing campaigns. The phishing kits are capable of detecting the “service associated with the compromised credentials.”
“Cybercriminals analyze content to look for evidence of financial transactions,” the FBI explains.
“Using the information collected from the compromised accounts, criminals mimic email communications between the compromised businesses and third parties (vendors or customers).”.
Fraudsters impersonate employees of compromised organizations or their affiliates, attempting to redirect payments to bank accounts under their control.
They also steal partner information, which they can use at a later time for other phishing attacks that will put other businesses at risk .
Tips for defending against BEC attacks
Microsoft Office 365 and Google G Suite have security features that can help prevent BEC attacks. However, many of these must be configured by IT administrators and security teams .
“For this reason, small to medium-sized organizations or those with limited IT resources are more vulnerable to BEC scams,” the FBI added.
The FBI has issued a series of tips to prevent BEC attacks:
- Disable automatic email forwarding to external addresses.
- Add an email banner to messages coming from people outside the organization.
- protocols email legacy, such as POP, IMAP, and SMTP, which do not support multi-factor authentication.
- Turn on notifications for suspicious activity.
- Enable security features that block malicious emails, such as anti-phishing and anti-spoofing policies.
- Configure Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication Reporting and Conformance (DMARC) to prevent spoofing and validate emails.
Other tips for preventing BEC attacks include:
- Enable multi-factor authentication for all accounts .
- Checking and confirming all payments and transactions.
- training on BEC scams and phishing attacks.
The IC3 announced in September 2019 that BEC scams continue to increase every year. According to victims' complaints, over $26 billion has been lost in three years.
Many large companies, such as Toyota Group and Nikkei have fallen victim to such fraud and lost a lot of money.

