HomeSecurityFBI: Beware! BEC scammers impersonating construction companies

FBI: Beware! BEC scammers impersonating construction companies

The FBI is warning private sector companies about scammers impersonating construction companies in BEC attacks, targeting organizations across multiple critical infrastructure sectors in the U.S. BEC scammers use a variety of tactics – including social engineering and phishing – to compromise or spoof business email accounts, with the ultimate goal of redirecting pending or future payments to bank accounts under their control.

The FBI issued the warning via TLP: GREEN Private Industry Notification (PIN) sent to organizations on June 9 in an effort to help cybersecurity professionals defend against these active attacks . According to the agency, malicious actors are exploiting the business relationships of construction companies to defraud their customers in the private and public sectors.

Read also: Cyberattacks 2021: Emphasis on ransomware and BEC scams

FBI
FBI

The attacks in question are part of a campaign that began in March and has already led to financial losses ranging from hundreds of thousands to millions of dollars.

To be successful in their attacks, BEC scammers use information collected through online services on the manufacturing companies they are spoofing and the customers they are targeting.

Platforms used to collect valuable data – e.g. contact information, bid data and project costs – include, among others, local and state government budget data portals,

The information collected by the attackers allows them to customize emails designed to exploit the business relationship between the victims and the construction contractors.

See also: BEC scams: From which countries are they carried out and with what goal?

BEC scammers - construction companies
BEC scammers impersonate construction companies

To make the messages more convincing, scammers send emails asking targets to change direct deposit and automated clearing (ACH) account information. The new account information leads to bank accounts controlled by the scammers.

These emails are sent using domains that spoof the legitimate sites of the contractors and the legitimate logos and graphics of the companies, in order to reduce the likelihood that victims will realize that these are "fraudulent" messages.

In March, the FBI issued a warning about another series of BEC attacks increasingly targeting US entities, with losses ranging from $10,000 to $4 million between November 2018 and September 2020.

Suggestion: Microsoft: "BEC attacks targeting schools have increased significantly"!

Additionally, Microsoft last month discovered a large-scale BEC campaign that targeted more than 120 organizations.

BEC scammers
BEC scammers impersonate construction companies

The FBI's 2020 annual report on cybercrime affecting victims in the US highlighted a large number of complaints and financial losses last year.

The FBI reported the following: “The FBI’s Internet Complaint Center (IC3) notes that BEC is a growing and evolving threat as malicious actors become more sophisticated and adapt to current events. There was a 5% increase in losses from 2019 to 2020, with over $1.7 billion in losses reported to the IC3 in 2019 and over $1.8 billion in losses in 2020, respectively.”

In other warnings issued last year, the FBI referred to BEC scammers exploiting automated email forwarding and cloud email services, such as Microsoft Office 365 and Google G Suite, in their attacks.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS