HomeSecurityFBI on BEC attacks: Fraudsters impersonate CEOs in virtual meetings

FBI on BEC attacks: Fraudsters impersonate CEOs in virtual meetings

According to the FBI, hackers are carrying out BEC attacksby impersonating company CEOs on virtual meeting platforms.

FBI virtual meetings

The Federal Bureau of Investigation (FBI) has warned that American organizations and individuals are increasingly being targeted by BEC (business email compromise) attacks on virtual meeting platforms.

BEC attackers use a variety of tactics (including social engineering, phishing, and hacking) to compromise corporate email accounts. The goal is to convince victims to send money to accounts controlled by the attackers.

See also: Strengthen Cybersecurity Amid Russia-Ukraine Crisis, Warns Bank of Greece & Security Services

In this type of attack, scammers target small, medium, and large businesses, as well as individual users. The success rate is very high, as scammers usually pose as people employees trust, such as business partners or CEOs.

Fraudsters impersonate CEOs in virtual meetings

The FBI has observed that scammers carrying out BEC attacks are turning to virtual meeting platforms to target their victims. This move doesn’t seem surprising, given that many employees are working from home, so they use such platforms to communicate with their colleagues. Attackers always exploit trends to have higher success rates.

“Between 2019 and 2021, the FBI IC3 has received numerous reports of BEC attacks related to the use of virtual meeting platforms and directing victims to send funds to accounts,” the FBI reported [PDF].

See also: Ukraine: Ministry of Defense, Army and banks receive DDoS attacks

FBI on BEC attacks: Fraudsters impersonate CEOs in virtual meetings

As the FBI explains, criminals use such platforms in their attacks in a variety of ways. They can participate in virtual meetings impersonating company CEOs or secretly enter meetings to collect business intelligence. In detail, the methods that attackers may use:

  • BEC attackers compromise the emails of an employer or financial director, such as a CEO or CFO, and ask employees to join a virtual meeting platform. There, the criminal uses a static image of the CEO without sound or “deep fake1” audio and tells the victim(s) that the video/audio is not working properly. They then instruct the employees to initiate the funds transfers via the platform’s chat or in a follow-up email.
  • Attackers can also compromise employee email to gain access to corporate meetings via virtual meeting platforms, with the goal of gathering information about a company's daily operations.
  • Finally, they can hack an employer's (e.g. CEO's) email and send messages to employees instructing them to initiate fund transfers, as the CEO claims to be busy and unable to do so from his own computer.

See also: CISA: Federal agencies must fix Chrome and Magento bugs

BEC attacks

BEC attacks can cause major financial losses

According to the FBI's annual 2020 Cybercrime Report, BEC scams are a very lucrative "business" for hackers, having led to losses of approximately $1.8 billion.

It is worth noting that total losses from cybercrime in 2020 were $4.2 billion.

Of the 791,790 complaints received by the FBI's Internet Crime Complaint Center (IC3), 19,369 complaints involved BEC scams or email account compromises (EACs).

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS