A global stop-payment mechanism created by INTERPOLhas successfully recovered more than $40 million stolen in a BEC attack on a company in Singapore.
See also: BEC is now the main method of cyberattack

INTERPOL says this is the largest recovery of funds stolen through a BEC scam. BEC scams are a type of cyberattack in which cybercriminals attempt to redirect legitimate corporate payments to a bank account controlled by the attackers.
These attacks are carried out by threat actors who compromise a seller or company’s email address to trick billing departments into approving new banking information where payment. Once the malicious actors receive the payment, they quickly use the funds to drain the account or transfer it to multiple other accounts under their control.
The FBI's 2023 IC3 Report says they received 21,489 complaints with $2.9 billion in reported losses due to business email breaches.
I-GRIP recovers over $40 million
According to an INTERPOL announcement, a Singapore-based commodities company fell victim to a BEC attack after receiving an email from its alleged supplier.
"On July 15, the company received an email from a supplier requesting that a pending payment be sent to a new bank account based in East Timor," said .
See also: TA4903 hackers impersonate government entities in BEC attacks
Believing this to be a legitimate request, the company sent $42.3 million to bank accounts controlled by the attackers, only to realize four days later that it had fallen victim to a BEC attack, according to INTERPOL.

After reporting the attack to Singaporean authorities, law enforcement used Global Rapid Intervention in Payments (I-GRIP) to request assistance from authorities in East Timor and recover $39 million from the BEC attack.
Further investigations by East Timorese authorities led to the arrest of seven suspects and the recovery of an additional $2 million, bringing the total amount recovered to $41 million.
In June, a global police operation called “Operation First Light” arrested 3,950 people for suspected involvement in phishing, pig butchering scams, fake online shopping websites, and impersonation scams.
I-GRIP was also used during the operation to recover millions of dollars stolen by hackers. Since its launch in 2022, it has been used to recover over $500 million stolen through fraud and cybercrime.
See also: OAuth applications are used in more BEC attacks
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
A BEC attack is a sophisticated form of cybercrime that targets companies and individuals through fraudulent email tactics. In these attacks, cybercriminals impersonate legitimate business contacts or high-ranking executives to trick the victim into transferring funds or sensitive information. These schemes often use social engineering, leveraging research about the target to create a sense of urgency or legitimacy. BEC attacks can lead to significant financial losses as they exploit the trust and relationships built within a business. To protect against such threats, it is vital for organizations to implement strong email verification processes, employee training, and robust cybersecurity measures.
Source: bleepingcomputer
