Audio By Carbonatix
As organisations around the world spend even more on cybersecurity tools, cybercriminals are increasingly using a simple, yet effective ways to access organisations’ data or money through business email compromise (BEC) or CEO fraud.
International security awareness organisation, KnowBe4, explains that BEC is a type of scam in which cybercriminals gain access to – or convincingly replicate – the email address of a senior staff member. They then mail a relevant person within the organisation, instructing them to share information, or assist in making a payment. Because they do not request the recipient to click on a link or open up an attachment, they seem quite innocuous at first and do not trigger any security scanners or warning signs. However, they cause the largest monetary loss related to cybercrime.
BEC wire transfer fraud sees criminals taking advantage of an expected financial transaction such as a supplier payment, and asking the recipient to adjust the bank account information on an outgoing wire transfer. In many cases, the instruction may appear to come from the victim’s boss, and may even be written in a similar style that is used by the boss. Another common type of BEC is gift card scams, in which attackers pretend to be a colleague of the victim and ask them to purchase a digital gift card.
Anna Collard, SVP of Content Strategy&Evangelist for KnowBe4 Africa, says, “35% of all security incidents are business email compromise phishing attacks. According to security vendor GreatHorn’s 2021 Business Email Compromise Report (https://apo-opa.info/47byw0a), 71% of BEC attacks use a spoofed email account or website to establish credibility. Sixty-nine percent of BEC attacks utilise spear phishing, increasing their chances of reaching the right people within an organisation who have influence over money. According to the report, the finance industry is targeted 57% of the time, with CEOs next (22%) and IT third (20%).
“Reducing the risk of such attacks starts with security awareness training. People are sometimes not aware of the value of their email accounts. Beware of falling for phishing emails and ensure that you use strong and unique passwords on all your email accounts. Add another layer such as two-step or multi-factor authentication to your password. Verify any payment requests or change of banking details with the recipient out of band, for example via WhatsApp or a phone call,” Collard says.
KnowBe4’s free Phishing Security Test enables organisations to find out whether their staff would fall for convincing phishing attacks. Sign up for the test here: https://apo-opa.info/3FW1fuJ
Distributed by APO Group on behalf of KnowBe4.
Latest Stories
-
Mahama’s African Games forensic audit reveals over $40m in financial irregularities
22 minutes -
Russia threatens more Kyiv strikes and tells foreign nationals to leave
47 minutes -
I don’t wish NDC well; they’ve become a menace – Miracles Aboagye on NDC internal tensions
52 minutes -
Oil prices slide on hopes of US-Iran peace deal
1 hour -
John Mahama receives customized set of golf clubs ahead of 2026 Head of State Invitational Tournament
1 hour -
‘Recent cedi depreciation within reasonable limits compared to historic rates’ — Prof. Asuming
2 hours -
QNET donates football equipment to S-Inkoom Football Academy
2 hours -
NDC likely to witness fiercest internal contest – Miracles Aboagye
2 hours -
Over 300 actors audition for Big Ghun and Doreen Avio’s ‘Scarlett Unveiled’
3 hours -
MTN introduces 0.75% charges on MoMo-to-bank transfers from June 1
3 hours -
NDC urged to establish clear guidelines to manage growing political ambitions
3 hours -
Tarkwa-Nsuaem teachers declare strike over alleged assault of colleagues by military men
3 hours -
Ghana to ban styrofoam products from January 2027 in major anti-pollution drive
3 hours -
Ghana to host landmark global supply chain summit as EU deforestation deadline looms
3 hours -
Haruna vs Asiedu Nketiah: Tensions could distract gov’t from governance agenda — Dr Osae-Kwapong
3 hours