Business email attacks are going increasingly mobile


Business Email Compromise (BEC) attacks – in which threat actors assume the identities of business executives over email and try to trick employees into sending a wire transfer or something similar – are going mobile, security experts have warned.
A report (opens in new tab) from Trustwave found the number of BEC attacks that leverage the Short Message Service (SMS) instead of email has been steadily increasing.
The process is almost identical – the attacker would reach out to the victim, introduce themselves as one of the company’s executives, and share a copy of an aging report. In the same message, they’d ask the victim to initiate a wire transfer, change a payroll account, or have them transfer company funds in some other way.
More potent than email
There are many benefits to using SMS for BEC attacks instead of emails, the researchers say. The obvious one is that there are fewer elements that can make the target suspicious. While every email carries the sender’s address, which can be the first way to check for potential fraud, an SMS message only has the phone number and in many cases, employees don’t have their bosses’ numbers and might not double-check them.
Furthermore, the attackers can decline a potential phone call, saying they’re in a meeting or otherwise unable to answer the call. Finally, SMS communication is a lot faster than email, allowing threat actors to get the job done a lot quicker, with Trustwave also highlighting a Federal Communications Commission (FCC) report stating unsolicited text messages tripled in 2022, compared to 2019.
Initiating wire transfers is also something that might raise suspicions, which is why fraudsters usually ask the victims to purchase a gift card, instead. They would promise the victims that their purchase would be reimbursed. Most of the time, the crooks would ask their targets to purchase gift cards from Target, Google Play, Apple, eBay, or Walmart.
To protect against SMS-based BEC attacks, businesses should educate their workforce on security (opens in new tab) awareness, and have them always verify people’s identities when communicating via text messages, Trustwave said.
Furthermore, they should raise awareness among their employees that private data can be scraped from social media accounts and used in attacks, and finally – they should insist on multi-factor authentication (MFA) wherever possible, to make it harder for threat actors to gain access to valuable systems.
Audio player loading… Business Email Compromise (BEC) attacks – in which threat actors assume the identities of business executives over email and try to trick employees into sending a wire transfer or something similar – are going mobile, security experts have warned. A report (opens in new tab) from Trustwave…
Recent Posts
- Windows 11 24H2 hasn’t raised the bar for the operating system’s CPU requirements, Microsoft clarifies
- OpenSSH vulnerabilities could pose huge threat to businesses everywhere
- Magic: The Gathering’s Final Fantasy sets will tell the stories of the games
- All of Chipolo’s Bluetooth trackers are discounted in sitewide sale
- Fortnite: Lawless gets first trailer highlighting the new season’s battle pass roster and the chaos of Crime City
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010