Business Email Compromise Jumped 81% Last Year! Learn How to Fight It

Tanya Wetson-Catt • 17 July 2023

In recent years, electronic mail (email for short) has become an essential part of our daily lives. Many people use it for various purposes, including business transactions. With the increasing dependence on digital technology, cybercrime has grown. A significant cyber threat facing businesses today is Business Email Compromise (BEC).


Why is it important to pay particular attention to BEC attacks? Because they’ve been on the rise. BEC attacks jumped 81% in 2022, and as many as 98% of employees fail to report the threat.


What is Business Email Compromise (BEC)


Business Email Compromise (BEC) is a type of scam in which criminals use email fraud to target victims. These victims include both businesses and individuals. They especially target those who perform wire transfer payments.


The scammer pretends to be a high-level executive or business partner. Scammers send emails to employees, customers, or vendors. These emails request them to make payments or transfer funds in some form.


According to the FBI, BEC scams cost businesses around $1.8 billion in 2020. That figure increased to $2.4 billion in 2021. These scams can cause severe financial damage to businesses and individuals. They can also harm their reputations.


How Does BEC Work?


BEC attacks are usually well-crafted and sophisticated, making it difficult to identify them. The attacker first researches the target organization and its employees. They gain knowledge about the company’s operations, suppliers, customers, and business partners.

Much of this information is freely available online. Scammers can find it on sites like LinkedIn, Facebook, and organizations’ websites. Once the attacker has enough information, they can craft a convincing email. It's designed to appear to come from a high-level executive or a business partner.


The email will request the recipient to make a payment or transfer funds. It usually emphasizes the request being for an urgent and confidential matter. For example, a new business opportunity, a vendor payment, or a foreign tax payment.

 

The email will often contain a sense of urgency, compelling the recipient to act quickly. The attacker may also use social engineering tactics. Such as posing as a trusted contact or creating a fake website that mimics the company's site. These tactics make the email seem more legitimate.


If the recipient falls for the scam and makes the payment, the attacker will make off with the funds. In their wake, they leave the victim with financial losses.


How to Fight Business Email Compromise


BEC scams can be challenging to prevent. But there are measures businesses and individuals can take to cut the risk of falling victim to them.


Educate Employees


Organizations should educate their employees about the risks of BEC. This includes providing training on how to identify and avoid these scams. Employees should be aware of the tactics used by scammers. For example, urgent requests, social engineering, and fake websites.


Training should also include email account security, including:


  • Checking their sent folder regularly for any strange messages
  • Using a strong email password with at least 12 characters
  • Changing their email password regularly
  • Storing their email password in a secure manner
  • Notifying an IT contact if they suspect a phishing email


Enable Email Authentication


Organizations should implement email authentication protocols.


This includes:


  • Domain-based Message Authentication, Reporting, and Conformance (DMARC)
  • Sender Policy Framework (SPF)
  • DomainKeys Identified Mail (DKIM)


These protocols help verify the authenticity of the sender's email address. They also reduce the risk of email spoofing. Another benefit is to keep your emails from ending up in junk mail folders.


Deploy a Payment Verification Process


Organizations should deploy payment verification processes, such as two-factor authentication. Another protocol is confirmation from multiple parties. This ensures that all wire transfer requests are legitimate. It’s always better to have more than one person verify a financial payment request.


Check Financial Transactions


Organizations should deploy payment verification processes, such as two-factor authentication. Another protocol is confirmation from multiple parties. This ensures that all wire transfer requests are legitimate. It’s always better to have more than one person verify a financial payment request.


Establish a Response Plan


Organizations should establish a response plan for BEC incidents. This includes procedures for reporting the incident. As well as freezing the transfer and notifying law enforcement.


Use Anti-phishing Software


Businesses and individuals can use anti-phishing software to detect and block fraudulent emails. As AI and machine learning gain widespread use, these tools become more effective.


The use of AI in phishing technology continues to increase. Businesses must be vigilant and take steps to protect themselves.


Need Help with Email Security Solutions?


It only takes a moment for money to leave your account and be unrecoverable. Don’t leave your business emails unprotected. Give us a call today to discuss our email security solutions.

Let's Talk Tech

More from our blog

by Tanya Wetson-Catt 21 February 2025
These days, everything is digital. We deal with data every day: from personal photos to work files that hold a lot of value. What happens if you lose that? Well, this is the reason behind doing secure backups of data. Let’s go through some best practices to keep your data safe and secure. What is Data Backup? Data backup refers to the creation of a copy of your data. The copy can be used in the event of loss or destruction of the original data. Backups can be stored on various devices, such as external hard drives, or in the cloud. Having a backup ensures you don’t lose important information. Why Is Secure Backup Important? Backing up will save your data from being lost forever. Sometimes computers crash, or get viruses. Other times, you may delete some important files accidentally. If you do not have a backup, then you could lose everything. Backing up your data keeps it safe from these problems. How Often Should You Back Up Your Data? Backing up your data is very important and should be done regularly. Some people back up their data every day, while others do it on a weekly basis. It depends on how often your data changes. If you have important files that change daily, then you should back them up every day. Regular backups mean you will always have the latest version of your files. What Are The Different Types of Backups? There are several types of backups you can use: Full Backup A full backup copies all your data. It takes more time and space but is very thorough. Incremental Backup An incremental backup only copies new or changed files since the last backup. It saves time and space. Differential Backup A differential backup copies all changes made since the last full backup. It’s faster than a full backup but takes more space than an incremental one. Where to Store Your Backups? The place of storage for your backups is an important consideration: External Hard Drives These are physical devices you can store at home or at work. It’s convenient, but they can get lost or damaged. Cloud Storage It keeps your backups online, so it is safe from any form of physical damage. It’s also easily accessible from any location. Offsite Storage Offsite storage means keeping backups in a different location than your main data. This protects against theft or natural disasters. How Can You Ensure Your Backups Are Secure? Keeping your backups secure is as important as making them: Use Encryption Encryption scrambles your data so only you can read it. This keeps it safe from hackers. Set Strong Passwords Use strong passwords for all your backup accounts and devices. This prevents unauthorised access. Regularly Test Your Backups Testing ensures that your backups work properly. Try restoring a file to make sure everything is correct. What Tools Can Help With Data Backup? Many tools can help automate and manage backups: Backup Software Backup software can schedule and perform backups automatically. This makes it easier to keep up with regular backups. Cloud Services Many cloud services include automatic backups in their package. They provide extra security features too. What Should You Avoid In Data Backup? Here are some of the common mistakes to avoid while backing up your data: Not Having Multiple Copies Always have more than one copy of your backup in different places. Ignoring Security Updates Keep all backup software and devices updated to protect against new threats. How Can You Make A Backup Plan? Creating a backup plan helps you get organised by: Determining what data should be backed up. Frequency of backups. Where the backups will be located. Reminders to test regularly. Take Action To Protect Your Data Today! Don’t wait until it’s too late to protect your data. Start backing up today! Secure your important files by following these best practices for data backup. If you need help setting up a secure backup system, contact us today!
by Tanya Wetson-Catt 17 February 2025
Password managers keep our online accounts safe. They store all our passwords in one place. But are they hackable? What are Password Managers? Password managers are like digital vaults: they save all your passwords inside themselves. You need only remember one master password, of course. This makes keeping a lot of accounts much easier to handle. How Do They Work? You make one main password. The manager scrambles your passwords. What this means is, it changes them into an unreadable format without a key. Why Use Them? People use password managers out of convenience and security. One single factor is the difficulty in remembering several strong passwords. A password manager allows you to generate and securely store all these. Can Password Managers be Hacked? They always hunt for ways to steal your information. However, breaking into a password manager is not easy. Security Measures Password managers use very strong encryption. This makes them barely readable by hackers. They are also using two-factor authentication-2FA. The addition of this adds a layer of security. No system is perfect. If a hacker gets your master password, then they can access your vault. A few managers have had security issues in the past, but these are rare. How Can You Protect Your Password Manager? You can take steps to keep your password manager safe. Choose a Strong Master Password Make your master password long and unique. Use a mix of letters, numbers, and symbols. Enable Two-Factor Authentication 2FA adds a layer of security. Even if someone knows your password, they need another code to log in. Keep Software Up-to-Date Always update your password manager. Updates fix security issues and keep your data safe. What Happens If a Password Manager Gets Hacked? If a password manager gets hacked, it can be serious. Hackers could access all your passwords. Immediate Actions Change your master password immediately. Decide which accounts could be affected and change their passwords as well. Long-Term Solutions Consider shifting to another password manager if it has been compromised anytime earlier. Keep up to date with any security news about your manager. Is the Use of Password Managers Worth the Risks? Despite the risks, many people still use password managers. They make managing passwords much easier. It’s also safer than trying to remember them all yourself. Benefits Outweigh Risks The benefits of using a password manager usually outweigh the risks. They help you create strong, unique passwords for each account. Trustworthy Options Choose a reputable password manager with good reviews and security features. Do some research before deciding which one to use. Take Control of Your Online Security Today! Using a password manager will go a long way in enhancing your online security. Remember to choose a strong master password. You should also use two-factor authentication and keep your software updated.  If you have any questions or need help in the selection of a password manager, contact us today!
by Tanya Wetson-Catt 14 February 2025
Encryption is a method of securing information. It converts readable data into secret code. Only the right key can decode it. This guide will help you understand different encryption methods. What is Encryption? Encryption is like a secret language. It converts regular text into unreadable text. This unreadable text is called ciphertext. Only people who have the right key will be able to convert it into normal text, called plaintext. Why Do We Use Encryption? We use encryption to keep our information safe. It makes our data safe from hackers. This is very important for privacy and security. How does Encryption Work? Encryption uses algorithms and keys. An algorithm is a set of rules for solving problems. A key is somewhat like a password that unlocks the secret message. Symmetric vs Asymmetric Encryption There are two main types of encryption: symmetric and asymmetric. Symmetric encryption uses the same key for encryption and decryption. The same key is shared between the sender and receiver. It’s fast but less secure when the key is shared. Asymmetric encryption uses two keys: a public key and a private key. A public key can encrypt a message, while a private key can decrypt it. It’s more secure since only the private key unlocks the message. What Are Some Common Encryption Methods? There are numerous encryption methods in use today. Here are some of the most common ones: AES (Advanced Encryption Standard) AES is one of the most secure forms of encryption. It is symmetric encryption. AES can have 128, 192, or 256-bit keys. The longer the key, the harder it is to break. RSA (Rivest-Shamir-Adleman) RSA is an asymmetric encryption method. It uses two keys: a public and a private key. RSA is widely used for secure data transmission. DES (Data Encryption Standard) DES was once a popular symmetric encryption method. It uses a 56-bit key, which is now considered weak. DES has mostly been replaced by AES. ECC (Elliptic Curve Cryptography) ECC is an asymmetric technique that offers better security and more compact key sizes. It is efficient and widely adopted in various mobile gadgets. How Do We Use Encryption in Everyday Life? Encryption plays a major role in our daily life routines. Online Shopping When you purchase online, your payment information is encrypted. This protects your credit card information against hackers. Messaging Apps Apps like WhatsApp use encryption to keep your messages private. Only you and the person you are chatting with can read them. Email Security Many email services use encryption to protect your emails from being read by others. What Are the Challenges of Encryption? Encryption has many benefits, but it also faces challenges. Key Management Managing keys securely is a challenge. If some person loses their key, they probably will lose their data. Performance Issues Encryption could slow down the systems since it needs processing power for encryption and decryption. How Can You Stay Safe with Encryption? You can take some steps to securely use encryption. Use Strong Passwords Always use strong passwords for accounts and devices. That will make hacking difficult as it will take time to access. Keep Software Up-to-Date Regularly update your software to protect against security vulnerabilities in software. Use Caution with Public Wi-Fi If you need to use public Wi-Fi, avoid sensitive transactions unless you can encrypt your internet connection using a VPN. Ready to Secure Your Data? Encryption helps protect your personal information from threats. Understanding different methods can help you choose the right one for your needs.  If you want more information or need help securing your data, contact us today!
Share by: