Microsoft Warns of Increase in Business Email Compromise Attacks

Microsoft has released a new report alerting businesses to the alarming surge in business email compromise (BEC) attacks and the evolution of tactics employed by cybercriminals.

Entitled “The Confidence Game,” the Cyber ​​Signals report provides a comprehensive analysis of the threat landscape from April 2022 to April 2023, with the company’s systems currently experiencing an average of 156,000 threats daily. suggests that it is detecting and investigating BEC attacks for These attacks have increased significantly by 38% over the past four years.

To learn more about this trend, see Phishing Surge Doubles BEC Transaction Volume.

According to Microsoft research, attackers are increasingly using platforms such as BulletProftLink to organize large-scale malicious email campaigns. BulletProftLink provides cybercriminals with end-to-end services, including templates, hosting and automation services, making it easy for them to execute BEC attacks.

By purchasing IP addresses that match the victim’s location, attackers can hide their origin, making it difficult to track and attribute their activity. This tactic is mostly observed in Asian and Eastern European countries.

Additionally, Microsoft warned that the specialization and consolidation of the cybercriminal economy in this space could lead to an increase in the use of residential IP addresses to evade detection. Cybercriminals typically leverage these addresses to harvest compromised credentials and access accounts, which can lead to catastrophic financial loss to an organization.

The report also highlights the increasing sophistication of BEC attacks. While traditional “phishing-as-a-service” tools are still prevalent, the aforementioned BulletProftLink, for example, employs a decentralized gateway design and utilizes public blockchain nodes to host phishing sites and his BEC site. . A decentralized approach therefore makes it significantly harder to stop these malicious activities.

Microsoft cited figures from the FBI’s Recovered Assets team, which recorded 2,838 BEC complaints in 2022 related to domestic transactions with potential losses in excess of $590 million.

To combat the growing threat, Microsoft recommends several precautions. This includes maximizing the security settings of your email system, enabling notifications for unverified email senders, and blocking suspicious identities.

Strong authentication, such as multi-factor authentication and passwordless technology, is also important for securing email accounts. Additionally, organizations should invest in employee training to recognize the warning signs of BEC attacks and deploy secure payment platforms to authenticate transactions.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *