THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Saturday, October 15, 2022
CEO fraud is a type of financial theft attack in which criminals impersonate a CEO or other C-level executive to obtain sensitive data or money.
FREMONT, CA: CEO fraud is a financial crime attack in which thieves pose as CEOs or other C-level executives to steal money or private information. The offenders frequently coerce an employee of finance or human resources into making unauthorised money transfers or transmitting private tax and payroll information. The attacker ensures that employees witness the infected email by pretending to be the CEO or another high-ranking official. Most employees normally offer the information since they are unwilling to object to a request from their CEO.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
According to the Federal Bureau of Investigation in the United States, CEO fraud is a type of business email compromise (BEC) scam. BEC employs a number of methods, such as computer penetration techniques, social engineering, the compromise of genuine corporate email accounts, malicious software to access inboxes, and others.
A Growing Threat
The prevalence and effects of BEC fraud are rising. Between July 2019 and December 2021, the FBI reported a 65 per cent rise in global losses attributable to BEC. According to the same research, data gathered from the FBI Internet Crime Complaint Centre, law enforcement, and financial institutions showed that scams cost victims more than USD 43 billion USD in 2021 and involved fraudulent bank transfers from more than 140 countries.
Because breach notification is not usually required, the true figures might be significantly higher. Due to potential embarrassment and a desire to protect their reputations, many victims are reluctant to report these cybercrimes. The perpetrators use this guilt to hide the enormous losses brought on by BEC.
Identifying and Compromising CEOs
The perpetrators use platforms like LinkedIn and company websites to identify CEOs and senior executives and obtain their contact details. They then use email or messaging platforms such as WhatsApp to contact the targets and attempt to hijack their accounts. With a stolen email or messaging account, the attacker can access the executive's contacts and use the same scam with CEOs and senior executives at other companies.
Spoofing Sender Details
In CEO fraud emails, the sender's information is frequently manipulated using one of two methods:
When a name spoofing attack is conducted, the attacker uses the CEO's name but a different email address. Sometimes, the false address closely resembles the website of the business. The perpetrator hopes that the recipient will concentrate on the sender's name and miss the wrong address. Many email applications, particularly those on mobile devices, don't show the sender address by default.
The attacker uses the CEO's name and legitimate sender address in name and email spoofing. The recipient's response is transmitted to the attacker directly because the reply-to address is frequently different from the sender's address.
More in News