Toutes les vulnérabilités
CRITICALPhishing

PHISH-BEC

Phishing · BEC · Business email compromise (BEC)

Résumé

Business email compromise is a social-engineering fraud in which an attacker impersonates a trusted party (an executive, a supplier, an attorney, payroll) over email to trick staff into wiring money or changing payment details. No malware is required; it abuses trust and weak payment process. Attackers either spoof a lookalike domain or take over a real mailbox and watch threads to time the request to a live invoice. The FBI's Internet Crime Complaint Center ranks BEC the costliest cybercrime category by dollar losses, identifying roughly $51 billion in exposed losses globally between October 2013 and December 2022, rising to about $55 billion by 2023, reported across more than 177 countries. Common variants are CEO/wire fraud, vendor and invoice fraud, payroll diversion, and real-estate closing fraud.

Comment l’éviter dans votre code

  • Verify any payment or bank-detail change out-of-band, using a phone number already on file, never one supplied in the email.
  • Deploy DMARC at p=reject with SPF and DKIM so spoofed sender domains are rejected before delivery.
  • Flag external and lookalike-domain mail at the gateway and alert on newly registered or homoglyph domains.
  • Require dual approval and a purchase-order match for wire transfers and vendor banking changes above a threshold.
  • Train finance and accounts-payable teams on invoice-fraud patterns and give everyone a one-click report-phish button.

Références

Vulnérabilités liées

Tout Phishing →