Article

Business Email Compromise: A Scam that Could Cost Your Company

Jan 01, 0001

Sam discovers that both emails were fraudulent, that there was no sale, and that he wired $500,000 of ABC’s money directly to fraudsters. ABC was the victim of a business email compromise (BEC) scam (also known as CEO fraud).

Ron Cresswell, J.D., CFE
Research Specialist, ACFE


Sam is the corporate controller of ABC, Inc., an online furniture retailer. As part of his job, Sam approves wire transfers to ABC’s suppliers, many of them Chinese companies. One day, Sam receives an email from ABC’s CEO. The email says that ABC just completed negotiations to buy one of its Chinese suppliers. The email tells Sam to await instructions from ABC’s accounting firm and to speak to no one else about the sale. According to the email, SEC regulations require the details of the sale to remain confidential at this point. A few hours later, Sam receives an email from ABC’s accounting firm, which instructs him to wire $500,000 to a Chinese bank immediately. Sam approves the wire transfer.

Later, Sam discovers that both emails were fraudulent, that there was no sale and that he wired $500,000 of ABC’s money directly to fraudsters. ABC was the victim of a business email compromise (BEC) scam (also known as CEO fraud).

The FBI has issued several public service announcements warning of the rapid and alarming increase in BEC scams. In the most recent public service announcement, issued on June 14, 2016, the FBI estimates that BEC scams have resulted in over $3 billion in exposed dollar loss [1] worldwide. From October 2013 to May 2016 alone, there were over 15,000 victims of BEC scams and over $1 billion in exposed dollar loss. According to the FBI, BEC scams have been reported in over 100 countries and the majority of the fraudulently transferred funds go to Chinese banks.

 

How BEC Scams Work

In the traditional BEC scam, a fraudster uses a fake email from an executive (e.g., CEO, CFO) to trick an employee into wiring funds to the fraudster. The executive’s email account may be compromised by social engineering or computer intrusion techniques (e.g., malware). Sometimes emails are spoofed by adding, removing or changing characters in the email address. For example, if a CEO’s email address is John.Smith@ABCINC.com, the fake email may come from John.Smit@ABCINC.com (the “h” in “Smith” is missing) or John.Smith@ACBINC.com (the letters “B” and “C” in “ABCINC” are transposed). This makes it difficult to spot the fake email address.

Prior to initiating the scam, fraudsters generally perform extensive research on the company, the executive and the person who will receive the fake email. Fraudsters use publicly available information (especially on the company’s website), social engineering, hacking and phishing to learn about the company’s employees, organizational structure and payment procedures. The fake emails are often well written and they sometimes mimic language used by the executive in prior emails.

The traditional targets of BEC scams are companies that work with foreign suppliers or that regularly make payments by wire transfer. However, as BEC scams have evolved, all types of companies have been targeted.



Fraud


Five Types of BEC Scams

 

Although BEC scams can take numerous forms, the FBI has identified five main scenarios by which BEC scams are perpetrated. Those scenarios are as follows:

  • Scenario 1: Fraudsters posing as a company’s foreign supplier send an email to an employee of the company and request that funds be transferred to an alternate account controlled by the fraudsters.
  • Scenario 2: The compromised email account of a high-level executive is used to ask an employee to transfer funds to the fraudsters’ account. 
  • Scenario 3: Fraudsters use an employee’s compromised email account to identify the company’s vendors and ask them to transfer funds to the fraudsters’ account.
  • Scenario 4: Fraudsters posing as the company’s attorney contact an employee and request a transfer of funds to the fraudsters’ account. The fraudsters often insist that the employee act quickly and secretly.
  • Scenario 5: The compromised email account of a high-level executive is used to request W-2s or other personally identifiable information from the employee responsible for maintaining such information. This is a tactic recently identified by the FBI and it may be used to gather information for one of the scenarios described above.

 

How Companies Can Protect Themselves

While companies cannot prevent being targeted by a BEC scam, they can take certain actions to prevent the scam from succeeding. First, companies should educate their employees and vendors about BEC scams. People are less likely to be victims of BEC scams if they understand how the scams work. Second, companies should implement a two-step verification procedure for certain transactions. For example, an employee who receives an email request for a wire transfer might be required to verify the request with a telephone call.

In addition, the FBI has suggested the following strategies to prevent BEC scams:

  • Establish a company domain name and a company email account. Avoid free, web-based email accounts.
  • Do not post sensitive information on company websites or social media. Sensitive information can include job duties and descriptions, organizational charts, and employee schedules or travel details.
  • Be wary of requests for secrecy or pressure to act quickly.
  • Use digital signatures.
  • Do not open spam email. Delete it from your spam folder.
  • Use the “Forward” option instead of “Reply” to respond to business emails. Then either type in the recipient’s email address or select it from your address book.
  • Use multifactor authentication for corporate email accounts.
  • Be suspicious of sudden changes in business practices. Verify such changes through alternate channels.
  • Create intrusion detection system rules that flag emails with extensions that are similar to company emails.
  • Register all domains that are similar to your company’s domain.
  • Scrutinize and confirm all requests to transfer funds.
  • Do not permit the same employee to initiate and approve wire transfers.
  • Know the habits of your customers, including their payment habits.

While the guidelines above are useful, they will not prevent every BEC scam. According to the FBI, a company that falls victim to a BEC scam should immediately contact its financial institution and ask it to contact the financial institution where the fraudulent transfer was sent. The FBI also recommends filing a complaint with the appropriate law enforcement agency, regardless of the amount of the loss.


    Footnotes

      [1] According to the FBI, “[e]xposed dollar loss includes actual and attempted loss in United States dollars.”