Increase in Business Email Compromise – Why you need to protect your email

 

The Silent Takeover: How BEC Attacks Reroute Your Reality

In today’s SensCy Cyber Brief, the SensCy team is looking into a growing trend regarding email account hacking, email account takeovers, and Business Email Compromise (BEC).

In the past few months, SensCy has helped multiple organizations with incidents involving email fraud. Recent data suggests that Business Email Compromise (BEC) incidents are up 200%, highlighting the urgent need for awareness. According to the Federal Bureau of Investigation, BEC is one of the most damaging cyber crimes for businesses of all sizes. Between June 2016 and December 2021, BEC-related fraud cost businesses around the world $43 billion in losses – $2.4 billion in 2021 alone. Because the stakes are so high, understanding how to protect your company from Business Email Compromise is no longer optional—it is a business necessity.

Key Takeaways

  • Silent Threat: In many Business Email Compromise (BEC) attacks, hackers do not lock you out; they silently monitor your inbox to learn your habits and financial schedules.
  • RSS Redirection: Attackers often reroute incoming emails to hidden RSS feeds, allowing them to intercept sensitive messages without the victim seeing them in the main inbox.
  • Financial Impact: BEC is one of the costliest cyber crimes, causing billions in global losses by tricking employees into wiring funds to fraudulent accounts.
  • Critical Defense: The most effective way to prevent account takeovers is enabling Multi-Factor Authentication (MFA) and using unique, complex passwords for every service.

 What are hackers doing once they have access to your email account? 

SensCy has observed an increase in subtle email account takeovers. These breaches often begin with deceptive entry points, such as DocuSign phishing emails designed to trick employees into handing over credentials. In recent cases, the hackers did not change the email account’s password or alter anything visible in the account. They simply watched and analyzed as the victims conducted regular business, making it almost impossible for the victims to realize that their account was compromised.

Once the hackers found an email relating to a financial transaction, they rerouted the emails to the RSS feed. This is a feed separated from an email account’s main inbox, typically used to receive newsletters, blogs, or online magazines. Once the emails started going to the RSS feed, the victim no longer saw them, allowing the hackers to impersonate the victim by communicating directly with the financial institution or the client. They then advised the wire sender that banking information had changed.

From the financial institution’s point of view or the victim’s client, nothing appeared suspicious; they believed they were still communicating with the correct email address, making it difficult for them to spot the fraud. SensCy has observed thousands to hundreds of thousands of dollars being fraudulently transferred via this method.

How can you protect yourself?

One of the most common mistakes people make with regular email account security is reusing the same password for different accounts. You should always use unique passwords, especially on important accounts like your work email, bank, credit card, or healthcare accounts. Never use passwords that include your name, birthday, address, or anything that would make the password easy to guess. Use letters, numbers, and symbols. To better manage your passwords, SensCy recommends investing in a password keeper for your employees.

Secondly, you should turn on two-factor authentication (2FA), also known as multi-factor authentication (MFA). This adds an extra step to the authentication process, providing an extra layer of security. Hackers who gained access to your email credentials could not access your account without the additional authentication method, usually sent to your phone, when trying to log in.

The new National Institute of Technology framework recommends changing your passwords once a year when combined with MFA or 2FA. It also recommends doing an immediate password reset when a known compromise has occurred. However, prevention is only half the battle; knowing how to react is equally important. Leaders should review what a Cyber Incident Response Plan is and why your business needs one to ensure they are prepared to act swiftly if defenses fail.

Frequently Asked Questions (FAQ)

1. What is an RSS feed in the context of email hacking?

An RSS (Really Simple Syndication) feed is a folder or stream often found in email clients (like Outlook) intended for news and blog subscriptions. Hackers create rules to automatically move specific emails (like those containing “invoice” or “wire”) into this folder so the victim doesn’t see them in the Inbox, while the hacker reads them silently.

2. Why don’t hackers just change my password immediately?

If a hacker changes your password, you will know immediately that you have been hacked and will call IT to reset it. by not changing the password, they can stay inside your email account for weeks or months, learning who your biggest clients are and when payments are due, allowing them to steal much more money.

3. How does Multi-Factor Authentication (MFA) stop BEC?

MFA requires two things to log in: something you know (your password) and something you have (your phone). Even if a hacker tricks you into giving them your password via a phishing email, they cannot log in to your account because they do not have your physical phone to receive the approval code.

4. What should I do if I suspect my email is compromised?

Immediately contact your IT department or security provider. Reset your password, force a logout of all active sessions, and check your email “Rules” folder to see if any forwarding or redirection rules (like the RSS feed trick) have been created without your knowledge.

If you have any questions regarding email security and Business Email Compromise, don’t hesitate to reach out to SensCy.

To understand the risk that BECs pose to your organization, book your SensCy Score here.