Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Businesses Security Social Networks The Almighty Buck

Businesses Lose $3.1 Billion to Email Scams, FBI Warns (networkworld.com) 18

Business have lost over $3 billion because of compromised e-mail accounts, the FBI reports, citing "a sophisticated scam targeting businesses working with foreign suppliers and/or businesses that regularly perform wire transfer payments." 22,143 business have been affected -- 14,302 within the U.S. -- with a total dollar loss of $3,086,250,090, representing an increase of 1,300% since January of 2015.

Using social engineering or "computer intrusion techniques," the attackers target employees responsible for wire transfers (or issuing checks) using five scenarios, which include bogus invoices or executive requests for a wire transfer of funds, with some attackers even impersonating a corporate law firm. "Victims report that IP addresses frequently trace back to free domain registrars," warns the FBI's Internet Crime Complaint Center, which also urges businesses to avoid free web-based e-mail accounts.
This discussion has been archived. No new comments can be posted.

Businesses Lose $3.1 Billion to Email Scams, FBI Warns

Comments Filter:
  • by NotInHere ( 3654617 ) on Saturday June 18, 2016 @09:35AM (#52342931)

    Wtf, I think gmail is 10x more secure than running the webserver on the same server you run your wordpress based website on.

    Its really hard to get your mail service as secure as gmail is.

    • by wbr1 ( 2538558 )
      Far better to use Google apps or even o365. You have more granular control over users, true archiving, etc. But if you are super cheap Gmail is the best free option.
      • by tlhIngan ( 30335 )

        I've seen many companies use GMail, even rather big outfits.

        They go and use something along the lines of "companyname-name@gmail.com" as their correspondence address. And yes, this would be emblazoned on their packaging.

        We've got suppliers that work like that - but considering we remove the packaging (it's just inside a tacky plastic bag when we pack our goods, no one really notices.

    • Well, since gmail is a spy outfit, it's not a good idea for business to send confidential correspondence over their servers. It's probably better to set one up at home, something that can be quickly 'cleaned', if you get my drift.

  • The giveaway is that the executives ask way too nicely in the emails.
  • Why not have internal messaging systems and file-checkin systems that are independent of email, and only allow email to a few trained/locked-down terminals?

    I know it's inconvenient and thus the antithesis of "modern web" startup culture, but one should ask the question with fresh eyes from a business logic perspective.

    Would you allow people coming and going with boxes in your business without any sort of controls on that? Strangers? Unattended packages?

    Wouldn't it be a higher hurdle for script kiddies to

  • by JustAnotherOldGuy ( 4145623 ) on Saturday June 18, 2016 @11:07AM (#52343235) Journal

    For more information on email scams, please click the link below and when the dialog box appears, click "Run".

  • by frovingslosh ( 582462 ) on Saturday June 18, 2016 @11:52AM (#52343411)
    Sounds like it is just a voluntary tax on stupidity, perhaps coupled with a low cost course in computer security when that lesson is very needed. One has to wonder, since this kind of thing is usually covered up by the "victim", just how the FBI know how much of it is going on.
    • Re:voluntary (Score:4, Interesting)

      by Areyoukiddingme ( 1289470 ) on Saturday June 18, 2016 @01:27PM (#52343803)

      One has to wonder, since this kind of thing is usually covered up by the "victim", just how the FBI know how much of it is going on.

      Easy. They don't. Given the specificity of that number, it's the sum of the reported cases. The actual number of cases is much much bigger, both in count and in losses. Many companies are successfully hiding it, from the FBI, from their insurance company, from their stockholders, and from the public.

      When RFC 822 was written in 1982, it was competing against a bunch of different email formats already in use since the late '70s. RFC 733, written in 1977, was supposed to have unified many of those formats and features already. It didn't, quite, so another attempt was made. To make a long story short, Internet email as we know it was in an uphill battle against entrenched formats, so to get it to fly, it had to be extraordinarily permissive. Minor things like authenticity of identity weren't even a consideration.

      Those days are over. Email has been adopted. There isn't even a dash in the name anymore. Authenticity of identity is now exceedingly important. $3 billion ($6 billion? $9 billion?) important. Perhaps it's time for companies to get a grip on their inter-business relationships, so they can be confident that an invoice is legitimate. Outlook has signature features[1]. Nobody uses them. Maybe it's time.

      ---

      [1] Let's not pretend the vast majority of businesses are using anything other than Outlook.

      • Which employees need email with the general public: Sales? Public Relations? Recruitment?
        Which employees need email to specific outside people: accounts receivable, accounts payable, payroll, management, etc.
        How about two email systems? A restricted one for employees who work with money or budgets and an external one for everyone else.

  • Are there any specific businesses, or types of businesses (say by size, sector or whatever) that are more susceptible to this kind of fraud?

    Just curious.

There are never any bugs you haven't found yet.

Working...