Ex-Bank of America Employee Charged with Business Email Compromise Money Laundering

Stu Sjouwerman | Oct 19, 2021

Business Email Compromise Scam Bank of AmericaA three-person team – including a personal banker at Bank of America – have been indicted for reportedly being behind a BEC scam that took 5 companies for over $1.1 Million.

I often hear of (and tell) stories of scams, but rarely hear about what happened after the money’s been stolen. In this care, according to U.S. Department of Justice press release, we get a small glimpse into what transpires post-attack with funds.

According to the DoJ, three men were behind a Business Email Compromise (BEC) scam that began with targeted phishing attacks designed to steal online credentials. Once a set of credentials was obtained, a material amount of time – in some cases, months – was spent intercepting email communications so that the team could learn about the internal billing systems, the types of communications between key players, and who were the vendors, clients, and people responsible for transactions. The team would send an email to a vendor impersonating an employee (by using a typo-squatting lookalike domain), requesting payment for an actual transaction, providing full details of the transaction for credibility purposes, but diverting payment to their own account.

One of the three, an ex-Bank of America personal banker, was responsible for setting up the bank accounts – in many cases under the names of the victim companies – to ensure payments would be accepted by the bank.

It’s important to remember that scams like this nearly always start with a phish. As long as a user falls for the phishing attack, the game is on and your organization is not at risk of either attack or fraud. Users that undergo Security Awareness Training – particularly those who have responsibility over the organization’s finances – are better prepared to spot scams designed to steal credentials, thwarting BEC scams like this one before they every get started.

Topics: CEO Fraud

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.