Here Is A New Term For Your Cybercrime Glossary: Vendor Email Compromise (VEC)

iStock-687977248Agari’s latest Email Fraud & Identity Deception Trends report highlights the growing threat of vendor email compromise (VEC), according to SecurityWeek. This is a variety of business email compromise (BEC) attack—also known as CEO Fraud— in which attackers gain access to email accounts at a company in the supply chain, and then use the accounts to target that company’s customers. PS, did you know that KnowBe4 has an extensive glossary with hundreds of these terms?

The attacks involve a reconnaissance phase in which the scammers quietly observe a company’s payment routines and identify a lucrative contract to target. Eventually, they’ll craft emails that perfectly imitate the real emails they’ve seen the company’s employees sending to their customers. The attackers will then send these emails from the hacked email account to request payment from the target company. These invoices are for the correct amount of money and appear identical to the real invoices, but they direct the money to the attacker’s bank account.

Armen Najarian, Agari's chief identity officer, told SecurityWeek that VEC attackers usually go after companies that have expensive contracts.

“Generally, these sophisticated attackers are looking for deep pocket, big contract scenarios – think of the supply of a major part of a component for an aircraft manufacturing process that is potentially hundreds of thousands of dollars,” Najarian said.

While VEC scams use the same tactics as other BEC attacks, they are much more lucrative. Najarian said attackers have already realized this, and Agari expects vendor-focused attacks to surpass other BEC attacks next year.

“We are seeing a notable shift in the focus from threat actor groups into this type of attack, primarily because the payout is much bigger,” Najarian said. “On average, a BEC CEO fraud attack will generally pay out in the $50,000 to $55,000 range, but a successfully executed VEC attack will pay more than double at around $125,000 on average.”

Companies need to have processes in place to ensure the legitimacy of transactions, and employees need to be trained to recognize suspicious behavior. New-school security awareness training can give your employees the ability to prevent these attacks. SecurityWeek has the story:

Will your users respond to phishing emails?

KnowBe4's Phishing Reply Test (PRT) is a complimentary IT security tool that makes it easy for you to check to see if key users in your organization will reply to a highly targeted phishing attack without clicking on a link. PRT will give you quick insights into how many users will take the bait so you can take action to train your users and better protect your organization from these fraudulent attacks!

PRT-imageHere's how it works:

  • Immediately start your test with your choice of three phishing email reply scenarios
  • Spoof a Sender’s name and email address your users know and trust
  • Phishes for user replies and returns the results to you within minutes
  • Get a PDF emailed to you within 24 hours with the percentage of users that replied

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

Subscribe To Our Blog

Free Phishing Security Resource Kit

Get the latest about social engineering

Subscribe to CyberheistNews