Executive Impersonation Business Email Compromise Attacks Go Beyond English Worldwide

Stu Sjouwerman | Mar 6, 2023

Executive Impersonation Business Email Compromise Attacks Go Beyond English WorldwideDespite hearing mostly about BEC attacks in English-speaking countries, analysis of new attack groups highlight the threat of these kinds of attacks in other languages.

English-speaking countries don’t have the monopoly on victim organizations that part with their money easily! According to new analysis of BEC attacks by cybersecurity vendor Abnormal Security, it only takes two threat groups – Midnight Hedgehog and Mandarian Capybara – to launch BEC attacks impersonating executives in 13 different languages!

How do they do it? According to Abnormal Security, exactly the same way legitimate Marketing and Sales teams do: they use online services to identify prospects and contact information, then use online translation services to localize the BEC emails.

Why be worried? Abnormal says it best:

We’ve taught our users to look for spelling mistakes and grammatical errors to better identify when they may have received an attack. When these are not present, there are fewer alarm bells to alert native speakers that something isn’t right.

In other words, if you’re going to train your users via Security Awareness Training to be vigilant when working with email, spelling and grammar are going to matter less, and the fact that an email is unexpected, unsolicited, unusual, etc. alone become the only red flag needed to at least warrant further scrutiny of the message’s sender, it’s links or attachments, etc. before interacting with it legitimately.

Topics: CEO Fraud

Access the World’s Largest Security Awareness Library

Explore over 1,000 interactive modules, videos, and games designed to sharpen user instincts and secure AI interactions. Get instant access to our Free Training Preview and find the perfect content to fortify your security culture.

Get Your Free Training Preview

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.