Your CEO's Email May Be Hacked And You Don't Even Know It

Stu Sjouwerman | Nov 14, 2019

Security concept Lock on digital screen, illustrationHackers focused on CEO fraud (or Business Email Compromise - BEC) attacks often go to great lengths to hide the fact they have access to your CEO’s mailbox as part of a larger scam.

BEC is a relatively commonplace attack with impressive success. Scammers often simply purport to be the CEO of a given organization and send one of the company employees a directive to wire money, purchase gift cards, and other financially-related activities that can benefit the scammer.

But, in some cases, hackers work to compromise email credentials – which isn’t difficult, given the ease access to Office 365 via the web; a quick scam, some social engineering, a realistic logon page, and voila! - scammers have their hands on email credentials.

But hackers are taking additional steps to ensure they operate in stealth; one great example is that of using messaging rules that focus on inbound messages from users that may be warning the hacked user of a potential breach.

10-19-19 Image

 

A simple rule, shown above, that looks for words of warning from colleagues, partners, and subordinates and deletes the email immediately can allow a hacker to retain their access to the CEO’s mailbox for an extended duration. This allows them time to understand where the opportunities lie; details about transactions, deals, individuals involved, etc. can all be used as part of a larger BEC scam.

Users of every level within your organization – from the CEO on down – need to be educated with continual Security Awareness Training. This training helps them to be better prepared for the initial attack that may be used to compromise credentials, infect an endpoint, or solicit personal information.

Topics: CEO Fraud

Get Your CEO Fraud Prevention Manual

CEO-Fraud-Prevention-Manual-WP-FannedCEO fraud has ruined the careers of many executives and loyal employees, causing over $26 billion in losses. Don’t be the next victim. This manual provides a thorough overview of how executives are compromised, how to prevent such an attack and what to do if you become a victim.

Get Your Manual

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.