April 27, 2020 By David Bisson 2 min read

A threat group known as “The Florentine Banker” stole approximately £600K in a successful business email compromise (BEC) scam.

Check Point Research reported that the Florentine Banker group had targeted three large organizations in the British and Israeli financial sectors. Those attacks began when the threat group set up a phishing campaign that targeted the CEO, CFO and/or other individuals in the organization who had the authority to authorize money transfers. After gaining access to a victim’s account, the attackers read the emails stored therein to learn about the channels used to process money transfers and to glean more about who might be involved in completing such a transaction.

Operating mostly from Monday through Friday, the nefarious individuals used this intelligence to create mailbox rules in order to divert emails with interesting content to a folder under their control. They then created domains that appeared to originate from entities they might want to impersonate in their emails. It’s at that point that the threat group sent out emails from those lookalike domains. Ultimately, they attempted to intercept wire transfer requests written in English or to authorize new transfers.

Via this attack chain, malicious actors succeeded in stealing approximately £600K from a victim and transferring these funds to fraudulent bank accounts.

The Growing Impact of Business Email Compromise

In 2019, the Federal Bureau of Investigation (FBI) received 23,775 complaints of BEC ruses. Those scams accounted for approximately 5 percent of the total number of digital crime reports received by investigators that year. Even so, BEC ruses accounted for nearly half ($1.7 billion) of the total losses of all those digital crime instances.

How to Defend Against BEC Scams and Other Email Threats

Security professionals can help defend their organizations against threat actors such as the Florentine Banker by regularly conducting security awareness trainings to educate the workforce about the latest phishing techniques, including executives and others who are most at risk of a BEC attack. Teams should back this education up with cyber resilience solutions, such as behavioral analytics tools that look for evidence of successful BEC scams and other attacks within authorized users’ activity.

More from

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

4 ways to bring cybersecurity into your community

4 min read - It’s easy to focus on technology when talking about cybersecurity. However, the best prevention measures rely on the education of those who use technology. Organizations training their employees is the first step. But the industry needs to expand the concept of a culture of cybersecurity and take it from where it currently stands as an organizational responsibility to a global perspective.When every person who uses technology — for work, personal use and school — views cybersecurity as their responsibility, it…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today