Welcome!

By registering with us, you'll be able to discuss, share and private message with other members of our community.

SignUp Now!
adv ex on 5 january 2024
adv ex on 22 February 2024
banner Expire 26 April 2024
Rescator cvv and dump shop
banner expire at 13 May

Yale lodge shop
UniCvv
banner Expire 1 April  2021

FBI: Block Email Forwarding to Stop BEC Attackers

Premiums

TRUSTED VENDOR
Joined
Dec 5, 2020
Messages
1,345
The FBI has warned businesses that cyber-criminals are exploiting an email forwarding vulnerability on remote workers’ webmail clients to make BEC attacks more successful.

In a Private Industry Notification released last week but just made public, the Feds explained that auto-forwarding rules are commonly used in BEC scams once attackers have compromised an employee’s inbox.

This means emails with specifically chosen keywords like “bank” and “invoice” are automatically sent on to the attacker’s inbox. They can then monitor communications between that employee and other users, and delete certain emails to hide their activity.

Eventually the attacker steps in, pretending to be a legitimate contact such as a supplier, and sends a fake invoice or similar to be paid by the employee’s company.

The FBI warned that if IT administrators don’t sync staff web and desktop email clients, then auto-forwarding rules updated by an attacker will only appear in the former, meaning security teams have no idea that a scam may be taking place.

“While IT personnel traditionally implement auto-alerts through security monitoring appliances to alert when rule updates appear on their networks, such alerts can miss updates on remote workstations using web-based email,” it continued.

“If businesses do not configure their network to routinely sync their employees’ web-based emails to the internal network, an intrusion may be left unidentified until the computer sends an update to the security appliance set up to monitor changes within the email application.”

Even if a bank or law enforcement sounds the alarm, a victim organization may still miss the rule update unless they audit both applications, giving attackers even more time, the FBI added.

This oversight led to a $175,000 loss at a US medical equipment company in August 2020, it warned.

The alert urged administrators to ensure desktop and web email clients are running the same version to enable easy syncing and updates. It also advised them to prohibit automatic email forwarding to external addresses and to monitor for suspicious behavior such as last-minute changes in established email addresses.
 

Sergpbz

New member
Joined
Mar 24, 2021
Messages
4
Can I contact admin??
I'ts important.
Thank.

Могу я связаться с администрацией?
Это важно.
Спасибо.
 

Serzwzs

New member
Joined
Mar 30, 2021
Messages
1
Can I contact admin??
It is about advertisement on your website.
Thank.
 

Ilushikhwv

New member
Joined
Apr 1, 2021
Messages
1
Могу я связаться с администрацией?
Речь идет о рекламе на вашем сайте.
С уважением.
 
Top Bottom