Stories
Slash Boxes
Comments

SoylentNews is people

posted by cmn32480 on Saturday December 26 2015, @09:05PM   Printer-friendly
from the moby-dick dept.

If you work in finance or accounting and receive an email from your boss asking you to transfer some funds to an external account, you might want to think twice.

That's because so-called "whaling" attacks -- a refined kind of phishing in which hackers use spoofed or similar-sounding domain names to make it look like the emails they send are from your CFO or CEO -- are on the rise, according to security firm Mimecast.

If fact, 55 percent of the 442 IT professionals Mimecast surveyed this month said their organizations have seen an increase in the volume of whaling attacks over the past three months, the firm reported on Wednesday.

Those organizations spanned the U.S., U.K., South Africa and Australia.

Domain-spoofing is the most popular strategy, accounting for 70 percent of such attacks, Mimecast said; the majority pretend to be the CEO, but some 35 percent of organizations had seen whaling emails attributed to the CFO.

"Whaling emails can be more difficult to detect because they don't contain a hyperlink or malicious attachment, and rely solely on social engineering to trick their targets," said Orlando Scott-Cowley, a cybersecurity strategist with Mimecast.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 3, Interesting) by bziman on Sunday December 27 2015, @02:41AM

    by bziman (3577) on Sunday December 27 2015, @02:41AM (#281350)

    Wouldn't that be relatively easy to track after the fact? I mean, the victims have the account number for the scammers, and it would seem like it would not be a stretch to figure out "Hey, a fraud has been committed here. Hey bank, who was that guy?"

    Outside of the United States, you don't have to submit a blood sample and a first born child to open an account capable of receiving a wire. Even in the United States, it is easy enough to fake the required documentation to open an account. The trick is you only have the account open long enough to receive funds from all of your scams over the course of a day or two, and then you transfer the money out to another account where you have the money converted to a cashier's check or cash or whatever. If you run the money through a country with poor controls, and you make off with the money before anyone has bothered to investigate the accounts, you can get away with this.

    Starting Score:    1  point
    Moderation   +1  
       Interesting=1, Total=1
    Extra 'Interesting' Modifier   0  
    Karma-Bonus Modifier   +1  

    Total Score:   3