200% increase in invoice and payment fraud BEC attacks

There has been a 200 percent increase in BEC attacks focused on invoice or payment fraud from April to May 2020, according to Abnormal Security. This sharp rise continues the trend. Also, according to the report, invoice and payment fraud attacks incre… Continue reading 200% increase in invoice and payment fraud BEC attacks

Email security challenges and BEC trends during the pandemic

COVID-related attacks increased 436% between the second and third weeks of March 2020, with an average 173% week-over-week increase during the quarter, according to Abnormal Security. A trend toward payment fraud There has also been a shift from indivi… Continue reading Email security challenges and BEC trends during the pandemic

Understanding the Payload-Less Email Attacks Evading Your Security Team

Business email compromise (BEC) attacks represent a small percentage of email attacks, but disproportionately represent the greatest financial risk. Continue reading Understanding the Payload-Less Email Attacks Evading Your Security Team

Office 365 users: Beware of fake company emails delivering a new VPN configuration

Phishers are impersonating companies’ IT support team and sending fake VPN configuration change notifications in the hopes that remote employees may be tricked into providing their Office 365 login credentials. Yet another Office 365 phishing cam… Continue reading Office 365 users: Beware of fake company emails delivering a new VPN configuration

Abnormal Security launches VendorBase to help orgs reduce supply chain cybersecurity risk

Abnormal Security, a leader in protecting large enterprises from Business Email Compromise (BEC) attacks, introduced VendorBase, a global, federated database that tracks the reputations of an organization’s vendors and customers, and improves detection… Continue reading Abnormal Security launches VendorBase to help orgs reduce supply chain cybersecurity risk

Beware of phishing emails urging for a LogMeIn security update

LogMeIn users are being targeted with fake security update requests, which lead to a spoofed phishing page. “Should recipients fall victim to this attack, their login credentials to their LogMeIn account would be compromised. Additionally, since … Continue reading Beware of phishing emails urging for a LogMeIn security update

Fake Microsoft Teams notification emails are hitting inboxes

Phishers are using fake Microsoft Teams notification emails to trick users into sharing their Microsoft Teams and Office 365 login credentials. “Should the recipient fall victim to this attack, this user’s credentials would be compromised. Additi… Continue reading Fake Microsoft Teams notification emails are hitting inboxes

Phishers exploiting employees’ layoff, payroll concerns

A few days ago, we outlined several phishing campaigns going after Zoom and WebEx credentials of employees. Two new ones are trying to exploit their (at the moment very rational) fears by delivering fake “Zoom meeting about termination” ema… Continue reading Phishers exploiting employees’ layoff, payroll concerns