West Africa’s Scattered Canary gang shows how cybercriminals supersize email scams

Sometimes the most effective scam techniques are also the most mundane. Business email compromise attacks don’t involve advanced malware, and aren’t carried out by headline-grabbing nation-state hackers. BEC scams simply rely on personalized emails to dupe victims into transferring funds to someone who appears to be a co-worker, friend, or family member.   But this fraud technique is taking a toll, depriving Americans of a vast sum of money each year. In 2018, the FBI’s cybercrime center received over 20,000 BEC complaints that accounted for estimated losses of $1.2 billion. Understanding the scale of the problem requires understanding how perpetrators scale their operations. The decade-long evolution of one Western African cybercriminal gang is a case in point. Email security firm Agari on Wednesday published research documenting the so-called Scattered Canary group’s rise from a lone individual to dozens of operatives specializing in various aspects of fraud. The group also has grown from peddling romance scams to targeting […]

The post West Africa’s Scattered Canary gang shows how cybercriminals supersize email scams appeared first on CyberScoop.

Continue reading West Africa’s Scattered Canary gang shows how cybercriminals supersize email scams

Employees report 23,000 phishing incidents annually, costing $4.3 million to investigate

Account takeover-based (ATO) attacks now comprise 20 percent of advanced email attacks, according to Agari’s Q1 2019 Email Fraud & Identity Deception Trends report. ATO attacks are dangerous because they are more difficult to detect than tra… Continue reading Employees report 23,000 phishing incidents annually, costing $4.3 million to investigate

BEC scammers add payroll diversion to their repertoire

All the attention the most typical BEC scams have been receiving in the last few years must have affected their effectiveness and forced scammers to come up with new ways for extracting money from companies. Late last year the FBI warned about scammers… Continue reading BEC scammers add payroll diversion to their repertoire

Agari introduces phishing incident response solution for cloud office suites

Agari Incident Response is the purpose-built phishing incident response solution for post-delivery remediation in Microsoft Office 365 environments. It eliminates error-prone and time-consuming reporting and response with automated investigation and re… Continue reading Agari introduces phishing incident response solution for cloud office suites

‘London Blue’ cybercriminals turn to large-scale email scam

Email users the world over are familiar with the “Nigeria prince” scam in which someone posing as a foreign dignitary requests a money transfer. While this ruse may not fool many, it has grown more clever and industrialized in recent years – to the point of threatening big businesses. A prime example is London Blue, a network of cybercriminals exposed by new research from email-security firm Agari. The group has laid the groundwork for large-scale business email compromise (BEC) attacks by compiling a list of more than 50,000 corporate officials, including dozens of executives from the world’s biggest banks, according to Agari.  Over half of the 50,000 targets were in in the United States. “The pure scale of the group’s target repository is evidence that BEC attacks are a threat to all businesses, regardless of size or location,” Agari researchers wrote. BEC attacks use personalized emails, sent using spoofed email-name […]

The post ‘London Blue’ cybercriminals turn to large-scale email scam appeared first on Cyberscoop.

Continue reading ‘London Blue’ cybercriminals turn to large-scale email scam

Beagle free visual analytics tool helps bring cybercriminals to justice

A team of researchers is helping law enforcement crack down on email scammers, thanks to a new visual analytics tool that speeds up forensic email investigations and highlights critical links within email data. Email scams are among the most prevalent,… Continue reading Beagle free visual analytics tool helps bring cybercriminals to justice

Most impersonated brands in email attacks? Microsoft and Amazon

Nearly two-thirds of all advanced email attacks used emails impersonating Microsoft or Amazon, according to new research by Agari. Microsoft was impersonated in 36 percent of all (brand) display name impersonation attacks in the third quarter. Amazon w… Continue reading Most impersonated brands in email attacks? Microsoft and Amazon

Agari Fall ‘18 release completes automated email security solution powered by AI

Agari announced its Fall ‘18 release, a series of enhancements for the Agari Email Trust Platform — the industry’s automated email security solution powered by artificial intelligence. Agari Customer Protect, which safeguards domains, now offers … Continue reading Agari Fall ‘18 release completes automated email security solution powered by AI

Agari: Most agencies on track for DMARC deadline

Most federal agency web domains are on track to meet a requirement that protects them from email spoofing, according to a report from email security company Agari. The requirement in question is Domain-based Message Authentication, Reporting and Conformance (DMARC), a policy that gives network administrators more visibility and control over how their domain is being used with regard to email. Without it, malicious actors can send emails that appear to be from a trusted source, such as a .gov website, to unsuspecting victims. The Department of Homeland Security issued a binding operational directive (BOD) in October 2017 that required all agencies to protect their domains with the highest level of DMARC within one year. With the deadline less than three months away, Agari reports that most domains are on track to meeting the requirements, and just over half have already done so. DMARC can be implemented on three levels of […]

The post Agari: Most agencies on track for DMARC deadline appeared first on Cyberscoop.

Continue reading Agari: Most agencies on track for DMARC deadline