Business Email Compromise (BEC) is also known as email account compromise, man-in the-email attack. Not only is this type of fraud one of the most financially damaging online crimes, but it is also costlier than other fraud attacks combined. It is becoming more targeted, there are fewer victims, but the losses are greater.

In BEC Scam, criminals send an email message that appears to come from a known source making a legitimate request whilst it is an illegitimate one. Anyone can be targeted in a BEC scam, although, high-level executives such as the c-level officers and people working in the finance department are the most likely target.

                        HOW DO CRIMINALS CARRY OUT THESE SCAMS?

Criminals carry out these scams by doing the following:

How to Spot & Protect Against Business Email Compromise (BEC) Attacks -  Hashed Out by The SSL Store™

BEC are successful for three main reasons.

  1. Insufficient security protocols
  2. Social Engineering: It is a technique used in tricking people to divulge private and sensitive information.
  3. Lack of employee awareness

                                                HOW TO PROTECT YOURSELF

                              WHAT TO DO IF FUNDS GET HIJACKED

If one falls victim to Business Email Compromise, below are the things that should be done.

  1. Contact the IT department and Cybersecurity insurer immediately to report the incident.
  2. Cybersecurity insurer is an insurance company that covers a company’s liability once a data breach occurs.
  3. Contact the originating bank to request a recall or reversal.
  4. File a detailed business email compromise complaint with the law enforcement agency responsible for this, in our case, the Economic & Financial Crimes Commission (EFCC)
  5. Secure Email Gateway is an example of an email security solution that can be used.

Written by: Oreoluwa Adegoke, CFE