Technology by Design

Technology news, reviews, and how to keep your technology running fast and smooth!

  • Home
  • About TbyD
    • Who is TbyD
    • Why Choose TbyD?
    • 16 Things
    • Your Computer Guy
  • Products and Services
    • Business Services
      • Monthly Service Plans
        • Enterprise Service Plan
        • Business Service Plan
        • Personal Service Plan
      • Performance Analysis
      • Optimization
      • Core Security Solution
      • Managed Backups
      • Computer and Network Systems
      • Computer Setup
      • Domain Names
      • Email Services
      • Extended Warranties
      • Network Cabling Services
      • Security Camera Systems
      • Managed Spam Filters
      • VoIp Phone Systems
      • Websites
    • Services
      • Monthly Service Plans
        • Enterprise Service Plan
        • Business Service Plan
        • Personal Service Plan
        • Computer Setup
      • Core Security Solution
      • Managed Backups
      • Extended Warranties
      • Performance Analysis
      • Optimization
      • Network Cabling Services
      • Security Camera Systems
      • Managed Spam Filters
      • VoIp Phone Systems
    • Products
      • Computers
      • Servers
  • Testimonials
    • What Our Clients Say About Us
  • Blogs
    • ALERTS
    • FAQ
    • How To Videos
  • Newsletters
    • TechTips Newsletters
  • Reviews
  • Media
    • Email Red Flags
    • E-Books
    • Disaster Prevention Planning Kit
    • Free Reports
  • Contact Us
    • Contact Us
    • Quick Support

ALERT: FBI Public Alert

September 21, 2015 by The T By D Team Leave a Comment

FBIALERT:  FBI Public Alert

The FBI released a warning recently against a new CyberCriminal I.T. crime wave that is so prevalent and so devastating to companies, that the FBI have named it:

“CEO Fraud”

This scam is also known as “Business Email Compromise“, which we sent out an ALERT for in January.  FBI CEO Fraud

“CEO Fraud”:  CyberCriminals impersonate a company’s CEO, using the company’s own spoofed domain name.  The fake CEO contacts company employees in charge of money transfers, and orders them to transfer large amounts of money out of the country.

CEO Fraud2CyberCriminals take employee email addresses and other information from the target company’s website to help make the emails more convincing.  In the case where executives or employees have their inboxes compromised by the thieves, the crooks will scour the victim’s email correspondence for certain words that might reveal whether the companies routinely deals with wire transfers (searching for messages with key words like “invoice”, “deposit” or “president” or “CEO”).

CyberCriminals monitor the email account of a company’s CEO for months, waiting for the right time to kick this fraudulent event off.  The “right time” is usually a time where the CEO is out of town, or can’t be easily reached.  

The CyberCriminals spoof the name of the company’s own domain (eg. “tbyd.co” instead of “tbyd.ca”) to make the emails more convincing, which can be done easily if your email server is not configured properly.

(One reason to get a professional I.T. organization to manage and maintain your I.T. network!)

IT Security Guard

The CyberCriminals, once they have spoofed the company’s domain, and have confirmed (by monitoring the CEO’s email account) that the CEO cannot easily be reached for confirmation, send URGENT emails that look legit.  The emails look like they are coming directly from the CEO, and are ordering the employee to send wire transfers.  

This email fraud is targeting small and medium-sized companies, and the current loss is tallied at $1.2 Billion.

“The scam has been reported in all 50 states and in 79 countries,” the FBI’s alert notes.  

“Fraudulent transfers have been reported going to 72 countries; however, the majority of the transfers are going to Asian banks located within China and Hong Kong.”

How To Prevent Becoming a Victim
The FBI suggests the following tips for businesses to avoid being victimized by this scam (a more complete list is available at:  www.ic3.gov).
  1. Verify changes in vendor payment location and confirm requests for transfer of funds.
  2. Be wary of free, web-based email accounts, which are more susceptible to being hacked.
  3. Be careful when posting financial and personnel information to social media and company websites.
  4. Regarding wire transfer payments – Be suspicious of requests for secrecy or pressure to take action quickly.
  5. Consider financial security procedures that include a two-step verification process for wire transfer payments.
  6. Create intrusion detection system rules that flag emails with extensions that are similar to company email, but not exactly the same.  For example “.co” instead of “.com”.
  7. If possible, register all Internet domains that are slightly different than the actual company domain.
  8. Know the habits of your customers, including the reason, detail, and amount of payments.  Beware of any significant changes.

 

Not sure if your company is safe?  Ask us for a FREE Network Security Assessment!

Check out our “Email Red Flags”  for what to watch for, in suspicious emails. 

Ask us about our “Core Security Solutions” package!
You can’t stop CyberCriminals from targeting your company or employees.
But you can be prepared for their arrival, and have full shields up.

Got CyberBugs?

Call 1-204-800-3166

For Cyber-Extermination!

#itthatworks

Filed Under: ALERTS, Featured

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Sign Up For The Monthly TechTips Newsletter!

* = required field
unsubscribe from list

powered by MailChimp!

Recent Posts

  • ALERT: Celebrity Death Scams
  • ALERT: Uber Hacked
  • ALERT: Netflix Email Scam
  • ALERT: Bad Rabbit
  • Scam – Reset Password Alert

Recent Comments

  • ALERT: New Ransomware Targets MS Office 365 Users - Technology by Design on Managed Backups
  • ALERT: FBI Warns Email Extortion Heating Up for Summer! - Technology by Design on ALERT: AshleyMadison Hack Blows Up
  • ALERT: Evil Android Trojan Empties Your Bank Account - Technology by Design on Definition: Phishing
  • ALERT: HTML Attachments - Technology by Design on Definition: Phishing
  • ALERT: New Ransomware Also Steals Your Bitcoins - Technology by Design on Managed Backups

Copyright © 2025 · Dynamik Website Builder on Genesis Framework · WordPress · Log in