Cybersecurity News that Matters

Cybersecurity News that Matters

BEC Is the next ransomware: Ransomware attackers will turn their eyes to BEC

by Dain Oh

Jun. 08, 2022
4:28 PM GMT+9

By Dain Oh, The Readable

RSA Conference 2022 ― San Francisco ― While business email compromise (BEC) attacks are relatively less well known than ransomware attacks, they will soon dominate the threat landscape, an expert of threat intelligence (TI) said Monday.

“It has a much higher return on investment, or ROI, than other types of cyber-attacks,” Director of TI Abnormal Security Crane Hassold said during a track session at the RSA Conference, referring to BEC attacks.

Abnormal Security defines BEC as a spear phishing attack that involves the impersonation of a trusted individual to trick a person into making a financial transaction or sending sensitive materials. Hassold, in other words, described BEC attacks as being “financial supply chain compromise attacks.”

The emphasis on the risk of BEC over that of ransomware comes as the ROI for ransomware attacks is dramatically sinking due to government regulations of cryptocurrency going into effect around the world. Hassold asserted that ransomware has been driven by three primary factors: an easy access, which is normally referred to as “Ransomware as a Service (Raas),” high incentives through extortion, and cryptocurrency to scale up an attack.

The increasing pressure by law enforcement on ransomware gangs is another reason why cyber criminals are likely to turn their attention to BEC attacks. Ransomware threat actors are centralized mainly in Russia and Eastern Europe. According to the 2022 Abnormal Ransomware Victimology Report, the Conti (30.4%) and Lockbit (20.1%) ransomware groups, both closely related to Russia and Eastern Europe, consist of 50.5% of the entire active ransomware group attack volume.

Contrary to popular belief, BEC attacks were more commonly reported than ransomware attacks. Ransomware is visible while BEC attacks are not usually exposed, Hassold said. In 2021, over 19,900 businesses reported that they suffered BEC attacks, while only 3700+ attacks were reported regarding ransomware. Furthermore, in terms of losses, BEC attackers made $2.4 billion, while ransomware attackers made $49 million during the same period.

BEC has become a major threat to business entities since its first notable incident was exposed in 2015. Ubiquiti Networks, a San Jose based networking technology firm, suffered from a BEC attack which resulted in a $46.7 million losses. Through the report submitted to the U.S. Securities and Exchange Commission (SEC) on August 4, 2015, the firm admitted that “it had been the victim of a criminal fraud,” and the “incident involved employee impersonation and fraudulent requests from an outside entity targeting the Company’s finance department.” During the attack, the company transferred $46.7 million in total to third parties’ accounts overseas.

The volume of BEC attacks remains almost the same even though law enforcement is going after BEC gangs. “Every single day, [law enforcement officers] are arresting people for BEC attacks, but the overall volume is not going down because BEC is difficult to disrupt,” said Hassold. “Because of the decentralized nature of the threat, you could arrest hundreds, if not thousands of these guys, and you would actually not make that big of a noticeable difference in the overall volume that we see.”

Hassold expects that ransomware attackers will turn into BEC threat actors in the near future. “[Financially motivated attackers] are going to pivot somewhere else,” he said. “In the next 12 to 18 months, we might see the essential convergence of ransomware actors to create this sophisticated, hybrid social attack. Ransomware actors are not blind to the fact that the amount of money to be made in BEC is there.”

Subscription

Subscribe to our newsletter for the latest insights and trends. Tailor your subscription to fit your interests:

By subscribing, you agree to our Privacy Policy. We respect your privacy and are committed to protecting your personal data. Your email address will only be used to send you the information you have requested, and you can unsubscribe at any time through the link provided in our emails.

  • Dain Oh
    : Author

    Dain Oh is a distinguished journalist based in South Korea, recognized for her exceptional contributions to the field. As the founder and editor-in-chief of The Readable, she has demonstrated her expe...

    View all posts
Author:
Stay Ahead with The Readable's Cybersecurity Insights