Thursday, January 21, 2021
No Result
View All Result
Reelnewz
  • Home
  • Recent
  • Local
  • Global
  • Politics
  • Business
  • Defense
  • Health
  • Tech
  • Finance
  • Sport
  • Entertainment
  • Travel
  • Lifestyle
  • Home
  • Recent
  • Local
  • Global
  • Politics
  • Business
  • Defense
  • Health
  • Tech
  • Finance
  • Sport
  • Entertainment
  • Travel
  • Lifestyle
No Result
View All Result
Reelnewz
No Result
View All Result
Home Technology

FBI warns of email forwarding rules being abused in recent hacks

2 months ago
in Technology
3 min read
Share on FacebookShare on Twitter


fbi.jpg

The US Federal Bureau of Investigation says that cyber-criminals are increasingly relying on email forwarding rules in order to disguise their presence inside hacked email accounts.

In a PIN (Private Industry Notification) alert sent last week and made public today, the FBI says the technique has been seen & abused in recent BEC (Business Email Compromise) attacks reported over the summer.

The hackers’ technique relies on a feature found in some email services and called “auto-forwarding email rules.”

As its name implies, the feature allows the owner of an email address to set up “rules” that forward (redirect) an incoming email to another address if a certain criteria is met.

Threat actors absolutely love email auto-forwarding rules as it allows them to receive copies of all incoming emails without having to log into an account each day — and be at risk of triggering a security warning for a suspicious login.

Recent spike of abuse in BEC attacks

Email auto-forwarding rules have been abused since the dawn of email clients; by both nation-state hacking groups, but also regular cybercrime operators.

But in a PIN last week, the FBI says it received multiple reports over the summer that the technique is now often abused by gangs engaging in BEC scams — a form of cybercrime where hackers breach email accounts and then send emails from the hacked account in attempts to convince other employees or business partners into authorizing payments to wrong accounts, controlled by the intruders.

The FBI provided two cases as examples were BEC scammers abused email forwarding rules during their attacks:

  1. In August 2020, cyber criminals created auto-forwarding email rules on the recently upgraded web client of a US-based medical equipment company. The webmail did not sync to the desktop application and went unnoticed by the victim company, which only observed auto-forwarding rules on the desktop client. RSS was also not enabled on the desktop application. After the BEC actors obtained access to the network, they impersonated a known international vendor. The actors created a domain with similar spelling to the victim and communicated with the vendor using a UK-based IP address to further increase the likelihood of payment. The actors obtained $175,000 from the victim.
  2. During another incident in August 2020, the same actor created three forwarding rules within the web-based email used by a company in the manufacturing industry. The first rule auto-forwarded any emails with the search terms “bank,” “payment,” “invoice,” “wire,” or “check” to the cyber criminal’s email address. The other two rules were based off the sender’s domain and again forwarded to the same email address.

FBI recommends syncing email account settings

FBI officials say that the technique is still making victims in corporate environments because some companies don’t forcibly sync email settings for the web-based accounts with desktop clients.

This, in turn, limits “the rules’ visibility to [a company’s] cyber security administrators,” and the company’s security software, which may be configured and capable of detecting forwarding rules, but may remain blind to new rules until a sync occurs.

The FBI PIN — a copy of which is available here — contains a series of basic mitigations and solutions for system administrators to address this particular attack vector and prevent future abuse.

The FBI PIN comes after the FBI reported earlier this year that BEC scams were, by far, the most popular form of cybercrime in 2019, having accounted for half of the cybercrime losses reported last year.



Source link

Previous Post

Queen Elizabeth II, Prince Philip’s Christmas Plans Revealed

Next Post

Concacaf Champions League 2020 schedule finalized for remaining matches

Related Posts

Microsoft Edge can finally generate new passwords for you

by admin
31 mins ago
0

Microsoft is poised to release several substantial security updates to version 88 of its Edge browser, including a long-awaited...

Microsoft Edge gets new colorful themes, sleeping tabs feature, and password manager

by admin
1 hour ago
0

Microsoft is introducing new colorful themes for its Edge browser this week, alongside updated icons and a new sleeping...

Bodyguard is a mobile app that hides toxic content on social platforms – TechCrunch

by admin
1 hour ago
0

If you’re somewhat famous on various social networks, chances are you are exposed to hate speech in your replies...

Today only: Save 52% on this Raspberry Pi starter kit

by admin
1 hour ago
0

A combination of cold weather and a certain pandemic has left many of us in need of a new...

How Linux was ported to the Apple Silicon M1 Mac mini

by admin
1 hour ago
0

Linux now works on the Mac mini with M1 processor — but Apple did not make it easy for...

How to share folders between VirtualBox guest and host

by admin
3 hours ago
0

Sharing folders between a VirtualBox host and guest is actually much easier than you might think. Jack Wallen shows...

Load More
Next Post

Concacaf Champions League 2020 schedule finalized for remaining matches

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent News

At the Inauguration, Amanda Gorman Wove History and the Future Into a Stirring Melody

January 21, 2021

Apple Valley PD Issues Alert After Neighborhood Burglaries – WCCO

January 21, 2021

Seattle Sounders sign midfielder Joao Paulo from Botafogo on permanent transfer

January 21, 2021

Microsoft Edge can finally generate new passwords for you

January 21, 2021

How Did The Parler Hack Happen? WordPress Security Issues Lead the Way

January 21, 2021

Biden gets to work as Pelosi says Trump impeachment will head to Senate ‘soon’ – live | US news

January 21, 2021

SWAN Introduces First Swiss Digital Directory of Women Working in Audiovisual Sector

January 21, 2021

Goodthreads Sweater Demonstrates the Power of a Mock Neckline

January 21, 2021

Biden proposes 5-year extension of nuclear treaty with Russia. U.S. official says

January 21, 2021

U.S. Vaccine Supply: What to Know

January 21, 2021
Reelnewz

All the latest breaking news on Reel Newz. Browse The Independent's complete collection of articles and commentary on Reel Newz.

Follow Us

Browse by Category

  • Business
  • Defense
  • Entertainment
  • Finance
  • Global
  • Health
  • Lifestyle
  • Local
  • Politics
  • Recent
  • Sport
  • Technology
  • Travel

Recent News

At the Inauguration, Amanda Gorman Wove History and the Future Into a Stirring Melody

January 21, 2021

Apple Valley PD Issues Alert After Neighborhood Burglaries – WCCO

January 21, 2021
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
  • Cookie Privacy Policy
  • Contact us

© 2020 All Rights Reserved - Reel Newz.

No Result
View All Result

© 2020 All Rights Reserved - Reel Newz.