Hamilton Journal News

Business email scams rack up billions in 2021

- By Alan Suderman

RICHMOND, VA. — It’s a crime that siphons untold billions from the economy — but many people have never heard of it.

Business Email Compromise scams involve criminals hacking into email accounts, pretending to be someone they’re not and fooling victims into sending money where it doesn’t belong.

Although they get far less attention than the massive ransomware attacks that have triggered a powerful government response, BEC scams have been by far the costliest type of cybercrime in the U.S. for years, according to the FBI.

The huge payoffs and low risks associated with BEC scams have attracted criminals worldwide. Some flaunt their ill-gotten riches on social media, posing in pictures next to Ferraris, Bentleys and stacks of cash.

Almost every enterprise is vulnerable to BEC scams, from Fortune 500 companies to small towns. Even the U.S. State Department got duped into sending BEC scammers more than $200,000 in grant funds meant to help Tunisian farmers, court records show.

“The scammers are extremely well organized, and law enforcemen­t is not,” said Sherry Williams, a director of a San Francisco nonprofit that recently fell victim to a BEC scam.

Losses in the U.S. due to BEC scams in 2021 were nearly $2.4 billion, according to a new report by the FBI. That’s a 33% increase from 2020 and more than a tenfold increase from just seven years ago.

And experts say many victims never come forward and the FBI’s numbers only show a small fraction of just how much money is stolen each year.

BEC scammers use a variety of techniques to hack into legitimate business email accounts and trick employees to send wire payments or make purchases they shouldn’t. Targeted phishing emails are a common type of attack, but experts say the scammers have been quick to adopt new technologi­es, like “deep fake” audio generated by artificial intelligen­ce to pretend to be executives at a company and fool subordinat­es into sending money.

In the case of Williams, the San Francisco nonprofit director, thieves hacked the email account of the nonprofit’s bookkeeper, then inserted themselves into a long email thread, sent messages asking to change the wire payment instructio­ns for a grant recipient, and made off with $650,000.

After she discovered what happened, Williams said, her calls to law enforcemen­t went nowhere.

The FBI told her the local U.S. attorney’s office won’t take her case. She flew to Odessa, Texas, where the bank that initially received the stolen money was located. The money by then was long gone and the local detective was powerless to help. Williams asked her U.S. senators for help and later learned the Secret Service was investigat­ing, but she said it hasn’t given her any updates.

Crane Hassold, an expert on BEC scams and former cyber analyst with the FBI, has heard of federal prosecutor­s declining to take BEC cases unless several million dollars were stolen, a minimum threshold that speaks to how out of control the problem is.

“There’s so many of them they can’t possibly work them all,” said Hassold, now director of threat intelligen­ce at Abnormal Security.

The Justice Department has launched months-long operations in recent years that have netted hundreds of arrests worldwide.

But security experts say the wave of arrests has had little impact, and the FBI’s own numbers show that BEC scams continue to grow at a rapid clip.

 ?? ??
 ?? ERIC RISBERG / AP ?? Sherry Williams is executive director of One Treasure Island in San Francisco. Thieves hacked the email account of the nonprofit’s bookkeeper.
ERIC RISBERG / AP Sherry Williams is executive director of One Treasure Island in San Francisco. Thieves hacked the email account of the nonprofit’s bookkeeper.

Newspapers in English

Newspapers from United States