微信内可能无法直接打开本站。请点右上角 ··· → 在浏览器打开,或复制链接。
Business Email Compromise Attack Hijacks Session Token to Steal Vendor Payments
RSS 官方收录 · 可信分层展示
关键摘要
Cybersecurity firm TrendAI uncovered a business email compromise (BEC) scheme in which an attacker tricked a victim into clicking on a link and was then able to reroute payments that were sent by the victim’s company and intended for its vendors, it said in a Aug.…
- 14 blog post.
- In this attack, the adversary targeted a finance user with a spear-phi…
- The spear-phishing email included the target’s name, job title and org…
摘要引擎:抽取
正文提要
Cybersecurity firm TrendAI uncovered a business email compromise (BEC) scheme in which an attacker tricked a victim into clicking on a link and was then able to reroute payments that were sent by the victim’s company and intended for its vendors, it said in a Aug. 14 blog post.
In this attack, the adversary targeted a finance user with a spear-phishing email, used an Adversary-in-the-Middle phishing page to bypass multifactor authentication, and hijacked the victim’s live Microsoft 365 session token, according to the post.
The spear-phishing email included the target’s name, job title and organization, said it concerned “PTO Request Denied” and called on the target to click a button labeled “View Conflicting PTO Dates,” the post said.
Having hijacked the victim’s live Microsoft 365 session token, the adversary then used three malicious inbox rules to auto-archive and mark as read incoming vendor and internal collection emails to conceal the fraud from the victim for 30 days while the attacker impersonated vendors and rerouted the company’s payments to bank accounts controlled by the attacker, per the post.
“The BEC campaign is another illustration of where the enterprise perimeter really sits today: trust and identity,” TrendAI said in the post. “By stealing a single authenticated session, the minds behind this campaign gained everything they needed to impersonate a finance user and redirect real money.”
PYMNTS reported in December 2024 that business email compromise attacks have evolved with a level of sophistication that is reshaping how companies must defend themselves.
While traditional BEC schemes often relied on impersonating high-ranking executives or key suppliers, the modern iteration is far more nuanced and multilayered, as phishing attempts get a shot in the arm from the democratization of artificial intelligence.
The PYMNTS Intelligence report “Winning the Fraud Fight: How AP Automation Can Deflect Rising Security Threats” found that 83% of U.S. companies had been targeted by highly sophisticated cyberfraud and that business email compromise schemes comprised the lion’s share of those attacks.
“Acting now is critical to prevent future losses as fraudsters continue to develop new tactics,” the report said. “Companies that adopt comprehensive fraud prevention strategies today will be better positioned to protect their assets and ensure long-term security.”
The post Business Email Compromise Attack Hijacks Session Token to Steal Vendor Payments appeared first on PYMNTS.com.