Compromised Messaging Apps Lead To Executive Impersonation Scams

The India Cyber Crime Coordination Centre recently issued a warning about the increase of executive impersonation scams on messaging apps.

These executive impersonation scams, called "Boss Scams", occur when cyber criminals pretend to be senior company executives in order to pressure employees to transfer money. The scammers rely on urgency to convince the employee to bypass protocol and transfer money without allowing them time to think and utilize proper procedures.

Cyber criminals are now using messaging apps such as WhatsApp and Microsoft Teams to execute this scam. They pose as senior executives and reach out to employees via these platforms. The novelty of carrying these schemes out via messaging apps instead of email makes the request seem authentic, tricking employees.

Source: https://www.outlookmoney.com/news/boss-scam-alert-cyber-criminals-are-using-whatsapp-to-trick-employees-into-sending-company-funds

Commentary

Many view messaging apps as more secure than traditional email or texting.

This way of thinking is exactly what cyber criminals are counting on as they leverage the perceived legitimacy and personal nature of messaging apps to convince employees to transfer money by impersonating executives.

To help avoid the risks on messaging apps, consider the following:

· Apply the same business email compromise controls to all messaging platforms including WhatsApp, Microsoft Teams, Slack, Signal, text message, and more.

· Require independent verification for all communications regarding fund transfers.

· Never allow independent verification to occur on a number or email address provided within the messaging app that instigated the need for verification. Instead, always use a known, trusted phone number or email address.

· Prohibit fund transfers when they are initiated only via chats or text messages, no matter who is making the request.

· Publish a list of approved channels for fund transfer requests.

· Conduct training focused on fraud tactics, including urgency, authority, and secrecy, which cyber criminals often use to get employees to bypass proper protocols.

Finally, your opinion is important to us. Please complete the opinion survey:

Product

Articles

Compromised Messaging Apps Lead To Executive Impersonation Scams

Fraudsters are using messaging apps to impersonate senior executives and convince employees to send money. We discuss how this traditionally email-centered scam has moved to messaging apps and how to avoid the risks.

Retaliatory Actions In Healthcare: What Are They?

A New Jersey hospital must pay $1 million to a former physician for retaliation after she testified in a class action. We examine this case and retaliatory actions.

Unilateral Access To Funds Leads To Multi-Million Dollar Embezzlement?

A private equity fund manager was able to embezzle more than $11 million through bypassing the investment committee. We discuss the importance of committee oversight to help prevent fraud.

AI Malware May Be The New Hot Scam, But Don't Forget The Classics

AI has been getting much media attention in the cybersecurity sphere; however, the cyber attack basics are still legitimate risks, and they are not going away. We discuss those risks and what organizations need to know.

How Exclusion And Ultimatums To Whistleblowers Support Charges Of Retaliation

A health system is sued by an employee, who alleged she was excluded and given an ultimatum after reporting compliance concerns. We comment on the risks healthcare employers create when they isolate employees instead of conducting an investigation.