{"id":10265,"date":"2023-03-16T08:43:00","date_gmt":"2023-03-15T19:43:00","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=10265"},"modified":"2023-03-16T08:43:00","modified_gmt":"2023-03-15T19:43:00","slug":"cyber-attacks-on-emails-get-faster-and-faster","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=10265","title":{"rendered":"Cyber-attacks on emails get faster and faster"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221; sticky_enabled=&#8221;0&#8243; custom_margin=&#8221;||-19px|||&#8221;]<\/p>\n<h3>A lot can happen between your morning coffee and your lunch.<\/h3>\n<h2>That\u2019s all it takes to go from \u2018normal\u2019 to \u2018disaster\u2019 when the hackers strike.<\/h2>\n<p>Microsoft researchers recently worked backwards through a \u2018BEC\u2019 attack (business email compromise \u2013 IT people love to convert everything into three-letter acronyms).<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;3_5,2_5&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221; custom_padding=&#8221;16px|||||&#8221;][et_pb_column type=&#8221;3_5&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p>They found the hackers set up fake \u2018typo-squatting\u2019 email domains and had hijacked an email thread within a couple of hours.\u00a0 That\u2019s the time from when they started setting up until when they struck.<\/p>\n<p><strong>The business would have had very little warning that they were under attack before the hackers were already harvesting confidential information.<\/strong><\/p>\n<p>The hacker\u2019s goal is to gain access to an email account, then pretend to be a senior executive, so they can trick your payables team to make a fraudulent payment to the hacker.<\/p>\n<h3>They will use any means they can.\u00a0<\/h3>\n<p>Typo-squatting allows them to set up a fake email account with a minor misspelling so it looks legitimate.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;2_5&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_image src=&#8221;http:\/\/kinetics.co.nz\/wp-content\/uploads\/2023\/03\/EmailSpeed.jpg&#8221; title_text=&#8221;EmailSpeed&#8221; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221; custom_padding=&#8221;11px|||||&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<div class=\"et_pb_text_inner\">\n<div data-shortcode-id=\"0.1.0.0.0.1.0.0-1678865949262\" data-quickaccess-editable=\"yes\" class=\"et-fb-popover-tinymce\">\n<div class=\"mce-content-body\" contenteditable=\"true\" style=\"position: relative;\">\n<p>Another trick is \u2018man-in-the-middle\u2019 in which they setup a fake login-screen and pass through the MFA details.\u00a0 We\u2019ve outlined sone of the ways that MFA can be overcome such as <a href=\"http:\/\/kinetics.co.nz\/cyber-risk-mitigation-why-multi-factor-authentication-mfa-is-vital-but-not-enough\">\u2018fatigue\u2019<\/a> or similar <a href=\"http:\/\/kinetics.co.nz\/mfa-is-important-but-it-is-no-silver-bullet\/\">fake sites\u00a0<\/a> (but MFA still incredibly important).<\/p>\n<p>By impersonating a senior exec on an email address that looks legit, and getting involved in conversation, the perpetrator can uncover other names, learn about the organisation and even learn to mimic the language styles used.<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<\/div>\n<\/div>\n<h3>So, the news is that hackers can move faster than ever.<\/h3>\n<p>You might be headed into a meeting with everything being normal, only to find that while you were busy doing business, the hackers were setting up an attack on your business and using machine-learning AI tools to go faster and do more damage than you could imagine. \u00a0The evidence shows this isn\u2019t a theory, it\u2019s the reality.\u00a0<\/p>\n<p>It can happen at any time. The internet and the cloud means your systems and data are exposed <strong>around the clock<\/strong>.<\/p>\n<p>That\u2019s why we\u2019ve just completely reviewed and refreshed our <a href=\"http:\/\/kinetics.co.nz\/proactive-it-service-and-support\/\">KARE support service.<\/a> Our new plans are available now and we are no longer offering our older ones because, frankly, they don\u2019t offer the necessary protection for the cyber-threat landscape as we see it in 2023.<\/p>\n<p>In this case, our EDR and 365 monitoring along with MFA management are key to keeping you, and your colleagues safe,<\/p>\n<p>Refer: <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-business-email-compromise-attacks-can-take-just-hours\/\">Microsoft: Business email compromise attacks can take just hours (bleepingcomputer.com)<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A lot can happen between your morning coffee and your lunch. That\u2019s all it takes to go from \u2018normal\u2019 to \u2018disaster\u2019 when the hackers strike. Microsoft researchers recently worked backwards through a \u2018BEC\u2019 attack (business email compromise \u2013 IT people love to convert everything into three-letter acronyms).They found the hackers set up fake \u2018typo-squatting\u2019 email [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":10269,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4,5],"tags":[],"class_list":["post-10265","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-security"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/10265","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10265"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/10265\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10265"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10265"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10265"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}