Over the years, I’ve seen a significant number of incident response (IR) cases that have stemmed from a business email compromise (BEC), which should come as no surprise considering recent studies show that approximately 90% of cyberattacks begin with a phishing email. A BEC occurs when an adversary uses email to defraud an organization or gain access to sensitive information. Attackers gain access to email accounts through phishing emails, password attacks, unsecured wi-fi, credential stealing malware, etc. Some attackers like to stay in the email environment, where they can snoop around, change rulesets, and impersonate people, in hopes of tricking others to complete specific tasks; while more sophisticated hackers find ways to move from email into the IT environments of their victims where they usually deploy ransomware. Whatever the approach may be, the end goal of the attacker is to find the quickest way to steal money and/or information without being detected.
Because of the prevalence of BECs, it’s not uncommon for organizations to handle these types of incidents on their own if they believe there hasn’t been too much damage (keep in mind that what they “believe” and what actually happened may be vastly different). Once spotted, an attacker can usually be kicked out of a user’s mailbox through password changes and enabling multi-factor authentication (MFA). The organization can then make a risk-based decision as to whether further action is required.
While it’s easy to assume that the situation was handled by kicking the attacker out of the mailbox, unfortunately, many businesses have learned that what you don’t know today, can harm you tomorrow. Which is why, if you ever suspect a BEC, you should call in your legal counsel and a cybersecurity professional to investigate how far the adversary progressed – and whether or not they are still in your email environment or IT network. Based on the findings, there may be legal obligations your organization must comply with.
After an organization has fallen victim to a BEC, a review of available log data, devices, and settings comes into play. If a proper IR investigation is not conducted (although we highly recommend having one and they are usually required by insurance carriers if a claim is filed), stakeholders should, at the very least, consider preserving the impacted user’s mailbox, all relevant log data, and devices at the time of the incident in case information is used or leaked at a later date. At Avalon Cyber, we’ve seen many cases where this was not done initially and how it impeded the IR investigation later.
We all know there’s no silver bullet in IT security, no one-and-done action that can prevent all attacks, or even one framework that can check all of the boxes, but we do know that a defense-in-depth strategy can give these online thieves a run for their money (pun intended) by making it difficult to break in, and even harder to stay in (if, in fact, they do breach a system).
Now that we’ve discussed ways to help prevent malicious emails from reaching users, what happens when these technologies fail, and a phishing email is successfully executed? This is where I believe the use of a Security Information and Event Management (SIEM) could be beneficial. By utilizing a SIEM, input from your email environment, servers, firewalls, antivirus agents, intrusion prevention systems, and much more can be collected, correlated, and alerted on within one place, so immediate action can be taken no matter where the threat occurs. Those of us who have been involved in an IR case know how easily adversaries can move laterally into other hosts/applications. And speaking of IR cases, a SIEM also provides “one place” to conduct most, if not all, of your IR investigations too.
A non-exhaustive list of a few things to look for if you suspect a BEC are as follows:
Remember, a SIEM is what you make it and can be fine-tuned however an organization sees fit. You can create rules to fire off alerts based on just about anything you want, as long as the logs and/or agent activity are coming into the SIEM. Most SIEMs come with out-of-the-box alert rules in place, but it’s recommended that your security team takes the time to further develop these rules to align with your organization’s risk appetite and security strategy. Also, make sure logging is enabled wherever possible/feasible – NEVER assume this is in place by default.
It only takes one unwitting employee to click on a phishing email and provide credentials for an attacker to gain access and wreak havoc. So, to wrap up, here are some of my recommendations to help thwart a BEC attack and considerations for when the inevitable happens (sigh):
If you have been compromised, Avalon Cyber offers full incident response support, which includes threat hunting, actionable threat intelligence, digital forensics, and a comprehensive report detailing the results of our breach investigation.
Contact Avalon Cyber today if you have any questions or need assistance.
Brandy Griffin is the Director of Cyber Operations, overseeing our team of penetration testers and security analysts. She continues to support our clients' needs on a daily basis and ensures we always deliver high-quality customer service. Brandy’s experience in cybersecurity is further complimented by her skills in eDiscovery and digital forensics from previous positions she’s held at Avalon and her past employer, a fortune 1000 Company.