Beware of Business Email Compromise (Whaling) Cyber Attacks in 2016

Business Email Compromise (BEC) attacks are sophisticated scams that compromise legitimate business e-mail accounts to conduct unauthorized fund transfers. These attacks are also called ‘whaling’ because they are similar to phishing, but on a larger scale. BEC attacks have grown in popularity in recent years, and are expected to pose a significant risk to businesses in 2016.

The FBI reported a 270% increase in BEC victims since January 2015, and nearly $750 million of actual and attempted U.S. losses since August 2015. Research conducted by Mimecast, an email security provider, found that 55% of organizations have seen an increase in BEC attacks over the last three months.

Using complaint data, the FBI identified four general versions of BEC attacks.

  • The Supplier Swindle. A business is asked by a current supplier to wire an invoice payment to a fraudulent account. Hackers use spoofed e-mails that appear very similar to a legitimate account.
  • CEO Fraud. Spoofed or hacked e-mail accounts of high-level business executives are used to request a wire transfer from an employee within the company who is normally responsible for processing these requests.
  • Fraudulent Invoices. An employee’s personal e-mail account is hacked and used to request invoice payments from multiple vendors identified in the employee’s contact list.
  • Attorney Scam. An employee is asked to quickly transfer funds by someone posing as an attorney who is handling a confidential or time-sensitive matter for the business.

BEC attacks are not random. Victims are specifically targeted by hackers using information that is made readily available on company websites and social media sites like Facebook, LinkedIn and Twitter. For example, LinkedIn can be used to map entire departments and reporting structures. Websites may also provide valuable information, such as email addresses, titles, responsibilities and even biographical information.

According to Mimecast, a BEC attack can be broken down into five phases.

  • Research: Criminals identify a target organization and its employees. Open source intelligence, social media and corporate websites are then used to build an accurate picture of the organization and identify key executives and finance team members.
  • Similar Domain Names: Criminals may then register a domain name that sounds or appears similar to that of the target company. For example, the domain ajaxcornpany.com could be used to spoof ajaxcompany.com. Were you able to spot the difference between the two?
  • Whale Emails: Criminals make initial contact by posing as a high-level executive and sending an innocuous email to a member of the finance team. These emails are typically innocuous, brief and to the point, such as “I need you to complete a task ASAP, are you in the office?”
  • Victim Tricked: Due to the research done before the attack, victims are likely to believe the email is genuine and respond accordingly. Criminals may then engage in email ‘small talk’ prior to requesting a wire transfer.
  • Wire Transfer: Victims, typically those with authority to initiate or approve financial transactions, are asked to transfer funds. Having no reason to doubt the authenticity of the request, the funds are transferred.

BEC attacks can be very difficult to identify. Since criminals don’t rely on emails with attachments or links, current barriers are often inadequate. Nevertheless, steps can be taken to protect against BEC attacks. For example, in addition to increased awareness, the FBI identified various preventative measures, such as:

 

  • Create detection system to flag e-mails with extensions that are similar to company e-mail.
  • Register all domains that are similar to the company’s actual domain.
  • Verify changes in vendor payment with two-factor authentication, like requiring secondary approval.
  • Confirm requests to transfer funds. If verifying over the phone, use previously known numbers, not the numbers provided in the e-mail request.
  • Know your customers.
  • Carefully scrutinize all e-mail requests to transfer funds.

 

Businesses should also consider cyber insurance coverage to protect against cyber attacks that could not be prevented. Unlike traditional commercial insurance, Cyber Liability and Security Breach (Cyber Perils) Insurance policies protect against privacy injuries, such as identity theft, and cover the cost of complying with data breach notice laws.

We would be happy to provide you with more information about insurance for existing and emerging cyber threats.

Additional information is also available in our weekly Risk Management Newsletters.

Perhaps these predictions explain the growing number of businesses purchasing new cyber insurance policies or increasing coverage under existing cyber policies.

Are You Protecting Customers’ Credit and Debit Card Data?

It’s hard to ignore the fact that data security breaches seem to be increasing in frequency and severity, particularly those involving credit and debit card data. Just ask Home Depot, Michaels Stores, Neiman Marcus, or their 50+ million customers whose payment card data may have been compromised in 2014. To reduce the chances of making the list in 2015, preventative measures must be taken by every business that accepts credit and debit card payments.

The PCI Security Standards Council developed the Payment Card Industry Data Security Standard (PCI DSS) to encourage and enhance cardholder data security. This standard includes 12 requirements.

Build and Maintain a Secure Network and Systems

  • Install and maintain a firewall to protect cardholder data.
  • Do not use defaults for system passwords or security parameters.

Protect Cardholder Data

  • Protect stored cardholder data.
  • Encrypt transmission of cardholder data.

Maintain a Vulnerability Management Program

  • Protect systems against malware and regularly update anti-virus software.
  • Develop and maintain secure systems and applications.

Implement Strong Access Control Measures

  • Restrict access to cardholder data to those who need to know.
  • Identify and authenticate system access.
  • Restrict physical access to cardholder data.

Regularly Monitor and Test Networks

  • Track and monitor all access to networks and cardholder data.
  • Regularly test security systems and processes.

Maintain an Information Security Policy

  • Maintain a policy that addresses information security for all personnel.

The PCI Security Standards Council also provides a number of tips and strategies to increase the security of payment card data, such as:

  • Never store Sensitive Authentication Data, such as the full track contents on the magnetic stripe or chip, card verification codes/values, or PINs.
  • Ask point-of-sale vendors about the security of payment card systems.
  • Do not store cardholder data that is not needed.
  • Consolidate and isolate cardholder data that is needed.

The Council notes that the PCI DSS provides minimum security requirements that may be enhanced by additional controls and practices. Various laws, rules or regulations may also require enhanced security measurers. For example, under the Fair and Accurate Credit Transaction Act (FACTA), electronically printed credit and debit card receipts given to customers cannot include a card’s expiration date or more than the last five digits of the card number.

Sometimes security measures aren’t enough to prevent a data security breach, so businesses should use insurance to manage their cyber risks. There are a number of cyber liability products that protect against privacy injuries, such as identity theft, and that cover the cost of complying with various data breach notice laws. However, given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained.

A solid understanding of your insurance needs is the key to overcoming the quality versus cost argument. An experienced and reputable independent insurance agent can help you purchase insurance that is both economical and effective.

If you would like to learn more about insuring against cyber risks, contact us.

If you would like to subscribe to our newsletters please click here.

Here We Go Again with Another Massive Data Security Breach

Before the dust could settle on Target’s data security breach, news of a potentially larger one has surfaced. On September 18, 2014, Home Depot confirmed that it suffered a data breach involving the debit and credit card information of approximately 56 million customers. Target’s breach involved approximately 40 million cards.

Home Depot’s breach involved payment card information for purchases made at U.S. and Canadian Home Depot stores from April to September, 2014. According to Home Depot, criminals used unique, custom-built malware not seen previously in other attacks to breach payment card systems. Though their investigation is ongoing, Home Depot said names, card numbers, expiration dates, cardholder verification values and service codes may have been compromised.

Seeing yet another large business with substantial resources suffer a massive data security breach should be more than enough to confirm that data security breaches can happen to any organization. Though preventing data breaches is becoming more difficult, businesses can take steps to reduce the risk.

A subsidiary of Reinsurer Munich Re recently held a presentation with cybersecurity experts and risk managers to show how cybercriminals choose their targets and access their systems. This presentation provided several key takeaways for businesses.

  • Businesses are not only viewed as targets by cybercriminals, but also as conduits to attack a business’s clients.
  • Businesses must identify any data that may be valuable to others, and keep only what is needed.
  • Most hackers use email and browsers to access a business’s systems.

The cybersecurity presentation identified 10 ways for businesses to prevent a data breach.

  • Outsource payment processing (point-of-sale, web payments) to take advantage of their sophisticated and dedicated security measures.
  • Separate social media from financial activity by using a dedicated device for online banking and a different device for email and social media.
  • Don’t reuse passwords and don’t trust websites to store them for you. Set up a two-factor authentication process that verifies identity by sending a secret code to your phone.
  • Train employees to protect sensitive and confidential information. Remind employees that most malicious attacks involve email, and that they should alert others when suspicious emails are received.
  • Identify risks by evaluating systems and networks, including email infrastructure and browser vulnerability. Learn how business associates (vendors, suppliers, partners) handle data security.
  • Mandate encryption for all data that is stored (at rest) and transmitted (in motion), and avoid the use of Wi-Fi networks if possible.
  • Use the latest web browser version that is available rather than relying on individual patches and updates.
  • Update operating systems to take advantage of built-in security improvements.
  • Secure routers connecting business computers to the Internet. Set strong administrator passwords and, if Wi-Fi is necessary, use a WPA2 password.
  • Encrypt backup data and store it off-site.

Home Depot is currently dealing with the consequences of its data security breach by investigating the breach, updating data security systems, notifying potential victims, providing free identity theft protection and adjusting its public relations to minimize the damage to its reputation. The costs of these efforts can be staggering. For businesses lacking the resources of the Target’s and Home Depot’s, these costs can be devastating.

As we have seen, nothing is foolproof, so businesses should use insurance to protect against cyber risks. There are a number of cyber liability products that protect against privacy injuries, such as identity theft, and that cover the cost of complying with various data breach notice laws. However, given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained.

If you would like to learn more about insuring against cyber risks, contact us.

If you would like to subscribe to our newsletters please click here.

A Narrow View of Cyber Risks Can Leave You Overexposed

Recent, high-profile incidents show that every business is at risk of suffering a data security breach, regardless of size, resources or sophistication. To combat the risk, many organizations are taking steps to identify and secure organizational vulnerabilities, such as wireless networks, laptop computers, and even the office copy machine. However, a report by Zurich Insurance and the Atlantic Council suggests organizations must look beyond their own operations to truly recognize their exposure to cyber risks.

Businesses are increasingly using the internet and information technology functions to expand their operations and create opportunities. They are also increasing their exposure to external cyber risks that are often beyond their control. This is why businesses need to expand their horizon when evaluating and managing cyber risks. According to the report, businesses must consider these seven aggregations of cyber risk to fully understand their exposure.

  • Internal IT Enterprise: Risks associated with an organization’s internal IT (hardware, software, servers, processes).
  • Counterparties and Partners: Risks from dependence on or interconnection with outside organizations.
  • Outsource and Contract: Risks from contractual relationships with third-parties (IT and cloud providers, legal, accounting).
  • Supply Chain: Risks to supply chains in the IT sector and cyber risks to traditional supply chains and logistics.
  • Disruptive Technologies: Risks caused by unseen effects from, or disruptions to new technologies (smart grids, embedded medical devices, driverless cars), or existing but poorly understood technologies (internet, networks).
  • Upstream Infrastructure: Risks from disruptions to infrastructure relied on by economies and societies (electricity, telecommunications, financial systems).
  • External Shocks: Risks from incidents outside the system (international conflicts, acts of terrorism, malware pandemic).

Despite the external risks resulting from increased outsourcing and interconnectivity, businesses are urged to continue taking steps to control their internal cyber risks. According to the report, there are a relatively small number of actions that every organization can take to protect against most cyber risks, such as:

  • Implementing applicationwhite-listing to prevent systems from running programs that have not been pre-approved, such as malicious software
  • Using standard secure system configurations to keep systems simple and easier to defend.
  • Installing patch software for systems and applications within 48 hours of being released by the software manufacturers
  • Controlling administrative privileges to only those who need it and can be trusted with it

The report also recommends that businesses:

  • Expand their risk horizon to consider the seven aggregations of risk
  • Have cyber insurance, particularly for third-party risks associated with data breaches or business interruption
  • Deal with cyber risks at the board-level

Finally, the report states that resiliency is the key in a world where the number of cyber risks is increasing and the ability to control them is decreasing. To survive cyber threats and limit their impact, the report recommends that every business:

  • Incorporate redundancies in critical systems
  • Implement incident response and business continuity plans
  • Utilize scenario planning and exercises to stay prepared

As we have seen, nothing is foolproof, so businesses should use insurance to protect against cyber risks. There are a number of cyber liability products that protect against privacy injuries, such as identity theft, and that cover the cost of complying with various data breach notice laws.

Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like to learn more about insuring against cyber risks, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

Insurance for Tech Companies

Since most businesses rely on technology, providing technology services has become big business. Technology companies provide goods, services and expertise that can increase efficiency, productivity and profitability. These businesses may involve:

  • System / network development and administration
  • Application and website programming and design
  • Hardware installation and repair
  • Website hosting, maintenance and optimization
  • Information Technology consulting, staffing and training
  • Project management
  • Consulting

Technology companies face the same risks as other businesses, so traditional insurance coverages are required, such as general liability, property, automobile and workers compensation insurance. However, additional insurance coverage may also be necessary to address the unique risks facing technology companies.

For example, many technology companies do not believe they need Errors & Omissions (Professional Liability) insurance. The reality is that technology companies, just like doctors and lawyers, can be held liable for errors and omissions committed in the performance of their professional services.

Unfortunately, a traditional E&O policy may not protect against many of the risks unique to technology companies. This is why technology-specific insurance is needed to cover technology-specific risks. To ensure adequate insurance coverage, technology companies should look for an E&O policy that, at a minimum:

  • Broadly defines “Computer Technology Services”
  • Provides coverage for failure to prevent unauthorized access to or use of any electronic system or program of a third party
  • Provides coverage for unauthorized, corrupting or harmful pieces of code, including, computer viruses, worms and Trojan Horses
  • Covers personal injury claims alleging wrongful entry, wrongful eviction, wrongful detention, false arrest, false imprisonment, libel, slander or defamation, advertising injury or violation of any right of privacy
  • Provides sufficient coverage limits

The right E&O policy lets technology companies focus on their business knowing that they are protected in the event of a claim. And, since clients are increasingly requiring proof of E&O insurance from their technology vendors, an E&O policy may also create new opportunities.

Given the complexity of the risks facing technology companies, evaluating insurance needs and options is not always easy. For example, in addition to E&O insurance, technology companies may also need coverage for cyber liability claims, including data security breaches, which are becoming more common.

An experienced insurance agent can guide you through the process of protecting your technology company. If you would like to learn more about insuring a technology company, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.

Protecting Your Business from Cyber Liability Risks

Almost every business relies on computers, networks and electronic data to support their business operations and serve their customers. What most business owners don’t realize is the substantial exposure associated with their use of electronic platforms and the data those platforms host. Today, Cyber Liability insurance is available to business owners for the exposures associated with their use of electronic platforms.

Most businesses are not aware that standard Commercial General Liability policies do not contemplate these types of claims, leaving companies with significant gaps in coverage for cyber-related perils. Any business that collects or handles confidential information, stores client data, uses email, generates revenue online, relies on the internet for transactions or uses a network to conduct its business is in need of this important coverage.

Cyber Liability insurance is designed to protect the insured against direct and indirect loss to the Company’s assets as well as third party claims of negligence. Losses can be caused by hazards such as the transmission of virus/malicious code, denial of service attacks, physical theft of a computer/device, accidental release of an insured’s confidential data and attacks by hackers. First party coverage under the Cyber Perils policy includes:

  • Loss of data
  • Loss of business income
  • Electronic theft
  • Cyber extortion
  • Security event costs

Third party claims of negligence can include allegations that an insured:

  • Permitted the unauthorized disclosure of confidential information
  • Failed to secure a Network against attack
  • Committed an act of defamation

Of particular interest to many businesses are data breach security concerns. Recent studies have shown that over 70 percent of all data security breaches are experienced by small to medium sized businesses and the cost of a breach can be staggering. The average cost for a data breach claim is over two million dollars. These damages include the cost of data reconstruction, customer/client notification and credit monitoring. This leaves small businesses most at risk because they are unlikely to have the time and resources necessary to handle a data breach security event.

Given the variety and complexity of these occurrences, an experienced insurance agent should be consulted to ensure that proper coverage is obtained and that no gaps remain. If you would like to learn more about insuring against data security breaches, contact us.