الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

A targeted attack mimics communication from company CEO to steal funds

 

Over the last weeks, Kaspersky detected a series of sophisticated attack attempts aimed at deceiving an organization’s finance team into paying fraudulent invoices. Emails mimicking correspondence between the organization’s CEO and contractor companies were sent to the organization’s finance department to persuade them into paying urgent “invoices” for alleged “consulting services”. These attack attempts highlight a disturbing trend of targeted schemes leveraging forged executive identities to exploit corporate trust.
The analyzed attack attempts were examples of business email compromise (BEC) attacks. As a rule, such attacks are made on behalf of a management representative of a compromised firm. Importantly, in all analyzed cases the senders were fake – the real addresses from where the emails came had nothing in common with the displayed sender names. These tricks were used to persuade the victims that the emails were legitimate.
Some incidents involved emails that imitated correspondence between the company’s CEO and an alleged contractor law firm, urging the financial department to pay the attached fake invoice. The fake correspondence with the CEO of a victim company was used as “proof” that the request for payment was legitimate. In this attack the name of the fictional partner company was indicated only in the name of the sender field, and a real email address was different and changed from email to email.
Other incidents featured similar emails that mimicked communications between the CEO and contractor companies to request urgent payment for a fake invoice, but this time the invoice itself was not attached.
“This attack stands out for its meticulous attention to detail and exploitation of trusted relationships. By fabricating convincing email threads and impersonating high-level executives, attackers are banking on employees’ reluctance to question seemingly authentic requests. Companies must prioritize employee training and robust email verification systems to counter these evolving threats,” commented Anna Lazaricheva, spam analyst at Kaspersky.
In order to avoid becoming a victim of fraudulent messages and specifically business email compromise attacks, Kaspersky experts advise the following:
• Check the sender’s email address and do not rely on the displayed name of the sender, as actual email addresses may have nothing in common with the companies and people who are displayed to have sent the email.
• Only open emails and click links if you are sure you can trust the sender; make sure that the sender’s address is legitimate.
• When a sender is legitimate, but the content of the message seems strange, it is worth checking with the sender via an alternative means of communication.
• Check the spelling of a website’s URL if you suspect you are faced with a phishing page. The URL may contain mistakes that are hard to spot at first glance, such as a 1 instead of I or 0 instead of O.
• Use a proven cybersecurity solution such as Kaspersky Next and Kaspersky Premium when surfing the web.

Related Posts:

Kenzz Marks Three Years of Growth and Community Impact with “All Good Things Come in 3s” Campaign

DevisionX and NtegralOne Announce Strategic Partnership to Deliver Integrated AI Solutions Across Egyptian Markets

ZG Developments to Participate in Cityscape Egypt 2025 to Showcase Achievements and Newest Project

HUAWEI Charts the Future of Smart Technology with Pioneering Product Lineup

Kaspersky warns travelers: AI-powered attacks are targeting hotel guests

“EFG Hermes Tops Extel 2025 with EMEA Conference”

Tashkeel Reopens Nad Al Sheba 1 Gallery with Of Liminal Threads by Ranim AlHalaky

Valu and MobileMasr Launch Egypt’s First Peer-to-Peer BNPL Service for Pre-OwnedSmartphones

آخر الأخبار
خبير اقتصادي: زيارة رئيس سنغافورة لمصر يعزز من الشراكة الاستراتيجية بين الدولتين فرص استثمارية جديدة وطفرة في أسعار الأسهم والعقارات عقب خفض الفائدة وزير الدولة للإنتاج الحربي يستقبل السفير الباكستاني بالقاهرة لبحث أوجه التعاون في مجال التصنيع العسك... وزير التربية والتعليم يستكمل جولته لمتابعة انطلاق العام الدراسي الجديد بعدد من المدارس وزير التربية والتعليم يستكمل جولته لمتابعة انطلاق العام الدراسي الجديد بعدد من المدارس شركة «AJAD Developments» تطرح وحدات مميزة بمشروع «Elaia» خلال معرض سيتي سكيب 2025 المركز الإعلامي لمجلس الوزراء: مدينة الدواء "جيبتو فارما" أمان دوائي لمصر واستثمار في صحة المواطن مجموعة جدير تعلن شراكتها مع IHG العالمية لإطلاق أول فندق إنديجو في مصر اورنچ مصر تُعلن عن الفائزين في مسابقتها المحلية للمشروعات الناشئة Orange Social Venture Prize Kenzz Marks Three Years of Growth and Community Impact with “All Good Things Come in 3s” Campaign "كنز" تحتفل بثلاث سنوات من النمو والتأثير المجتمعي عبر حملتها الجديدة "كنز تالت ومكمل" تحالف “IMS للتطوير” و”وينفسيتور” يبدآن تنفيذ المرحلة الأولى من مشروع “كابيلا ريزيدنس” بالمعادي.. وتع... في مؤتمر ICCE 2024: تريبو كير تطلق خطتها لقيادة سوق التجميل والدرماتولوجي في مصر والشرق الأوسط برق سيستمز تحصد ثلاث جوائز من فورتينت أفضل شريك أداء لعام ٢٠٢٤  في مصر البنك المركزي المصري يشارك في حفل تخرج طلاب مدينة زويل لعام 2025 DevisionX and NtegralOne Announce Strategic Partnership to Deliver Integrated AI Solutions Across Eg... انطلاق معرض (تراثنا 2025) في ٤ أكتوبر القادم بمركز مصر للمعارض الدولية وزير الإسكان يُصدر 7 قرارات إزالة لمخالفات بناء بمدينة السادات والساحل الشمالي الغربي شراكة بين DevisionX وNtegralOne لتقديم حلول ذكاء اصطناعي متكاملة في مصر والشرق الأوسط وزير التربية والتعليم ومحافظ القليوبية يتابعان سير العملية التعليمية بعدد من المدارس