Top CFOs are being targeted by a sophisticated email scam

A group of hackers based in Nigeria is trying to trick thousands of top executives across the globe into sen...

Posted: Dec 4, 2018 2:51 PM
Updated: Dec 4, 2018 2:51 PM

A group of hackers based in Nigeria is trying to trick thousands of top executives across the globe into sending them company funds.

The ambitious scheme that mainly targets chief financial officers via email is described in a new report by cybersecurity firm Agari, which investigated the group after coming under attack itself.

Business operations

Business, economy and trade

Company activities and management

Corporate finance

Continents and regions

Digital security

England

Europe

London

Northern Europe

Technology

United Kingdom

Crime, law enforcement and corrections

Criminal offenses

Fraud and financial crimes

Wire fraud

"Targets included companies in a very broad range of sectors, from small businesses to the largest multinational corporations," the report warns. More than half of them are in the United States.

The attackers are carrying out an increasingly common scam known as "business email compromise" in which they attempt to pose as a company insider, such as the CEO, requesting a money transfer to an outside account.

The FBI estimates that businesses around the world lost more than $12 billion through this kind of email scam between October 2013 and May 2018.

Agari said that the Nigerian group, which it calls "London Blue," has developed a highly sophisticated operation to dupe money out of finance executives.

"London Blue operates like a modern corporation," the report says. The group has people working on business intelligence, sales, email marketing, financial operations and human resources, according to Agari.

It carries out attacks in multiple languages and has at least 17 collaborators in the United States, United Kingdom and other Western European countries who are mainly involved in moving stolen money, Agari added.

50,000 finance execs on the target list

The email security firm said that during its investigation, it got hold of a list of the group's potential targets this year that contained more than 50,000 finance executives, of which 71% were CFOs.

Agari declined to reveal how it secured the data, other than saying it had actively engaged with the scammers. It said it had shared the info with US and UK law enforcement.

"Several of the world's biggest banks each had dozens of executives listed," it said. "The group also singled out mortgage companies for special attention, which would enable scams that steal real estate purchases or lease payments."

As well as the United States, companies in more than 80 other countries were on the list, including Spain, the United Kingdom, Finland, the Netherlands and Mexico.

Agari said it became aware of London Blue after the group tried to trick the security firm's own CFO in August. Agari said it "then engaged actively with the attacker, giving us an initial glimpse of the gang that we would widen into a penetrating X-ray."

London Blue relies on commercial data providers, most recently one based in San Francisco, to build up its list of targets and gather information about them, according to the report. That includes executives' names, company titles, work email addresses and personal email addresses.

The list of more than 300 potential targets on which Agari's CFO appeared was obtained by London Blue from a commercial data provider in November 2017.

The list also contained information about "CFO victims at one of the world's top private universities, a major enterprise data storage company, a famed guitar maker, casinos and hotels, a retirement home, and small and medium-sized businesses of all types," the report says.

Agari estimated that the scam has caused damage worth hundreds of thousands of dollars.

Minnesota Coronavirus Cases

Data is updated nightly.

Cases: 609387

Reported Deaths: 7743
CountyCasesDeaths
Hennepin1262491796
Ramsey52997910
Dakota47216475
Anoka43200465
Washington27664296
Stearns22659227
St. Louis18245319
Scott17686139
Wright16518153
Olmsted13503103
Sherburne1212396
Carver1073749
Clay829692
Rice8249111
Blue Earth769944
Crow Wing687999
Kandiyohi669885
Chisago626954
Otter Tail590087
Benton585198
Goodhue485574
Douglas477781
Mower477533
Winona463552
Itasca462768
Isanti445566
McLeod434261
Morrison427762
Beltrami410163
Nobles409850
Steele400719
Polk390772
Becker389157
Lyon365054
Carlton356958
Freeborn350734
Pine337323
Nicollet334045
Mille Lacs314856
Brown308640
Le Sueur299527
Cass288133
Todd288133
Meeker265444
Waseca240723
Martin236933
Roseau212221
Wabasha20833
Hubbard197741
Dodge18943
Renville183146
Redwood178141
Houston175416
Cottonwood168124
Wadena165023
Fillmore158910
Faribault156920
Chippewa154038
Pennington153820
Kanabec147828
Sibley147310
Aitkin139237
Watonwan13619
Rock129019
Jackson123112
Pipestone117126
Yellow Medicine115320
Pope11396
Murray107310
Swift107318
Koochiching96819
Stevens92611
Clearwater89217
Marshall88817
Lake84320
Wilkin83813
Lac qui Parle76122
Big Stone6094
Grant5958
Lincoln5863
Mahnomen5669
Norman5509
Kittson49122
Unassigned48193
Red Lake4037
Traverse3815
Lake of the Woods3474
Cook1740

Iowa Coronavirus Cases

Data is updated nightly.

Cases: 374664

Reported Deaths: 6109
CountyCasesDeaths
Polk58891646
Linn21448342
Scott20426250
Black Hawk16680319
Woodbury15319230
Johnson1473686
Dubuque13595213
Dallas1144099
Pottawattamie11307177
Story1082848
Warren592092
Clinton564393
Cerro Gordo562297
Webster538996
Sioux519174
Muscatine4920106
Marshall491479
Des Moines478275
Jasper452073
Wapello4366123
Buena Vista431040
Plymouth404982
Lee392658
Marion369177
Jones301257
Henry301037
Bremer292763
Carroll286252
Boone271234
Crawford270841
Benton262755
Washington259851
Dickinson250745
Mahaska232551
Jackson225842
Kossuth219166
Clay217327
Tama213372
Delaware211743
Winneshiek200636
Buchanan196734
Page195422
Cedar192923
Hardin191144
Wright189140
Fayette188243
Hamilton186851
Harrison181973
Clayton173057
Butler167835
Madison167719
Floyd164642
Mills163824
Cherokee161538
Lyon160941
Poweshiek159036
Allamakee155552
Hancock153134
Iowa148324
Winnebago145731
Calhoun143113
Cass140855
Grundy139333
Emmet136741
Jefferson134535
Sac132620
Shelby131838
Louisa130249
Union129535
Appanoose128049
Franklin127823
Mitchell127243
Chickasaw125717
Guthrie124532
Humboldt124526
Palo Alto114924
Montgomery106738
Howard105322
Clarke102424
Monroe100633
Keokuk99932
Ida92735
Adair89632
Davis86825
Pocahontas86822
Monona85931
Greene79111
Osceola79017
Lucas77423
Worth7568
Taylor67112
Decatur6629
Fremont64810
Ringgold56824
Van Buren56718
Wayne56323
Audubon52913
Adams3494
Unassigned90
Rochester
Clear
75° wxIcon
Hi: 87° Lo: 62°
Feels Like: 75°
Mason City
Partly Cloudy
70° wxIcon
Hi: 89° Lo: 65°
Feels Like: 70°
Albert Lea
Partly Cloudy
70° wxIcon
Hi: 87° Lo: 62°
Feels Like: 70°
Austin
Partly Cloudy
66° wxIcon
Hi: 88° Lo: 59°
Feels Like: 66°
Charles City
Partly Cloudy
68° wxIcon
Hi: 87° Lo: 61°
Feels Like: 68°
Heat Trend on Tap for Week Ahead
KIMT Radar
KIMT Eye in the sky

Latest Video

Image

DREAMS COME TRUE

Image

TRIP OF A LIFETIME

Image

QUARRY HILL NATURE CENTER CAVE TOURS

Image

QUARRY NATURE CENTER CAVE TOURS

Image

Rochester Honkers bat boy wrapping up two years with the team

Image

The Curling Club of Rochester is at the Olmsted County Fair this year

Image

Motocross at Spring Creek National

Image

Larping group meets each Sunday

Image

Spring Creek Motocross

Image

Ryan's Evening Forecast (7/25/21)

Community Events