Peraton Fights Back Against Cybersquatting Following Invoice Scam

Protect Your Business: How to Combat Credential Theft and Invoice Fraud

In today’s digital landscape, businesses face a constant barrage of cyber threats. From phishing scams to sophisticated malware attacks, the risks are ever-present. One particularly concerning trend is the rise of credential theft, where scammers attempt to steal employee login information to gain unauthorized access to sensitive systems. This often leads to devastating consequences, including invoice fraud, financial losses, and reputational damage.

Invoice fraud concept: Two fingers pointing to line items on an invoice.

The Growing Threat of Credential Theft

Recent conversations with several business owners highlighted a common challenge: the vulnerability of new employees to credential theft attempts. Scammers often target new hires, assuming they are less familiar with company security protocols and more likely to fall for deceptive tactics.

These tactics can range from phishing emails disguised as internal communications to fake login pages designed to capture usernames and passwords. Once scammers obtain these credentials, they can access email accounts, internal networks, and other critical systems.

My own family experienced a similar incident recently. When my wife started a new job, someone attempted to impersonate the company’s CEO via text message. While the message was sent to me instead of her (likely due to similar phone numbers), it underscores the pervasive nature of these scams.

Invoice Fraud: A Common Outcome of Credential Theft

One of the most common and damaging consequences of credential theft is invoice fraud. Once scammers gain access to a company’s email system, they can intercept legitimate invoices, alter payment details, and redirect funds to their own accounts. This type of fraud can be difficult to detect, as the fake invoices often appear authentic.

The process typically involves the following steps:

  1. Gaining Access: Scammers steal employee credentials through phishing or other means.
  2. Monitoring Communications: They monitor email conversations to identify upcoming invoices.
  3. Intercepting Invoices: They intercept legitimate invoices sent to customers.
  4. Altering Payment Details: They modify the invoice, changing the bank account information to their own.
  5. Deceptive Communication: They impersonate the company and send the altered invoice to the customer.
  6. Funds Diversion: The customer unknowingly wires funds to the scammer’s account.

Real-World Example: The Peraton Case

A recent cybersquatting lawsuit filed by government contractor Peraton provides a stark example of invoice fraud in action. In this case, someone registered the domain name “peratons.com” (note the added “s” at the end), a common tactic known as typosquatting.

The scammers then hijacked an email thread between Peraton and one of its customers. They used the fraudulent domain to send emails that appeared to be legitimate, tricking the customer into wiring funds to their account. The subtle difference in the domain name was likely unnoticed by the customer, highlighting the sophistication of these scams.

Peraton took swift action, filing an in rem lawsuit against the domain name and requesting an injunction to prevent further fraudulent activity. While the injunction may not have been ultimately necessary, the domain registrar, Namecheap, placed the domain on ClientHold, effectively preventing it from being used for malicious purposes.

Protecting Your Business: Proactive Measures

The Peraton case and the experiences of other business owners underscore the importance of taking proactive measures to protect your business from credential theft and invoice fraud. Here are some essential steps you can take:

1. Employee Training and Awareness

The most important step is to educate your employees about the risks of credential theft and invoice fraud. Provide regular training sessions on:

  • Phishing Awareness: Teach employees how to identify and avoid phishing emails, including those disguised as internal communications.
  • Password Security: Emphasize the importance of strong, unique passwords and discourage the reuse of passwords across multiple accounts.
  • Two-Factor Authentication (2FA): Implement 2FA for all critical systems, adding an extra layer of security that makes it much harder for scammers to access accounts even if they have stolen passwords.
  • Suspicious Activity Reporting: Encourage employees to report any suspicious activity, such as unusual emails or login attempts, immediately.
  • Invoice Verification Procedures: Establish clear procedures for verifying invoices, including contacting the vendor directly to confirm payment details.

2. Implement Strong Security Measures

In addition to employee training, it’s crucial to implement robust security measures to protect your systems and data:

  • Regular Security Audits: Conduct regular security audits to identify vulnerabilities and ensure that your security protocols are up to date.
  • Network Monitoring: Implement network monitoring tools to detect suspicious activity and unauthorized access attempts.
  • Email Security Solutions: Use email security solutions to filter out phishing emails and other malicious content.
  • Endpoint Protection: Deploy endpoint protection software on all devices to protect against malware and other threats.
  • Domain Monitoring: Monitor for typosquatting domains (like “peratons.com”) that could be used to impersonate your company.

3. Establish Clear Communication Protocols

Clear communication protocols can help prevent invoice fraud by ensuring that all parties are aware of the correct payment procedures:

  • Verify Changes in Payment Details: Always verify any changes in payment details directly with the vendor, using a known and trusted phone number or email address.
  • Secure Communication Channels: Use secure communication channels, such as encrypted email or phone calls, when discussing sensitive information like payment details.
  • Dual Authorization: Implement a dual authorization process for large payments, requiring two individuals to approve the transaction.

4. Monitor Your Online Reputation

Regularly monitor your online reputation to identify any potential scams or impersonation attempts. Set up Google Alerts for your company name and other relevant keywords to stay informed about what is being said about your business online.

5. Incident Response Plan

Develop an incident response plan to outline the steps you will take in the event of a security breach or fraud attempt. This plan should include:

  • Containment: Steps to contain the breach and prevent further damage.
  • Eradication: Steps to remove the threat and restore systems to normal operation.
  • Recovery: Steps to recover any lost data and resume business operations.
  • Lessons Learned: A review of the incident to identify areas for improvement in your security protocols.

Conclusion

Credential theft and invoice fraud are serious threats that can have devastating consequences for businesses of all sizes. By implementing the proactive measures outlined above, you can significantly reduce your risk and protect your company from these costly scams. Employee training, strong security measures, clear communication protocols, and vigilant monitoring are all essential components of a comprehensive cybersecurity strategy. In today’s digital world, vigilance is the key to staying ahead of the scammers and protecting your business.