Security

How to protect your startup from email scams

Comment

Image Credits: Getty Images / anilakkus

Despite years of claims that the “death of email” is fast approaching, the decades-old communication method continues to thrive in business. In particular, the business of hacking.

An email containing a link that looks legitimate but is actually malicious remains one of the most dangerous yet successful tricks in a cybercriminal’s handbook and has led to some of the largest hacks in recent years, including the 2022 breach of communications giant Twilio and last year’s hack of social media platform Reddit

While these emails are sometimes easy to spot, be it thanks to bad spelling or an unusual email address, it is becoming increasingly difficult to identify a dodgy email from a legitimate one as hackers’ tactics become increasingly sophisticated.  

Take business email compromise (or BEC), for example, a type of email-borne attack that targets organizations large and small with the aim of stealing money, critical information, or both. In this type of scam, hackers impersonate or compromise someone familiar to the victim, such as a co-worker, boss or business partner, to manipulate them into unknowingly disclosing sensitive information.

The risk this poses to businesses, particularly startups, can’t be overstated. Individuals in the U.S. lost close to $3 billion in BEC scams last year alone, according to the latest data from the FBI. And these attacks are showing no signs of slowing down.

How to spot a business email compromise scam

Look for the warning signs

While cybercriminals have become more advanced in their email-sending tactics, there are some simple red flags that you can — and should — look out for. These include an email sent outside of typical business hours, misspelled names, a mismatch between the sender’s email address and the reply-to address, unusual links and attachments, or an unwarranted sense of urgency. 

Contact the sender directly

The use of spear phishing — where hackers use personalized phishing emails to impersonate high-level executives within a company or outside vendors — means it can be near-impossible to tell whether a message has come from a trusted source. If an email seems unusual — or even if it doesn’t — contact the sender directly to confirm the request, rather than replying via any email or any phone number provided in the email.

Check with your IT folks

Tech support scams are becoming increasingly common. In 2022, Okta customers were targeted by a highly sophisticated scam that saw attackers send employees text messages with links to phishing sites that imitated the look and feel of their employers’ Okta login pages. These login pages looked so much like the real deal that more than 10,000 people submitted their work credentials. Chances are, your IT department isn’t going to contact you via SMS, so if you receive a random text message out of the blue or an unexpected pop-up notification on your device, it’s important to check if it’s legitimate.

Be (even more) wary of phone calls

Cybercriminals have long used email as their weapon of choice. More recently, criminals rely on fraudulent phone calls to hack into organizations. A single phone call reportedly led to last year’s hack of hotel chain MGM Resorts, after hackers successfully deceived the company’s service desk into granting them access to an employee’s account. Always be skeptical of unexpected calls, even if they come from a legitimate-looking contact, and never share confidential information over the phone.  

Multi-factor all the things!

Multi-factor authentication — which typically requires a code, PIN, or fingerprint for logging in along with your regulator username and password — is by no means foolproof. However, by adding an extra layer of security beyond hack-prone passwords, it makes it far more difficult for cybercriminals to access your email accounts. Take one security step even further by rolling out passwordless technology, like hardware security keys and passkeys, which can prevent password and session token theft from info-stealing malware.

Implement stricter payment processes

With any type of cyberattack, a criminal’s ultimate goal is to make money, and the success of BEC scams often hinges on manipulating a single employee into sending a wire transfer. Some financially motivated hackers pretend to be a vendor requesting payment for services performed for the company. To lessen the risk of falling victim to this type of email scam, roll out strict payment processes: Develop a protocol for payment approvals, require that employees confirm money transfers through a second communication medium, and tell your financial team to double-check every bank account detail that changes. 

You can also ignore it

Ultimately, you can minimize the risk of falling for most BEC scams by simply ignoring the attempt and moving on. Not 100% sure that your boss actually wants you to go out and buy $500 worth of gift cards? Ignore it! Getting a call you weren’t expecting? Hang up the phone! But for the sake of your security team and helping your co-workers, don’t stay quiet. Report the attempt to your workplace or IT department so that they can be on higher alert.

More TechCrunch

Featured Article

One man decided to take on Google Maps, 20 years later OpenStreetMap is still going strong

From internet protocols and operating systems, to databases and cloud services, some technology is so omnipresent most people don’t even know it exists. The same can be said about OpenStreetMap, the community-driven platform that serves companies and software developers with geographic data and maps so they can rely a little…

One man decided to take on Google Maps, 20 years later OpenStreetMap is still going strong

This list only includes major penalties issued to tech firms under the GDPR. In recent years, some significant sanctions have also been issued on Big Tech

The 10 largest GDPR fines on Big Tech

The data breach is the latest security issue to beset CSC ServiceWorks over the past year, after multiple researchers found security bugs.

CSC ServiceWorks reveals 2023 data breach affecting thousands of people

Featured Article

After global IT meltdown, CrowdStrike courts hackers with action figures and gratitude

CrowdStrike tried to go back to business as usual at one of the world’s largest annual cybersecurity conferences, weeks after its massive global IT crash.

After global IT meltdown, CrowdStrike courts hackers with action figures and gratitude

Tragedy has again struck a famous Silicon Valley family. Former YouTube CEO Susan Wojcicki just passed away, according to social media posts by her husband, Dennis Troper, and by Google…

Former YouTube CEO Susan Wojcicki has passed away at age 56

This is the second cyberattack targeting the school device management service Mobile Guardian this year.

Student raised security concerns in Mobile Guardian MDM weeks before cyberattack

Featured Article

Smartwatches shipments see sharp decline in India

India’s wearable market declined in Q2, primarily because smartwatch are not attracting consumers.

Smartwatches shipments see sharp decline in India

Anysphere, a two-year-old startup that’s developed an AI-powered coding assistant called Cursor, has raised over $60 million in a Series A financing at a $400 million post-money valuation, two sources…

Anysphere, a GitHub Copilot rival, has raised $60M Series A at  $400M valuation from a16z, Thrive, sources say

The internet is full of deepfakes — and most of them are nudes. According to a report from Home Security Heroes, deepfake porn makes up 98% of all deepfake videos…

How to ask Google to remove deepfake porn results from Google Search

Researchers found flaws that could allow anyone to spy on the owners of Ecovacs home robots by hijacking their cameras and microphones.

Ecovacs home robots can be hacked to spy on their owners, researchers say

When digging into the data to determine how large the exodus everyone on Threads is talking about actually is, we oddly came up short.

The X exodus that wasn’t

Substack is opening up to more users with its recent announcement that anyone can now publish content on its platform without setting up a publication. With the change, Substack is…

Substack now lets anyone publish posts, even if they don’t have a newsletter

WeRide, a Chinese autonomous vehicle company, is officially gearing up for a U.S. public debut, over a year after China started easing its effective ban of foreign IPOs.  WeRide registered…

China’s autonomous vehicle startup WeRide prepares for a US IPO

Welcome to Startups Weekly — your weekly recap of everything you can’t miss from the world of startups. Want it in your inbox every Friday? Sign up here. This week we…

AI founders play musical chairs

Featured Article

How a cybersecurity researcher befriended, then doxed, the leader of LockBit ransomware gang

Jon DiMaggio used sockpuppet accounts, then his own identity, to infiltrate LockBit and gain the trust of its alleged admin, Dmitry Khoroshev.

How a cybersecurity researcher befriended, then doxed, the leader of LockBit ransomware gang

The U.K. government has indicated it may seek stronger powers to regulate tech platforms following days of violent disorder across England and Northern Ireland fueled by the spread of online…

As unrest fueled by disinformation spreads, the UK may seek stronger power to regulate tech platforms

The Startup Battlefield is the crown jewel of Disrupt, and we can’t wait to see which of the thousands of applicants will be selected to pitch to panels of top-tier VCs…

First look at the Startup Battlefield judges at TechCrunch Disrupt 2024

The startup’s core technology is a proprietary material that absorbs moisture from the air, allowing air conditioning to cool buildings more efficiently.

Humidity sucks. Transaera has a new way to deal with it

YouTube’s latest test involves a sleep timer that pauses the video after, well, a set period of time.

YouTube is testing a sleep timer on its Premium tier

Ola Electric, India’s largest electric two-wheeler maker, surged by 20% on its public debut on Friday, making it the biggest listing among Indian firms in two years. Shares of the…

Ola Electric surges 20% in India’s biggest listing in two years

Rocket Lab surpassed $100 million in quarterly revenue for the first time, a 71% increase from the same quarter of last year. This is just one of several shiny accomplishments…

Rocket Lab’s sunny outlook bodes well for future constellation plans 

In 1996, two companies, Patersons HR and Payroll Solutions, formed a venture called CloudPay to provide payroll and payments services to enterprise clients. CloudPay grew quietly over the next several…

CloudPay, a payroll services provider, lands $120M in new funding

The vulnerabilities allowed one security researcher to peek inside the leak sites without having to log in.

Security bugs in ransomware leak sites helped save six companies from paying hefty ransoms

Featured Article

A comprehensive list of 2024 tech layoffs

The tech layoff wave is still going strong in 2024. Following significant workforce reductions in 2022 and 2023, this year has already seen 60,000 job cuts across 254 companies, according to independent layoffs tracker Layoffs.fyi. Companies like Tesla, Amazon, Google, TikTok, Snap and Microsoft have conducted sizable layoffs in the…

A comprehensive list of 2024 tech layoffs

A new “beta rabbit” mode adds some conversational AI chops to the Rabbit r1, particularly in more complex or multi-step instructions.

Rabbit’s r1 refines chats and timers, but its app-using ‘action model’ is still MIA

Los Angeles is notorious for its back-to-back traffic. Three events that promise to bring in millions of spectators from around the world — the 2026 World Cup, the Super Bowl…

Archer to set up air taxi network in LA by 2026 ahead of World Cup

Featured Article

Amazon is fumbling in India

Amazon’s decision to overlook quick-commerce in India is now looking like a significant misstep.

Amazon is fumbling in India

OpenAI’s GPT-4o, the generative AI model that powers the recently launched alpha of Advanced Voice Mode in ChatGPT, is the company’s first trained on voice as well as text and…

OpenAI finds that GPT-4o does some truly bizarre stuff sometimes

On Thursday, Box filled in a missing piece on its AI platform when it bought automated metadata extracting startup, Alphamoon.

Box adds crucial piece to its AI platform with Alphamoon acquisition

OpenAI has announced a new appointment to its board of directors: Zico Kolter. Kolter, a professor and director of the machine learning department at Carnegie Mellon, predominantly focuses his research…

OpenAI adds a Carnegie Mellon professor to its board of directors