FBI: SMBs Losing Millions To Cybercrooks

Cybercrooks may have tried to nab as much as $100 million from small and midsized U.S. businesses in payroll scams over he last year. Now the FBI is talking about how to protect yourself from this automated threat.

Keith Ferrell, Contributor

November 4, 2009

2 Min Read
Dark Reading logo in a gray background | Dark Reading

Cybercrooks may have tried to nab as much as $100 million from small and midsized U.S. businesses in payroll scams over he last year. Now the FBI is talking about how to protect yourself from this automated threat.The automated clearinghouse (ACV) con as described by the FBI hits small and midsized businesses, as well as school, local governments and other organizations where they live -- in their bank accounts, and particularly their payroll accounts.

Noting "a significant increase" in ACH fraud targeting small and midsized bsuinesses recently, the FBI says the ripoff typically begins with a spear phishing expedition that delivers malware via either e-mail or a link to the business's computers.

Once the malware takes up residence, a keylogger harvests the company's financial information.

Armed with legitimate banking credentials, the crooks establish new payroll accounts, the recipients being themselves of course, and authorize transfers of thousands of dollars, often using work-at-home processing services (who think they're working for legitimate businesses) to bank the booty, then wire it to the overseas criminals.

ACH is growing as a cybercrime target for the same reason it's growing as a business subject: convenience.

Because the payroll withdrawals are kept under $10,000, they don't set off currency transaction alarms that would, at the least, slow down the automated process.

Using work-at-home transaction processors (money mules) keeps the process, and the cash, flowing.

Working with the National Cyber-Forensics and Training Alliance (NCFTA), the Bureau is issuing strong warnings about the scam, which we can expect to continue picking up steam.

An in-depth picture of how the con works is offered by the FBI here.

If your business has experienced an unauthorized transfer of funds, you can report it here.

About the Author

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights