1/12
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Business Email Compromise (BEC)
A social engineering attack that exploits trusted email communication to trick employees into transferring money, sharing credentials, or updating financial info.
BEC Example — Wire Transfer
Attacker impersonates a title company or vendor and provides fake wire transfer instructions to redirect funds.
BEC Example — Gift Cards
Attacker impersonates a CEO and asks an employee to purchase gift cards for "employee awards," then requests the card numbers.
BEC Example — Payroll Redirect
Attacker impersonates an employee and emails payroll to update direct deposit banking information to the attacker's account.
Preventing BEC
Watch for email spoofing, verify all urgent financial requests via phone or video call, and train employees to recognize spearphishing.
Supply Chain Attack
An attack that targets a less-secure part of the supply chain (supplier, vendor, software update) to compromise a larger target downstream.
Service Provider Risk
Third-party providers (HVAC, payroll, cloud, cleaning) often have internal network access, making them a target for attackers trying to reach a larger organization.
Target Breach (2013)
Attackers compromised an HVAC vendor's VPN credentials via malware, then used that access to infect 1,800 Target stores' cash registers — stealing 40 million credit cards.
Hardware Supply Chain Risk
Counterfeit or tampered hardware (routers, switches, servers) can be introduced into the supply chain. Example: $1B in fake Cisco gear sold from 2013–2022.
Software Supply Chain Risk
Attackers can compromise software updates or open-source code to push malware to thousands of users — even through trusted, automatic update channels.
Verifying Software Integrity
Confirm digital signatures during installation and after updates to ensure software has not been tampered with in the supply chain.
SolarWinds Attack (2020)
Attackers compromised SolarWinds Orion software updates in 2020, affecting 18,000 customers including the Pentagon, Homeland Security, Microsoft, and Cisco. Undetected for ~9 months.