2.5 - Business Email Compromise/Supply Chain Attacks

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/12

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 8:43 PM on 8/2/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

13 Terms

1
New cards

Business Email Compromise (BEC)

A social engineering attack that exploits trusted email communication to trick employees into transferring money, sharing credentials, or updating financial info.

2
New cards

BEC Example — Wire Transfer

Attacker impersonates a title company or vendor and provides fake wire transfer instructions to redirect funds.

3
New cards

BEC Example — Gift Cards

Attacker impersonates a CEO and asks an employee to purchase gift cards for "employee awards," then requests the card numbers.

4
New cards

BEC Example — Payroll Redirect

Attacker impersonates an employee and emails payroll to update direct deposit banking information to the attacker's account.

5
New cards

Preventing BEC

Watch for email spoofing, verify all urgent financial requests via phone or video call, and train employees to recognize spearphishing.

6
New cards

Supply Chain Attack

An attack that targets a less-secure part of the supply chain (supplier, vendor, software update) to compromise a larger target downstream.

7
New cards

Service Provider Risk

Third-party providers (HVAC, payroll, cloud, cleaning) often have internal network access, making them a target for attackers trying to reach a larger organization.

8
New cards

Target Breach (2013)

Attackers compromised an HVAC vendor's VPN credentials via malware, then used that access to infect 1,800 Target stores' cash registers — stealing 40 million credit cards.

9
New cards

Hardware Supply Chain Risk

Counterfeit or tampered hardware (routers, switches, servers) can be introduced into the supply chain. Example: $1B in fake Cisco gear sold from 2013–2022.

10
New cards

Software Supply Chain Risk

Attackers can compromise software updates or open-source code to push malware to thousands of users — even through trusted, automatic update channels.

11
New cards

Verifying Software Integrity

Confirm digital signatures during installation and after updates to ensure software has not been tampered with in the supply chain.

12
New cards

SolarWinds Attack (2020)

Attackers compromised SolarWinds Orion software updates in 2020, affecting 18,000 customers including the Pentagon, Homeland Security, Microsoft, and Cisco. Undetected for ~9 months.

13
New cards