Approximately 96% of phishing attempts are done through email, so it is important for companies and business owners to prioritize email security. One common type of phishing is Email Spoofing.
 
Imagine you receive an email from your boss making you aware that you are receiving a bonus for all your hard work. Your boss asks you to provide your bank account information, so they can put money directly into your account. This would be a prime example of Email Spoofing.
 
 
 
Email Spoofing can also occur within businesses, especially when working with clients or vendors. A good example of this is when a vendor emails a business and requests funds to be sent to a new account. Whether you’re a business owner or a client, it’s important to understand how fraudsters attack your inbox and what you need to look out for.
 

Defining Email Spoofing

Simply put, email spoofing is a technique used to trick users into thinking a message came from a trusted entity or person. 

 
The trickster can use different techniques to replicate email headers, company logos, or email addresses to build more of a level of trust.
 
Malicious data, attachments, or links are added for a user to click on or engage with, so the fraudster can steal confidential data or information connected to a person’s identity or financials, including bank accounts or passwords.
 

How It All Started

This technique first became evident in the 1970’s and became more common in 1990’s with the popularity of more advanced email and digital messaging. Security processes continued to reinforce protective measures against email spoofing, but it wasn’t until 2014 that security professionals worked to fight against spoofing and spam attempts. With the help of spam boxes, email software can better identify and reject spoofing attempts ahead of time.

 

Identify Fraudulent Attempts

While spam boxes are helpful when identifying potential fraudulent attempts, spoofing emails can still enter inboxes and it’s important to know fraudsters’ common tactics. Some methods include:

  1. Suspicious Links or Attachments
  2. A Sense of Urgency or a Need to Complete a Task Immediately
  3. Generic Greetings, such as “Hello Customer” or “Greetings Client”
  4. Questionable Email Headers or Addresses
  5. Inconsistencies with Email Signatures

 

How to Protect Yourself Against Email Spoofing

Acting against email spoofing can be done proactively if you know what to do. Here are some simple ways to help protect yourself against fraudulent email attempts.

  1. Keep your systems and software up to date.
  2. Monitor your emails regularly.
  3. Avoid clicking on any unknown links or attachments.
  4. Don’t provide any personal information.
  5. Look for inaccuracies in the email signature or email header.
  6. Verbally verify any changes to financial information before making any updates with a verified phone number in your system, not a phone number from the spoofed email.

 

How We Can Help

Protecting yourself from email spoofing attempts requires support, and Bank of Central Florida’s Relationship Management team is here to help. If you believe you’ve been a victim of email spoofing, contact the team for assistance.

In addition, some immediate steps you can take:

  • Turn off your device’s Wi-Fi: If you downloaded an attachment or clicked on a specific link, turning off your device’s Wi-Fi may help stop the malware from spreading.
  • Secure your email account: Update your password and enact multi-factor verification, so an extra layer of protection is in place.
  • Report the spoofed email: File a complaint or report to the FBI Internet Complaint Center to analyze and stop the fraudulent threat.

 

For more information on business fraud protection, visit our Phishing resources page on our website.



Member FDIC 

 

Sources used: 

https://www.sentinelone.com/cybersecurity-101/threat-intelligence/email-spoofing/#real-world-examples-of-email-spoofing

https://www.proofpoint.com/us/threat-reference/email-spoofing