惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
有赞技术团队
有赞技术团队
Apple Machine Learning Research
Apple Machine Learning Research
V
V2EX
Engineering at Meta
Engineering at Meta
美团技术团队
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 司徒正美
I
InfoQ
S
SegmentFault 最新的问题
博客园 - 叶小钗
N
Netflix TechBlog - Medium
Y
Y Combinator Blog
IT之家
IT之家
博客园 - Franky
大猫的无限游戏
大猫的无限游戏
人人都是产品经理
人人都是产品经理
T
The Blog of Author Tim Ferriss
月光博客
月光博客
The Cloudflare Blog
U
Unit 42
GbyAI
GbyAI
L
LangChain Blog
Microsoft Azure Blog
Microsoft Azure Blog

Security

Scope Systems confirms cyber incident, says no data loss occurred Instructure breach: ShinyHunters says ‘matter has been resolved’ Rapid7 launches Cyber GRC program to connect compliance with live risk data Australian federal budget 2026: The industry perspective Op-Ed: Microsoft May Patch Tuesday reveals 137 vulnerabilities Federal Budget 2026: The state of cyber security spending for the coming year OpenAI offers EU early access to its cyber security model Exclusive: Aussie firm Earth Systems listed by INC Ransom hacking group Op-Ed: Why Middle East tensions demand immediate action on OT security Aussie schools breach: Instructure boss “reaches agreement” with ShinyHunters to not release data Institute of Public Accountants members hit by data breach Union demands answers on Qantas AI plans 1 in 3 small businesses don't think they're a cyber target, new research finds Exclusive: Aussie toy distributor listed by M3rx ransomware Exclusive: Australian Computer Society investigating possible breach after ShinyHunters hack claims The industry speaks – part 2: World Password Day 2026 Aussie schools breach: The Instructure hack “transcends an isolated IT incident” Exclusive: Aussie car part importer Strategic Imports allegedly breached by threat actors New South Wales, other states, investigating Instructure/Canvas data breach Australian Cyber Security Centre warns of ClickFix campaign leveraging Australian infrastructure Queensland Department of Education confirms students & staff impacted by ShinyHunters data breach ACMA takes action against SpinTel & Yomojo over mobile number fraud violations The Industry Speaks, Part 1: World Password Day 2026 Qualys and Converge tie cyber insurance pricing to real-time security posture Fakeout: Iranian APT caught hiding behind Chaos ransomware activity Exclusive: Australian energy management firm allegedly breached by SafePay Real estate giant Cushman & Wakefield confirms cyber incident, Qilin and ShinyHunters claim attack CrowdStrike expands Project QuiltWorks as more partners join AI security coalition Hacked: ALS discloses cyber incident, unauthorised access to IT systems Microsoft the main target of AI phishing attacks, report uncovers
Report: Business email compromise attacks surged dangerou...
david.hollin · 2026-05-14 · via Security

BEC attacks rose 151 per cent month on month in April, with advanced fee and gift card fraud key drivers.

Report: Business email compromise attacks surged dangerously in April

In terms of making headlines, ransomware attacks and cyber extortion tend to make the biggest waves, but arguably the most common form of financially motivated cyber crime is business email compromise (BEC).

Cyber insurance firm Coalition recently held a security forum in Sydney, where Eden Winokur, head of the cyber team at law firm Hall & Wilcox, said that fully 40 per cent of all cyber security incidents his firm has dealt with over the last two years involved BEC, whereas only 22 per cent involved ransomware.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

And according to new research from cyber security vendor Fortra, BEC attacks surged in April.

Fortra’s BEC Global Insights Report for the month revealed a worrying 151 per cent rise in BEC attacks month on month, with the most common method being advance-fee fraud, which accounted for 26.8 per cent of all cash-out methods.

The amount of money BEC attackers sought also rose in April, rising to US$60,723 compared to US$47,652 in March.

Poison Apple

Gift cards are a common vector exploited by BEC scammers, and in April, Apple Store gift cards were the card of choice. Of all gift card requests, 54.9 per cent were for Apple Store cards, with Amazon following at 26.4 per cent and Sephora at 7.7 per cent.

In this form of scam, an email may come from a superior asking an assistant to purchase several gift cards, commonly dozens at a time, to be sent out to clients or employees, possibly as a loyalty reward. The superior asks for the cards’ serial numbers right away, and then the value is cashed out by the scammer or used to purchase goods.

Cryptocurrency was also popular in April, with Fortra tracking 45 crypto-related scams linked to 32 unique bitcoin wallets. The amounts requested ranged from US$800 to an impressive US$2,766,345.32.

Wire transfer attacks in April rose as well, increasing by 262 per cent compared to March. The average amount requested also rose, from US$47,652 in March to US$60,723.

“Analysis of requested amounts showed that 14 per cent of wire transfer requests were under US$10,000, while 73 per cent fell between US$10,000 and US$50,000,” JT Newby, Fortra’s principal threat research lead, said in an 11 May blog post.

“Requests between US$50,000 and US$100,000 accounted for 8 per cent, and 5 per cent exceeded $100,000.”

Perhaps unsurprisingly, the African nation of Nigeria was the source of most BEC attacks. Thirty-six per cent of all BEC attempts originated in Nigeria; however, the United States ranked not far behind, accounting for 34 per cent of BEC attacks.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.

Tags: