Football transfers involved huge amounts of money being shifted, often electronically, between clubs to bring in new players. If hackers were to place themselves into the communications between clubs, huge payments could easily be stolen.
This is exactly what happened recently when a scam was conducted against a Premier League football club in England. The hackers obtained access to the email account of the managing director of the club through a phishing campaign after directing the MD to a domain where Office credentials were gathered. Those details were then used to access the MD’s email account, and the scammers inserted themselves into and email conversation with another club looking to buy a player. Luckily, the scam was detected by the bank and a £1 million fraudulent payment was prevented.
This variety of scam starts with a phishing email but is referred to as a Business Email Compromise (BEC) scam. BEC scams are widespread and often successful. They range from straightforward scams to complicated multi-email communications between two parties, whether one party believes they are communicating with the real email account holder when they are actually communicating with the scammer. When the time comes to make payment, the scammer supplies their own account credentials. All too often, these scams are not detected until after payment is completed.
That is far from the only cyberattack on the sports sector in recent weeks and months. There have been numerous attempted cyberattacks which prompted to the UK’s National Cyber Security Center (NCSC) to release a warning advising the UK sports sector to be on high alert.
Before lockdown, a football club in the UK was hit with a ransomware attack that encrypted essential databases, including the computer systems that controlled the turnstiles, preventing them from working. A game nearly had to be called off due to the attack. The ransomware attack is suspected to have also begun with a phishing email.
The recent attacks are not restricted to football clubs. NCSC data show that 70% of sports institutions in the United Kingdom have suffered a cyberattack in the past year.
NCSC figures show around 30% of incidents lead to financial losses, with the average loss being £10,000, although one organization lost £4 million in a scam. 40% of the attacks involved the use of malware, which is often sent using spam email. 25% of attacks involved ransomware.
While malware and ransomware attacks are costly and disruptive, the main cause of losses is BEC attacks. Reports released by the FBI show these scams accounted for around 50% of all losses to cybercrime in 2019. $1.77 billion was lost to BEC attacks in 2019, with an average loss of $75,000 (£63,333). The true figure is likely to be even higher, as not all BEC attacks are reported. The FBI expects even greater losses this year.
While there are many different attack tactics, email remains the most common vector used in cyberattacks on companies. It is therefore vital to put in placea robust email security solution that can block malicious emails and stop them from being delivered to inboxes.
TitanHQ has created a powerful, advanced email security solution that can help businesses improve their email security measures and block phishing, spear phishing, BEC, malware, and ransomware attacks. SpamTitan incorporates many threat intelligence feeds, machine learning systems to identify phishing scams, dual anti-virus engines, and a sandbox to subject suspicious email attachments to in-depth analysis. SpamTitan also incorporates SPF and DMARC to identify and block email impersonation campaigns.
If you are worried about email security and want to improve your defenses against email dangers, call the TitanHQ team a call now to discover more about SpamTitan and other security solutions that can help you defend your company from cyberattacks.