Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Trump pulls Musk ally’s NASA Administrator nomination

    May 31, 2025

    This Staples Standing Desk Isn’t Flashy but It’s Reliable for the Money

    May 31, 2025

    The Nike x Hyperice Hyperboots Will Give You a Heated Foot Massage While You Walk

    May 31, 2025
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » How to Spot a Business Email Compromise Scam
    Security

    How to Spot a Business Email Compromise Scam

    News RoomBy News RoomJuly 19, 20243 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email

    So this is the first step: Take control of your emotions. Yes, it can be difficult if you work in a demanding field. But it’s your best first defense, and your employer will thank you for it (or, at least, they should).

    Always Confirm Through a Second Channel

    Now that you’re skeptically questioning the legitimacy of the urgent request, check to make sure the email is coming from the person it claims to be from. The best way to do this is to ask—just be careful.

    “If you received an email like this, it’s important to pick up the phone and call the number you know to be legitimate,” says Larson, adding a caveat. “Do not rely on a phone number in the email itself—it will be owned by the threat actor.”

    This is a crucial point: Any contact information in the email itself is likely compromised, and sometimes cleverly so. Use the phone number you’ve already saved in your phone for the person in question, or look up the phone number on an official website or in an official company directory. This applies even if the number in the email looks correct, because some scammers will go through the trouble of getting a phone number that’s similar to that of the person they’re impersonating, all on the hopes that you’ll call that number instead of the real one.

    “I’ve seen phone numbers off two digits from the actual phone number,” says Tokazowski.

    Call the person who supposedly emailed you—using a number you are 100 percent sure is real—and confirm the request is authentic. You could also use some other secure communication channel like Slack or Microsoft Teams, or, if they’re in the office, just ask them face to face. The point is to confirm any urgent request somewhere outside of the initial email. And even if the person is your boss or some other bigwig, do not worry about wasting their time.

    “The person that is being impersonated would so much rather have someone take the time to confirm than to lose thousands or a million dollars in a malicious transaction,” says Larson.

    Check the Email Address

    Getting in touch with the supposed sender isn’t always an option. If not, there are a few tricks you can use to spot whether an email is real or fake. The first: check the email address and make sure it’s from the company domain.

    “Always check the domains that you’re receiving emails from,” says Larson. Sometimes this will be obvious; your CEO likely isn’t emailing you from a Gmail account, for example. Sometimes it will be more subtle—fraudsters have been known to purchase domains that look similar to that of the company they’re attempting to defraud, all in the hopes of appearing legitimate.

    It’s also worth checking to see if the email signature matches the address the email is coming from. “If you look in the footer, they’ll use the actual domain of the company to make it look legitimate, but that won’t match the email address,” says Larson. Just keep in mind that the difference might be subtle. “Look-alike domains are very common: Someone will do a slight variation, like an ‘l’ instead of an ‘i’, to make it look legitimate.” One way to test that, if you’re suspicious, is to copy and paste the domain half of the address into a browser. If you don’t get a website, you’re probably dealing with a fake.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleGoogle’s shortened links will stop working next year
    Next Article The Bold Bose SoundLink Max Is Our New Favorite Outdoor Speaker

    Related Posts

    The Privacy-Friendly Tech to Replace Your US-Based Email, Browser, and Search

    May 30, 2025

    How to Win Followers and Scamfluence People

    May 30, 2025

    The US Is Building a One-Stop Shop for Buying Your Data

    May 29, 2025

    Feds Charge 16 Russians Allegedly Tied to Botnets Used in Ransomware, Cyberattacks, and Spying

    May 27, 2025

    Mysterious Database of 184 Million Records Exposes Vast Array of Login Credentials

    May 24, 2025

    3 Teens Almost Got Away With Murder. Then Police Found Their Google Searches

    May 22, 2025
    Our Picks

    This Staples Standing Desk Isn’t Flashy but It’s Reliable for the Money

    May 31, 2025

    The Nike x Hyperice Hyperboots Will Give You a Heated Foot Massage While You Walk

    May 31, 2025

    Apple’s Big OS Rebrand, OnePlus Embraces AI, and Samsung’s Next Folds—Your Gear News of the Week

    May 31, 2025

    Sony’s DualSense Edge controller is receiving a rare $30 discount

    May 31, 2025
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    News

    Slate Auto FAQ: your questions answered

    By News RoomMay 31, 2025

    Alright, we get it. Y’all are excited about Slate. We thought the little Slate Truck…

    A New Study Reveals the Makeup of Uranus’ Atmosphere

    May 31, 2025

    Never Drink Alone: A Guide to Turkish Coffee

    May 31, 2025

    Twitch is getting vertical livestreams

    May 31, 2025
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2025 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.