Researchers Study Fake Employee Scams Using Fake Company

Researchers built a fake company to lure victims into a phishing attack targeting employees of real companies like IBM and Microsoft.

Bottom line: Attackers used tactics like phishing, spoofing, and social engineering to trick employees into divulging sensitive information.

What's happening: Researchers built a fake company, "Epic Systems Inc.," to study fake employee scams, including a phishing attack that targeted employees of real companies like IBM (CVE-2021-20000) and Microsoft (CVE-2021-20001). Attackers used business email compromise (BEC) to trick employees into divulging sensitive information.

What to do: Security leaders should educate employees on how to identify and report phishing attacks, and implement measures to prevent business email compromise attacks

Source: Schneier on Security