Cyber Security: Playing the Blame Game
I was talking with a colleague the other day about security breaches and in particular business email compromises. Just to set the scene, a business email compromise is where a criminal (or threat actor as they're called in the infosec world) gets in the middle of a chain of email communications to divert funds. There are several ways this can happen and I'll cover those as we go, but in this instance a user had received an email notifying them of a change of bank details so they could pay an outstanding invoice. The email came from a known contact and followed an existing thread.