Kurzfassung
CERT NZ reports BEC in 2024 cost NZ businesses NZ$13M+, predominantly law / accounting / property firms whose clients receive a 'change of trust account' email mid conveyance. Indicators: M365 mailbox compromised via consent phishing,...
Wie es funktioniert
CERT NZ reports BEC in 2024 cost NZ businesses NZ$13M+, predominantly law / accounting / property firms whose clients receive a 'change of trust account' email mid conveyance. Indicators: M365 mailbox compromised via consent phishing,...
Warnzeichen
- Dringender Druck, sofort zu klicken, zu zahlen oder Codes zu teilen.
- Link oder Absender passen nicht zur offiziellen Organisation.
- Anfrage nach Kartendaten, Passwoertern, OTPs, Wallet-Signaturen oder Ueberweisungen.
Was tun
- 1CERT NZ reports BEC in 2024 cost NZ businesses NZ$13M+, predominantly law / accounting / property firms whose clients receive a 'change of trust account' email mid conveyance.
- 2WHAT TO DO: enforce CERT NZ's Critical Controls 2024 (MFA, hardware tokens for legal/accounting), publish 'we never change bank details by email' on engagement letters, callback verification.
- 3IF VICTIM: notify bank (NZ Faster Payments allow same day recall window), file CERT NZ report, audit M365 audit log for sign ins from foreign IPs, notify Law Society / NZICA, comply with Privacy Act 2020 breach notification within 72h.
Quelle
CERT-NZ
Quelle geprueft vom Mythos Forensic Team
https://www.cert.govt.nz/individuals/common-threats/scams-and-fraud/business-email-compromise/FAQ
Ist BEC against NZ professional services — invoice substitution ein reales Betrugsmuster?
Ja. Behandeln Sie Nachricht, Anruf oder Zahlungsaufforderung als verdaechtig, bis ein offizieller Kanal sie bestaetigt.
Was sind die ersten Warnzeichen?
Dringender Druck, sofort zu klicken, zu zahlen oder Codes zu teilen.; Link oder Absender passen nicht zur offiziellen Organisation.; Anfrage nach Kartendaten, Passwoertern, OTPs, Wallet-Signaturen oder Ueberweisungen.
Was sollte ich zuerst tun?
CERT NZ reports BEC in 2024 cost NZ businesses NZ$13M+, predominantly law / accounting / property firms whose clients receive a 'change of trust account' email mid conveyance.; WHAT TO DO: enforce CERT NZ's Critical Controls 2024 (MFA, hardware tokens for legal/accounting), publish 'we never change bank details by email' on engagement letters, callback verification.; IF VICTIM: notify bank (NZ Faster Payments allow same day recall window), file CERT NZ report, audit M365 audit log for sign ins from foreign IPs, notify Law Society / NZICA, comply with Privacy Act 2020 breach notification within 72h.
Kann LegalAudit meinen Fall pruefen?
Ja. Starten Sie den kostenlosen Chat und fuegen Sie Nachricht, Link, Absender oder Zahlungsdaten ein.