Exploiting trust for financial gain: an overview of business email compromise (BEC) fraud

Exploiting trust for financial gain: an overview of business email compromise (BEC) fraud
复制标题

利用信任获取经济利益:商业电子邮件泄露 (BEC) 欺诈概述

DOI:
--
复制
发表时间:
2020
影响因子:
--
通讯作者:
Rosalie Gillett
Rosalie Gillett
中科院分区:
--
文献类型:
--
作者:
Cassandra Cross;Rosalie Gillett

文献摘要

被引文献

相似文献

目的 本文旨在探究商业电子邮件入侵(BEC)欺诈的现有知识,即通过利用信任关系专门以组织为目标谋取经济利益的手段。BEC欺诈在全球范围内影响着各类组织,据估计自2016年以来,犯罪分子已从中获利超过260亿美元。尽管这些损失数额巨大,但旨在更好地理解这种犯罪类型并防止其发生的学术研究却十分匮乏。 设计/方法/途径 本综述总结了有关BEC欺诈的已知文献。它利用多种学术和行业资料来确定当前的知识状况,包括其实施方式、(对企业和个人的)影响、执法部门的应对措施以及预防方法。 研究结果 本综述强调了围绕BEC欺诈的诸多知识空白。人们大量关注BEC欺诈的技术方面,却忽视了人的因素。通常,BEC欺诈通过有针对性且有效地运用社会工程技术而得逞,并能够通过操纵人际关系突破任何技术解决方案。此外,虽然BEC欺诈的财务影响显而易见,但尚无已知研究探讨BEC欺诈(从组织和个人角度)的非财务危害。随着企业开始(未成功地)对相关责任人采取法律行动,显然有必要了解组织在事件发生时如何更好地应对。最后,对于预防BEC欺诈的技术和人为措施的最佳组合,还存在知识空白。 研究局限性/影响 本综述基于目前可获取的信息,如前所述,当前已知信息存在重大空白。 实践意义 本综述强调有必要针对当前的空白进行研究,以期提高预防和应对的最佳实践知识。 社会影响 目前尚不清楚,但可以假定BEC欺诈在个人和集体层面都有重大影响。对这些非财务影响的更多了解将改善组织应对BEC欺诈的方式,以及在事件发生前后如何为员工提供支持。 原创性/价值 尽管问题严重,但关于BEC欺诈的学术研究有限。这篇文献综述总结了当前的知识,并提出了一个强有力的未来研究议程。
Purpose This paper aims to explore current knowledge of business email compromise (BEC) fraud, or approaches that specifically target organisations for financial gain, through the exploitation of trusted relationships. BEC fraud affects organisations globally and is estimated to have netted offenders over US$26bn since 2016. Despite the sheer magnitude of these losses, there is a dearth of academic research seeking to better understand this crime type, and prevent it from occurring. Design/methodology/approach This review summarises the known literature on BEC fraud. It uses a variety of academic and industry sources to ascertain the current state of knowledge, including how it is perpetrated, its impact (on businesses and individuals), how law enforcement have responded and its prevention. Findings This review highlights many gaps in knowledge surrounding BEC fraud. There has been a large focus on the technical aspects of BEC fraud, to the detriment of the human elements. Often, BEC fraud is successful through targeted and effective use of social engineering techniques and is able to overcome any technical solutions through the manipulation of personal relationships. Further, while the financial impacts of BEC fraud are obvious, there is no known research which has explored the non-financial harms of BEC fraud (across organisational and individual perspectives). With companies starting to (unsuccessfully) take legal action against those who have responded, there is a clear need to understand how organisations can better respond to incidents when they occur. Finally, there are gaps in knowledge on what is the best combination of both technical and human measures to prevent BEC fraud. Research limitations/implications This review is based on information presently available, and as indicated, there are significant gaps in what is currently known. Practical implications This review highlights the need to undertake research into the current gaps, with a view to improving best practice knowledge on prevention and response. Social implications Currently unknown, BEC fraud is posited to have significant impacts at both personal and collective levels. Increased knowledge of these non-financial impacts will improve how organisations respond to BEC fraud and how employees can be supported before and after an incident occurs. Originality/value Despite the magnitude of the problem, there is limited academic scholarship on BEC fraud. This literature review offers a summary of current knowledge and advocates a strong research agenda moving forward.