- Run searches to steal personally identifiable information.
- Steal bank information to send e-mails requesting fraudulent wire transfers.
- Search the inbox to determine what HR and benefits self-service portal the employer uses, and then request a password reset for the user in that system. Once in the self-service portal, the attacker redirects the employee’s paycheck to one of their accounts.
- Send spam e-mails to all of the user’s contacts in an attempt to get others to give up their credentials as well.
- Change passwords regularly
- Have dual-factor authentication
- Remove auto-forwarding or auto-delete rules
- Teach your employees how to detect bogus-looking e-mails. If unsure, one of the best ways is to look at the sender’s full e-mail address and see if it comports with the e-mail address of a known entity, like a bank.
- Require two-factor authentication for access to Office 365.
- Use the Secure Score tool. This Microsoft tool can be used by anyone who has administrative privileges for an Office 365 subscription. It assists not just in analyzing, but also with implementing best practices regarding their Office 365 security.
- Enforce strong password policies. Educate employees about the risks of recycling passwords for different applications.
- Alert employees who have access to accounts-payable systems or wire transfer payments about these types of scams.
- Train all employees to beware of phishing attempts.
- If you use cloud-based platforms, investigate what logging is available and make sure it is enabled. For instance, if you’ve migrated from on-premises Exchange to Office 365, audit your security settings, which are reset to default settings during migration. In Office 365, you must turn on audit logging in the Security & Compliance Center.
- Work with your cloud provider’s technical team to determine what activities are logged and ensure you have the visibility you need, for the monitoring period you need.
Related Posts
Basics of a Strong Lockout/Tagout Program

READ MORE →
As Wildfire Risks Increase, Insuring Businesses More Difficult

READ MORE →
CALIFORNIA: Bureau Recommends Workers’ Comp Rates Drop 5.4%

READ MORE →
A Lesson in Timely Claims Reporting

READ MORE →
Discipline Should Be Part of Your Safety Program

READ MORE →
Leave a Reply