Exploiting trust for financial gain: an overview of business email compromise (BEC) fraud

Author:

Cross Cassandra,Gillett Rosalie

Abstract

Purpose This paper aims to explore current knowledge of business email compromise (BEC) fraud, or approaches that specifically target organisations for financial gain, through the exploitation of trusted relationships. BEC fraud affects organisations globally and is estimated to have netted offenders over US$26bn since 2016. Despite the sheer magnitude of these losses, there is a dearth of academic research seeking to better understand this crime type, and prevent it from occurring. Design/methodology/approach This review summarises the known literature on BEC fraud. It uses a variety of academic and industry sources to ascertain the current state of knowledge, including how it is perpetrated, its impact (on businesses and individuals), how law enforcement have responded and its prevention. Findings This review highlights many gaps in knowledge surrounding BEC fraud. There has been a large focus on the technical aspects of BEC fraud, to the detriment of the human elements. Often, BEC fraud is successful through targeted and effective use of social engineering techniques and is able to overcome any technical solutions through the manipulation of personal relationships. Further, while the financial impacts of BEC fraud are obvious, there is no known research which has explored the non-financial harms of BEC fraud (across organisational and individual perspectives). With companies starting to (unsuccessfully) take legal action against those who have responded, there is a clear need to understand how organisations can better respond to incidents when they occur. Finally, there are gaps in knowledge on what is the best combination of both technical and human measures to prevent BEC fraud. Research limitations/implications This review is based on information presently available, and as indicated, there are significant gaps in what is currently known. Practical implications This review highlights the need to undertake research into the current gaps, with a view to improving best practice knowledge on prevention and response. Social implications Currently unknown, BEC fraud is posited to have significant impacts at both personal and collective levels. Increased knowledge of these non-financial impacts will improve how organisations respond to BEC fraud and how employees can be supported before and after an incident occurs. Originality/value Despite the magnitude of the problem, there is limited academic scholarship on BEC fraud. This literature review offers a summary of current knowledge and advocates a strong research agenda moving forward.

Publisher

Emerald

Subject

Law,General Economics, Econometrics and Finance

Reference59 articles.

1. Cyber security trends to watch out in 2019;Cyber Nomics,2019

2. Australian Competition Consumer Commission (ACCC) (2019), “Targeting scams: report of the ACCC on scams activity 2018”, available at: www.accc.gov.au/publications/targeting-scams-report-on-scam-activity/targeting-scams-report-of-the-accc-on-scam-activity-2018 (accessed 14 January 2020).

3. Australian Cyber Security Centre (2018), “Business email compromise”, available at: www.cyber.gov.au/threats/business-email-compromise (accessed 14 January 2020).

4. Bansal, G. (2018), “Got phished! role of top management support in creating phishing safe organizations”, Paper presented at the Proceedings of the Thirteenth Midwest Association for Information Systems Conference, May 17-18, Saint Louis, MO, available at: https://aisel.aisnet.org/mwais2018/6 (accessed 14 January 2020).

5. BBC News (2019a), “Company sues worker who fell for email scam”, available at: www.bbc.com/news/uk-scotland-glasgow-west-47135686 (accessed 14 January 2020).

Cited by 11 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3