Tag

Email Spoofing

Covers email spoofing techniques where attackers forge sender addresses to impersonate trusted contacts. Learn how spoofed emails bypass basic filters, the role of SPF, DKIM, and DMARC in detection, and practical steps to protect your domain from spoofing abuse.

posts

Spoofing

Spoofing Attacks: How Hackers Impersonate Trust

In July 2020, a seventeen-year-old in Florida used phone-based spoofing and social engineering to compromise internal Twitter tools, hijacking the verified accounts of Barack Obama, Elon Musk, Jeff Bezos, and Apple. The attackers impersonated IT staff during phone calls to Twitter employees, spoofing caller IDs to appear legitimate. Within hours,

Carl B. Johnson Aug 25, 2021 8 min read
FakeEmail

FakeEmail Attacks: How Spoofed Messages Breach Networks

The FakeEmail That Cost One Company $75 Million In 2020, the FBI's Internet Crime Complaint Center reported that business email compromise — attacks built on fakeemail techniques — generated over $1.8 billion in losses in a single year. That made it the costliest category of cybercrime, beating ransomware by

Carl B. Johnson Aug 15, 2021 7 min read
Fake Mailer

Fake Mailer Attacks: How Threat Actors Spoof Emails

In March 2021, the FBI's Internet Crime Complaint Center reported that business email compromise — often launched using a fake mailer or spoofing tool — cost American organizations over $1.8 billion in 2020 alone. That made it the most financially damaging cybercrime category in the entire IC3 report, dwarfing

Carl B. Johnson Jul 01, 2021 7 min read
Spoofing

Spoofing Attacks: How Hackers Impersonate You Online

In 2023, a finance employee at the multinational firm Arup wired $25 million to threat actors after a deepfake video call that spoofed the company's CFO and several colleagues. Every face on the screen was fake. Every voice was synthesized. The employee had no reason to doubt what

Carl B. Johnson Feb 27, 2020 7 min read
Spoof

Spoof Attacks: How Threat Actors Hijack Trust

A Single Spoofed Email Cost This Company $46.7 Million In 2016, FACC Operations GmbH, an Austrian aerospace parts manufacturer, lost €42 million (roughly $46.7 million USD) after attackers sent a spoofed email impersonating the company's CEO. The finance department wired the money to accounts controlled by

Carl B. Johnson Feb 23, 2020 7 min read
FakeEmail

FakeEmail Attacks: How Spoofed Messages Breach Networks

In 2023, the FBI's Internet Crime Complaint Center reported that business email compromise — attacks built on fakeemail addresses and spoofed sender identities — accounted for over $2.9 billion in adjusted losses. That made it the single most financially devastating cybercrime category they tracked. Not ransomware. Not cryptojacking. Fake

Carl B. Johnson Feb 09, 2020 7 min read
Spoofing

Spoofing Attacks: How Hackers Impersonate You

A CFO, a Spoofed Email, and a $37 Million Wire Transfer In 2024, the FBI's Internet Crime Complaint Center (IC3) continued reporting staggering losses from business email compromise — a category where spoofing is the engine that makes the scam work. Threat actors forge sender addresses, manipulate caller IDs,

Carl B. Johnson Jun 18, 2019 8 min read
FakeEmail

FakeEmail Attacks: How Spoofed Messages Breach Networks

A Single FakeEmail Cost One Company $37 Million In 2024, Orion SA, a Luxembourg-based steel trading company, disclosed it lost approximately $60 million after an employee was tricked by a business email compromise scheme using fraudulent email communications. That same year, the FBI's IC3 received over 21,000

Carl B. Johnson Apr 05, 2019 7 min read
Fake Mailer

Fake Mailer Attacks: How Threat Actors Spoof Email

In March 2024, the FBI's Internet Crime Complaint Center reported that business email compromise — much of it powered by spoofed sender addresses — cost victims over $2.9 billion in a single year. Behind many of those attacks sits a deceptively simple weapon: a fake mailer. These tools let

Carl B. Johnson Mar 10, 2019 7 min read