Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Email Got Spoofed – And How DMARC Can Help?
Articles

Email Got Spoofed – And How DMARC Can Help?

ISBuzz TeamBy ISBuzz TeamSeptember 2, 2015Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
How DMARC Can Help
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Being at the forefront of fraud prevention, our level of awareness for fraud related schemes is definitively higher than it is for any other business. We live to fight back fraud 24 by 7, and being one of the pioneers in the industry to champion DMARC and knowing its benefits.

we decided to deploy the DMARC policy in monitoring mode, as you can see here :

unnamed1

P=none means no action is taken on emails that fail the authentication protocol, however, we have the visibility as to who is spoofing our domain and for what purpose.

Knowing that it was a matter of time until criminals attempted a move against our organization, we started our monitoring process. And it was last week when I received a call from the CFO, who was properly trained to identify suspicious emails, to validate if an email requesting a wire transfer was sent legitimately.

While you never want to be the attempted victim of fraud, part of me was happy this happened, because I’ve been thinking about this post for some time.

Below you see the screenshot with the spoofed email.

unnamed2

One note to make here is that most likely the recipient’s account was also compromised, so we immediately notified the financial institution so they can conduct their investigation.

A common technique, employed here is to follow-up with additional emails to increase the pressure:

unnamed3And then a bit more…

unnamed4Looking at the DMARC record, you can see that as a result of our published DMARC policy, these emails failed the email authentication protocol, and they would have been stopped if our policy was set to P=Reject.

unnamed5We were not hit by this scam because our team is well trained to know what to look for and we have deployed DMARC technology to help us identify and block spoofed messages. However, the consequences of an attack like this are infinite. Imagine this wire actually taking place, or a request for a new email account and privileged credentials being assigned to the wrong party, or confidential information being shared. Spear-phishing can come in many forms, but the formula is always the same.

These attacks exist because it is still possible to easily and cheaply forge emails from any address on the Internet as outlined by FS-ISAC/CERT. The alternative attack vector for these kinds of attacks is to directly compromise the sender’s email account via malware or some other method of compromise. This method, while possible it is harder and more expensive for the attacker. We believe that steps must always be taken to push costs to adversaries and never present them with an easy and cheap option.

What to Do?

  • Deploy DMARC to gain visibility into email attacks and spear-phishing both targeting your employees and your clients
  • Consider leveraging a DMARC visibility and compliance product such as DMARC Compass
  • Confirm with your enterprise email team that your email enterprise email provider honors DMARC policies on inbound email to prevent spear-phishing attacks.
  • Train your leadership, especially in finance about the risks associated with these kinds of attacks, methods of detection and manual authentication.

This is just another real-world example of the all-to-common attacks that are putting many enterprises at risk. We strongly encourage any enterprise that relies on trusted email-based communication with their clients to evaluate these recommendations to see if they work for you. Also, even if you have no plans currently to leverage DMARC to block spoofed email, it is very important to leverage the power of DMARC to gain visibility into real or potential attacks that might lead directly to successful attacks.

We are the living proof that it is a matter of time until criminals threaten your business. These attacks are inexpensive and easy to launch, as such, they will continue to happen until organizations improve their email authentication methods, making it harder for cybercriminals to carry on their fraudulent operations.[su_box title=”Ricardo Villadiego, CEO of Easy Solutions” style=”noise” box_color=”#336588″]Ricardo VilladiegoAfter more than a decade in the IT security sector, Ricardo Villadiego decided to take a risk and start a security company of his own. The result is Easy Solutions, a state-of-the-art and creative business that is a reflection of the man who runs it. Ricardo sought to build a company with a highly-motivated group of engineers free to unleash their imaginations and think up fresh and original solutions to confront the constantly evolving threat landscape of the internet. Flexible and agile, the Easy Solutions team can adapt, change course, and most importantly take care of any electronic security problem quickly. This hardworking team, affectionately dubbed the “Easy Solvers”, follow in their leader’s easygoing but results-oriented footsteps, working their tails off but always leaving some time to relax and bust some dance moves or play a quick game of soccer.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}