Swedish retail giant IKEA has been subject to an email-based cyberattack, with the company saying that it is investigating the incident.
The attack was revealed by cybersecurity news site Beeping Computer, which gained access to an internal email from the company. The message warned that messages had been sent to staff designed to imitate real emails, appearing as replies to existing email chains.
In addition, other groups affiliated with IKEA, such as suppliers, have also been caught up in the attack.
“There is an ongoing cyber-attack that is targeting Inter IKEA mailboxes. Other IKEA organisations, suppliers, and business partners are compromised by the same attack and are further spreading malicious emails to persons in Inter IKEA,” the email read.
“This means that the attack can come via email from someone that you work with, from any external organisation, and as a reply to an already ongoing conversations. It is therefore difficult to detect, for which we ask you to be extra cautious.”
IKEA’s IT team has warned its employees to avoid opening suspicious emails, and to be on the lookout for download links with seven digits at the end.
However, the group claimed that no customer data has been affected so far.
According to press statements, IKEA said that it is taking actions to prevent damage and is investigating the attack. For example, employees can no longer release emails from their spam filters, in case they accidentally release a malicious message.
At present, the attack is being linked to a compromised Microsoft Exchange server. Because the scam emails are being sent from internal email servers, there is a higher level of trust in the messages.
Recommended
- Contributed | Diversity: The secret sauce for tech sector growth?
- Facial recognition firm facing £17m ICO data handling fine
- Scottish creatives invited to join new digital up-skilling programme
The Microsoft Exchange attack took place earlier this year, when cybercriminals discovered an unpatched flaw in the company’s code, and used a new strain of malware, DearCry, to target email servers running Exchange.
While Microsoft released a patch, it warned that organisations would need to install in before threat actors exploited the vulnerability.
The email chain hijacking attack has been linked to Squirrelwaffle, a recently detected form of loader malware.
It leverages vulnerabilities in servers running Microsoft Exchange to add spoof emails to existing chains, lowering the victim’s guard. They can even imitate emails from previous contacts, including colleagues, to further gain their target’s trust.
The malware is generally contained in malicious Microsoft Office documents and spread via email. Once a user opens the infected document, Squirrelwaffle then runs and downloads its payload, such as Qakbot or Cobalt Strike.





