Email scammers are recruiting fluent English speakers in an attempt to provide credibility to their BEC scam emails.
These scams target large firms, usually beginning with a phishing email campaign, designed and customised based on the target.
BEC scams require little technical knowledge to carry out, however, they are easily noticed when filled with bad spelling and grammar.
According to a research by Intel 471, hackers have begun seeking out English speakers to bring together teams able to manage both the technical aspects and social engineering elements of these scams.
Wanted adverts have appeared on a popular Russian-speaking cybercriminal forum over the course of 2021 asking for native English speakers to manage all elements of BEC scam communications and to help avoid suspicion from firms.
In an increasingly digital age, threat actors are now having to communicate effectively in order to succeed. Scammers can be easily caught out if not not fluent in the language a target speaks, causing their attacks to fail.
Commenting on the the potential risk to users, Javvad Malik, security awareness advocate at KnowBe4, said: “Criminals are always looking for ways to improve their chances of being successful.
“Recruiting native English-speakers could very well help rid them of one of the most telling red flags in a phishing email which is poor spelling and grammar.
“However, poor spelling and grammar is by no means the only red flag in phishing emails, and well-trained users can spot the other signs of a phishing email, particularly BEC scams. Some of these include the subject line, any links or attachments, who the email is from, to, the date and time it was sent and of course the content.
“In particular, people should be aware of what the ask is, and whether action is requested on their part in order to avoid a negative consequence or to gain something of value.
“When in doubt, users should report suspicious emails to their IT team or try to validate by contacting the alleged sender by other means.”
Recommended
- UK chip maker ARM’s China boss ‘declares independence’
- The Open University granted £1 million to help Scottish SMEs upskill
- Hacker sells fake Banksy NFT through artist’s website
According to the Intel471 researchers, North American and European markets have become prime targets of BEC scams, so ensuring the emails are effective is essential.
“The BEC footprint on underground forums is not as large as other types of cybercrime, likely since many of the operational elements of BEC use targeted social engineering tactics and fraudulent domains, which do not typically require technical services or products that the underground offers,” Intel 471 says.
“Criminals will use the underground for all types of schemes, as long as those forums remain a hotbed of skills that can make criminals money.”





