Anzeige
Mehr »
Freitag, 04.07.2025 - Börsentäglich über 12.000 News

Indizes

Kurs

%
News
24 h / 7 T
Aufrufe
7 Tage

Aktien

Kurs

%
News
24 h / 7 T
Aufrufe
7 Tage

Xetra-Orderbuch

Fonds

Kurs

%

Devisen

Kurs

%

Rohstoffe

Kurs

%

Themen

Kurs

%

Erweiterte Suche
PR Newswire
146 Leser
Artikel bewerten:
(0)

Newly identified cybergang uses vendor email compromise to spy on communications and steal millions out of the global supply chain, according to Agari

Silent Starling is the latest cybergang uncovered by email security firm, Agari

- 500+ companies in 14 countries affected (97% of vendor victims in the US, Canada, and the UK)

- 700+ employee email accounts compromised with OneDrive and DocuSign credential phishing campaigns

- 20,000+ emails stolen since late-2018

- 39 employees compromised at a single US-based company

FOSTER CITY, California and LONDON, Oct. 2, 2019 /PRNewswire/ -- Agari, the next-generation Secure Email Cloud that restores trust to the inbox, released today its quarterly Threat Actor Dossier researched and developed by the Agari Cyber Intelligence Division (ACID). The Dossier delves into the shadowy world of a West African cybercriminal organisation ACID has dubbed Silent Starling.

Cybergang Silent Starling targets victims in the U.S., Canada and the U.K.

"We specifically created ACID to track down bad actors propagating harm to consumers and businesses," said Patrick R. Peterson, CEO, Agari. "We learn cybercriminal organisations' new tactics through the ACID active engagements and then work with law enforcement to take them down, while at the same time providing intelligence, like money mule accounts and phishing websites, to our customers."

Silent Starling's preferred type of attack is a rapidly emerging form of business email compromise, one Agari has coined vendor email compromise (VEC). This type of attack is unique in that it targets the global supply chain, using incredibly realistic-looking emails to trick a supplier's customers into paying fake invoices. Due to its covert nature, VEC is very difficult for legacy systems to detect.

To start their attack, Silent Starling associates hijack the email accounts of employees typically in a vendor's finance department, like accounts receivable or procurement. They then patiently wait and spy on all communications coming into these compromised mailboxes, gathering intelligence, data and critical context. This information enables Silent Starling associates to then craft and send perfectly timed emails asking for an invoice to be paid, using the identity of the employee they have been spying on.

This type of attack is particularly hard to spot, as it mimics the look and feel of legitimate communication. The only difference is that the invoice sent to a vendor's customer contains details for the scammer's bank account instead of the vendor.

Legacy technology cannot pick up on socially engineered attacks backed by contextual information, making VEC the biggest threat coming around the corner.

"Our visibility into Silent Starling's operations has given us a direct and in-depth look at how the entire VEC attack chain unfolds," said Crane Hassold, senior director of threat research at Agari and head of ACID. "VEC is the next evolution of BEC. These attacks will continue to increase in frequency over the next 12 to 18 months because the financial return for scammers is so significant."

Cumulative losses associated with this scam are difficult to calculate, as companies don't reveal the information publicly unless included in an indictment. The US Financial Crimes Enforcement Network (FinCEN) recently reported that average VEC scam costs a victim company more than US$125,000, compared to US$50,000 in a classical CEO impersonation BEC attack.

Given the scale and severity of VEC, AI and machine learning technology is the only mechanism that stands a chance of mitigating attacks from Silent Starling and cybergangs like it.

Peterson concluded: "ACID is a tangible and outward sign of the fulfilment of Agari's mission, which is to protect digital communications to ensure humanity prevails over evil."

Register now for the Silent Starling webinar, hosted by Crane Hassold.

About Agari
Agari is transforming the legacy Secure Email Gateway with its next-generation Secure Email Cloud powered by predictive AI. Leveraging data science and real-time intelligence from trillions of emails, the Agari Identity Graph detects, defends and deters costly advanced email attacks including business email compromise, spear phishing and account takeover. Winner of the 2018 Best Email Security Solution by SC Magazine, Agari restores trust to the inbox for government agencies, businesses and consumers worldwide. Learn more at www.agari.com.

Media Contact
Jean Creech Avent
Sr. Director, Global Corporate Communications
Agari
+1 843-986-8229
jcreech@agari.com

Photo - https://mma.prnewswire.com/media/1004805/SilentStarlingMap.jpg

© 2019 PR Newswire
Zeitenwende! 3 Uranaktien vor der Neubewertung
Ende Mai leitete US-Präsident Donald Trump mit der Unterzeichnung mehrerer Dekrete eine weitreichende Wende in der amerikanischen Energiepolitik ein. Im Fokus: der beschleunigte Ausbau der Kernenergie.

Mit einem umfassenden Maßnahmenpaket sollen Genehmigungsprozesse reformiert, kleinere Reaktoren gefördert und der Anteil von Atomstrom in den USA massiv gesteigert werden. Auslöser ist der explodierende Energiebedarf durch KI-Rechenzentren, der eine stabile, CO₂-arme Grundlastversorgung zwingend notwendig macht.

In unserem kostenlosen Spezialreport erfahren Sie, welche 3 Unternehmen jetzt im Zentrum dieser energiepolitischen Neuausrichtung stehen, und wer vom kommenden Boom der Nuklearindustrie besonders profitieren könnte.

Holen Sie sich den neuesten Report! Verpassen Sie nicht, welche Aktien besonders von der Energiewende in den USA profitieren dürften, und laden Sie sich das Gratis-PDF jetzt kostenlos herunter.

Dieses exklusive Angebot gilt aber nur für kurze Zeit! Daher jetzt downloaden!
Werbehinweise: Die Billigung des Basisprospekts durch die BaFin ist nicht als ihre Befürwortung der angebotenen Wertpapiere zu verstehen. Wir empfehlen Interessenten und potenziellen Anlegern den Basisprospekt und die Endgültigen Bedingungen zu lesen, bevor sie eine Anlageentscheidung treffen, um sich möglichst umfassend zu informieren, insbesondere über die potenziellen Risiken und Chancen des Wertpapiers. Sie sind im Begriff, ein Produkt zu erwerben, das nicht einfach ist und schwer zu verstehen sein kann.