Skip to content

At The Identity Organisation, we're here to help!

    Your privacy is important to us, and we want to communicate with you in a way which has your consent and which is in line with UK Law on data protection. As a result of a change in UK law on 25th May 2018, by providing us with your personal details you consent to us processing your data in line with current GDPR requirements.

    Here is where you can review our Privacy & GDPR Statement

    To remove consent at any time, please e-mail info@tidorg.com with the word "unsubscribe" as the subject.

    +44 (0) 1628 308038 info@tidorg.com

    Executive Impersonation Business Email Compromise Attacks Go Beyond English Worldwide

    Despite hearing mostly about BEC attacks in English-speaking countries, analysis of new attack groups highlight the threat of these kinds of attacks in other languages.

    English-speaking countries don’t have the monopoly on victim organizations that part with their money easily! According to new analysis of BEC attacks by cybersecurity vendor Abnormal Security, it only takes two threat groups – Midnight Hedgehog and Mandarian Capybara – to launch BEC attacks impersonating executives in 13 different languages!

    How do they do it? According to Abnormal Security, exactly the same way legitimate Marketing and Sales teams do: they use online services to identify prospects and contact information, then use online translation services to localize the BEC emails.

    Why be worried? Abnormal says it best:

    We’ve taught our users to look for spelling mistakes and grammatical errors to better identify when they may have received an attack. When these are not present, there are fewer alarm bells to alert native speakers that something isn’t right.

    In other words, if you’re going to train your users via Security Awareness Training to be vigilant when working with email, spelling and grammar are going to matter less, and the fact that an email is unexpected, unsolicited, unusual, etc. alone become the only red flag needed to at least warrant further scrutiny of the message’s sender, it’s links or attachments, etc. before interacting with it legitimately.


    The world’s largest library of security awareness training content is now just a click away!

    In your fight against phishing and social engineering you can now deploy the best-in-class simulated phishing platform combined with the world’s largest library of security awareness training content; including 1000+ interactive modules, videos, games, posters and newsletters.

    You can now get access to our new ModStore Preview Portal to see our full library of security awareness content; you can browse, search by title, category, language or content topics.

    The ModStore Preview includes:

    • Interactive training modules
    • Videos
    • Trivia Games
    • Posters and Artwork
    • Newsletters and more!

    PS: Don’t like to click on redirected buttons? Cut & Paste this link in your browser: https://info.knowbe4.com/one-on-one-demo-partners?partnerid=001a000001lWEoJAAW

    Sign Up to the TIO Intel Alerts!

    Back To Top