Tag: email security

  • Business email compromise warning signs for SMEs

    Business email compromise warning signs for SMEs

    Introduction

    Business email compromise (BEC) is a growing threat to South African small and medium-sized businesses. Unlike noisy ransomware or mass phishing campaigns, BEC is often targeted, quiet and financially damaging. For SMEs in Johannesburg, Pretoria and across Gauteng, recognising early warning signs is essential to prevent costly mistakes and downtime. This guide explains common indicators of BEC, practical prevention measures suitable for local businesses, and steps to take if you suspect compromise.

    What is business email compromise?

    Business email compromise is a type of cybercrime where attackers gain access to legitimate business email accounts or convincingly spoof them to defraud a company. Their typical goals include wire transfer fraud, invoice diversion, payroll manipulation or harvesting credentials for further access. Because BEC attacks frequently impersonate trusted colleagues, suppliers or executives, they can bypass basic defences.

    Common warning signs of BEC

    Timely detection often depends on staff vigilance. Teach your team to look for subtle anomalies rather than obvious malware alerts.

    Unusual payment requests or urgent financial demands

    • Requests to change banking details for recurring suppliers.
    • Emails demanding immediate payment or asking to bypass normal approval processes.
    • Last-minute “urgent” invoices with pressure to transfer funds.

    Sender anomalies and spoofing indicators

    • From addresses that look similar but contain slight misspellings (for example, finance@acme-co[.]za vs finance@acmeco[.]za).
    • Display names that match senior staff while the actual email domain differs.
    • Unexpected forwarding rules or auto-replies set by the sender.

    Requests for sensitive information

    Emails asking for employee tax numbers, ID details, banking credentials or password resets are red flags. BEC actors often harvest personal data to bypass two-factor authentication or social-engineer further access.

    Strange language, tone or writing style

    • Messages that deviate from the sender’s usual tone or contain awkward phrasing.
    • Generic greetings instead of personalised salutations.
    • Uncharacteristic urgency, threats, or over-politeness intended to manipulate.

    Irregular email behaviour and technical signs

    • Large volumes of outbound email from a user who normally sends few messages.
    • Unexpected login notifications, especially from foreign IP addresses or unusual locations.
    • New mail rules created to delete or divert responses.

    Why South African SMEs are attractive targets

    SMEs often have limited IT resources and mature processes, making them appealing to attackers. Additionally, local business practices—such as relying on email for payment instructions and informal approval chains—can be exploited. For companies operating in Gauteng, where many suppliers and clients are interconnected, fraud can spread quickly through networks of trust.

    Practical prevention steps for SMEs

    Protection doesn’t need to be complicated or expensive. Focus on layered controls, staff training and clear financial procedures.

    Technical controls

    • Enable multi-factor authentication (MFA) for all accounts, including administrators.
    • Use modern email filtering and anti-spoofing technologies: SPF, DKIM and DMARC.
    • Monitor login activity and implement conditional access where possible.
    • Keep systems patched and maintain device endpoint protection.

    Policy and process

    • Require dual authorisation for payments above defined thresholds—set thresholds in rand appropriate to your business size.
    • Verify bank account changes through a secondary channel such as a phone call to a known number.
    • Limit public exposure of staff email addresses and organisational charts on the website.

    Staff training and culture

    Regular, practical training helps staff recognise suspicious messages. Simulated tests are useful, but pair them with coaching and clear reporting paths so employees feel safe raising concerns without blame.

    How to respond if you suspect a compromise

    Act quickly to contain damage and gather evidence. A calm, methodical response improves chances of recovery.

    Immediate containment steps

    • Isolate affected accounts: force password resets and revoke active sessions.
    • Disable any suspicious mail forwarding rules and review send-as permissions.
    • Notify your bank immediately if payments were redirected and request a recall if possible.

    Investigate and document

    • Collect headers and logs to determine origin and timeline of the incident.
    • Identify any data exfiltration, credential theft or additional compromised accounts.
    • Preserve evidence for potential police or banking investigations.

    Report and recover

    • Report fraudulent transactions to your bank and file a case with the South African Police Service if funds were lost.
    • Notify affected clients or suppliers where appropriate, with factual guidance on next steps.
    • Review and update controls to prevent recurrence, including changes to policies and technical settings.

    Case scenario: invoice diversion in a small Gauteng supplier

    A Pretoria-based supplier received what appeared to be an email from a long-term customer requesting payment to a new account. The accounts clerk did not verify via phone and the supplier paid R120,000. The transaction was later flagged as fraudulent. Recovery depended on rapid bank engagement and a police case. The business then implemented mandatory two-person authorisation for all payments above R10,000 and enabled MFA for finance accounts.

    Key takeaways

    • BEC relies on trust and subtlety—train staff to question unusual requests.
    • Technical controls like MFA and SPF/DKIM/DMARC reduce risk significantly.
    • Clear financial procedures, verification steps and rapid incident response limit damage.

    FAQ

    1. Q: What immediate sign should trigger an investigation?

      A: Any unexpected request to change banking details or an urgent payment request that bypasses normal approvals should be investigated immediately.

    2. Q: Can email filtering stop all BEC attacks?

      A: No. Filtering helps but BEC often uses legitimate accounts or carefully crafted spoofing. Combine filtering with MFA, verification processes and staff training.

    3. Q: How quickly should we act if we detect suspicious activity?

      A: Immediately. Reset passwords, revoke sessions, notify your bank and preserve logs. Early action improves chances of stopping transfers and recovering funds.

    4. Q: Is MFA enough to prevent BEC?

      A: MFA significantly reduces risk but is not foolproof. Attacks that use social engineering or SIM swapping underline the need for layered controls.

    5. Q: Who should handle BEC incidents in an SME?

      A: Ideally a small incident response team: a senior manager, the IT lead and a finance representative. External technical support can help preserve evidence and restore security.

    Conclusion

    Business email compromise is a realistic threat for South African SMEs, but it is manageable. By recognising warning signs, reinforcing technical defences and enforcing sound financial procedures, businesses can reduce risk and respond effectively when incidents occur. RandTech IT focuses on fast, experienced response and practical controls so your team can get back to business with minimal disruption.

    If you suspect a compromise or want to strengthen your email defences, contact RandTech IT for practical, experienced assistance tailored to South African SMEs.

  • What to Do Immediately After a Business Email Account Is Hacked

    What to Do Immediately After a Business Email Account Is Hacked

    Introduction

    A hacked business email account can be disruptive and dangerous. For South African small and medium-sized businesses (SMBs), timely, decisive action reduces financial loss, reputational damage and regulatory exposure. This guide outlines clear, practical steps to take immediately after an email compromise, with local context and realistic options for businesses in Johannesburg and across Gauteng.

    Immediate first actions (first 0–60 minutes)

    Act quickly but calmly. Early containment limits what attackers can do with access to your correspondence, calendar and business systems.

    1. Confirm the breach

    • Identify signs: unexpected password reset emails, unfamiliar sent messages, login alerts from odd locations or devices, or staff reporting missing messages.
    • Check recent activity in the webmail or email admin console for unfamiliar IP addresses or devices.

    2. Isolate the compromised account

    • Temporarily disable or block the account in your email admin panel (Microsoft 365 admin center, Google Workspace console or your hosting control panel).
    • If you cannot disable the account, change the password immediately and revoke active sessions if the platform allows it.

    3. Notify key personnel

    • Inform your IT lead or managed service provider (MSP) — ideally RandTech IT or the company responsible for your support.
    • Alert senior management and any staff who may be targeted next, such as finance and HR teams.

    Containment and assessment (within the first few hours)

    Once immediate containment is in place, assess the scope and impact so you can prioritise recovery steps.

    4. Assess what the attacker did

    • Review sent items, deleted items and auto-forwarding rules to see if emails were exfiltrated or redirected.
    • Check calendar entries for unauthorised meetings and contacts for new or modified entries.
    • Search for password reset emails to other services — attackers often use email to reset accounts on banking, cloud or payroll platforms.

    5. Identify affected systems and data

    • List systems that use the compromised email as a login or recovery address (bank accounts, cloud services, vendor portals).
    • Prioritise systems that could cause financial loss or regulatory risk, such as payroll or client data storage.

    Recovery steps (same day)

    Restore control securely and close any easy routes back in.

    6. Secure the account

    • Reset the account password to a strong, unique passphrase. Use a password manager to generate and store it.
    • Set up multi-factor authentication (MFA) if not already active. Use app-based authenticators or hardware tokens rather than SMS where possible.
    • Remove suspicious forwarding rules, connected apps and delegated access.

    7. Restore communications and notify contacts

    • Send a brief, factual notification to internal staff and key clients or suppliers if their data or interactions may have been affected.
    • Advise recipients to ignore suspicious messages that originated during the compromise and to verify any payment requests by phone using known numbers.

    Containment beyond the account (24–72 hours)

    An email compromise often indicates wider security gaps. Extend your response to related systems.

    8. Check related user accounts and devices

    • Inspect other accounts that use the same password or recovery email. Reset passwords and enable MFA where needed.
    • Scan and update devices that accessed the compromised account for malware using reputable endpoint tools.

    9. Work with banks and payment partners

    • If invoices or payment details were altered, contact your bank immediately. In South Africa, report potential fraud to your bank’s fraud desk and keep all supporting evidence.
    • Consider instructing suppliers and customers to pause high-value transactions until you’ve validated the payment instructions.

    Documentation and legal/regulatory steps

    Keep a clear record of the incident and actions taken. This supports recovery, insurance claims and any legal or regulatory obligations.

    10. Document everything

    • Record timestamps, actions taken, people involved and evidence such as suspicious emails and logs.
    • Preserve logs from the email service provider and any relevant server or firewall logs.

    11. Consider reporting to authorities

    • If the breach caused financial loss, theft of personal data, or targeted clients, report to the South African Police Service (SAPS) and your insurer.
    • For data breaches involving personal information, check obligations under the Protection of Personal Information Act (POPIA) and notify affected data subjects if required.

    Steps to prevent future incidents

    After recovery, implement measures to reduce the likelihood of recurrence and to speed future response.

    12. Harden account security

    • Enforce organisation-wide MFA and strong password policies.
    • Use role-based access control and restrict privileged account rights to only those who need them.

    13. Improve email defences

    • Enable advanced email filtering, DMARC, DKIM and SPF to cut phishing and spoofed messages.
    • Consider email security gateways or the advanced features in business suites like Microsoft 365 Defender.

    14. Train staff and run simulations

    • Phishing is a common vector. Regular, practical training and simulated phish tests reduce click-through rates.
    • Make incident reporting simple so staff report suspicious emails immediately.

    When to call in specialist help

    If the compromise is complex, involves theft of funds, or you lack internal IT capacity, get experienced incident responders involved quickly.

    What specialist responders do

    • Perform forensic analysis of email logs, devices and network traffic to determine scope and persistence.
    • Coordinate recovery, liaise with banks and authorities, and implement technical remediations.

    FAQ

    • Q: How fast should we respond to a hacked business email?
      A: Immediately. The first hour is critical to block access and prevent fraudulent payments or data loss.
    • Q: Do we need to inform clients if our email was hacked?
      A: Yes, inform affected clients promptly if their data or transactions were impacted, and advise them how to verify communications.
    • Q: Can we recover everything from a hacked account?
      A: Often you can restore access and remove attacker persistence, but you must verify whether emails were copied or data exported and act accordingly.
    • Q: Is SMS-based two-factor authentication adequate?
      A: SMS is better than nothing but vulnerable to SIM-jacking. Use app-based authenticators or hardware tokens for stronger protection.
    • Q: Should we report the incident to POPIA authorities?
      A: If personal information was compromised and the breach presents a risk to data subjects, POPIA notification requirements should be considered and legal advice sought.

    Conclusion

    A hacked business email account is urgent but manageable. Fast containment, thorough assessment and careful recovery protect finances, clients and reputation. Strengthening technical controls and staff awareness reduces future risk.

    If you need practical, experienced assistance to recover from an email compromise or to harden your systems, contact RandTech IT. Our engineers prioritise rapid resolution so your business can get back to work with confidence.