Cybersecurity Issues: Email Domain Spoofing

28/10/2020
|

At onBRANDING, we have repeatedly warned about the consequences of falling victim to Phishing, identity theft, cybersecurity issues, and cyber risks associated with inadequate protection of digital devices and channels. This time, we will delve into why the email domains of official bodies and companies are spoofed by cybercriminals to deceive and defraud users and employees.

What is “email spoofing”?

It is one of the main problems that can arise from not having a completely secure email domain.

It consists of the spoofing of the affected email domain’s identity, with the aim of prompting victims to take an action: surrender access data to personal or bank accounts; download or open files; install software, etc.

A clear example of an organization that has paid the price for an incorrect domain configuration in this cyberattack is the Tax Agency.

Users received an email impersonating the official body, inviting them to “Download” an attached file that they would have to return signed within a maximum of 7 days, in the context of new tax measures introduced during the COVID-19 crisis.

By clicking “Download,” the application redirects them to a form where the user must enter their login credentials for the Tax Agency. In this way, the cybercriminals behind this action gain the key to directly access company data.

Less than 2% of the domains analyzed by Marc Almeida have the corresponding security filters activated on their email domains.

Marc Almeida, a technical analyst at onBRANDING, analyzed around 40 million email domains, finding that fewer than 53,000 were securely configured.

In the interview Marc granted to Business Insider magazine, he confirms that 99% of the sample analyzed for the study is vulnerable to phishing attacks.

The article emphasizes that this technique is the gateway for cybercriminals to attack companies and public organizations. Employees are a fundamental link and, at the same time, one of the weakest against cyberattacks, as human intervention is needed to download or access malicious content.

However, it may be disproportionate to think that the employee is responsible for cybercriminals gaining access to equipment or data. It is more logical to think, and in fact, it is the reality, that the security configuration of email domains is incomplete.

The importance of SPF, DKIM, and DMARC filters in email domain configuration.

These three filters are standards designed to increase or reinforce the three fundamental principles in cybersecurity:

  • Confidentiality: data remains protected, preventing unwanted access.
  • Availability: information is available to recipients.
  • Integrity: the information offered is accurate and does not vary during access or delivery.

The email domain is what generates user trust when receiving an email. If this domain is manipulated or has been spoofed, victims can easily fall into the trap.

To prevent this domain from being duplicated or spoofed, the three cybersecurity filters applied to email must be activated:

  • SPF (Sender Policy Framework): the first step to secure and legitimize the origin of emails. Its configuration involves listing which IPs are authorized to send emails using the domain name in question.
  • DKIM (DomainKeys Identified Mail): “signs” the outgoing email from the origin domain so that the recipient can validate that it has not been modified during transit.
  • DMARC (Domain-based Message Authentication, Reporting and Conformance): an evolved SPF, with more features. Notably: protecting domains and subdomains; as well as automatically generating reports of all emails sent using the configured domain. This way, a record can be available if needed.

There is a fourth filter we could configure:

  • BIMI – Still in the implementation process, it assigns an image in a specific format to a domain.

What benefits can activating these security filters provide?

The benefits and “whys” that answer this question are obvious.

Aside from protection against identity theft, phishing attacks, or ransomware, there are other less obvious but equally important benefits for a business:

  • Positioning the brand, organization, or company as a trusted source or sender.
  • Allows the organization to anticipate problems, avoiding the risks described.
  • It guarantees security by encouraging user action and interaction with the email and with the links or files sent.
  • Prevents and avoids reputational damage derived from the theft of confidential customer information or internal documentation.
  • Prevents financial losses derived from illicit access to accounts and bank movements.

Email domains of companies and corporations, as Marc Almeida, a technical analyst at onBRANDING, has demonstrated, are not configured correctly. This implies serious cybersecurity issues that can lead to incalculable costs in reputation and financially.

The risk of identity theft or “email spoofing” is higher the lower the digital security prevention. At onBRANDING, we are specialists in Digital Identity, Cybersecurity, Cyber Investigation, and Online Reputation.

If your company’s identity has been spoofed, or you are a victim of cybercriminals in your private or corporate environment, you can contact us through this form.

Digital Identity

Methods for analyzing and
assessing online
reputation damage