Jonathan Richards
Win tickets to the ATP finals
Corporate bosses have become the latest target of cyber-criminals, after a string of attacks in which senior management have been singled out to receive fraudulent e-mails.
Internet fraudsters have taken to sending personally addressed e-mails to chief executives and other high-level executives with a view to installing malicious software on computers that have access to the most privileged company information.
In the latest e-mail scam, known as "whaling" because it targets "the big fish", executives are sent official documents — for instance, court subpoenas — that apparently relate to the business of senior management.
The employees singled out are typically "C-level", meaning chief financial officers, chief technology and information officers, as well as those in other sensitive parts of the company, such as accounts.
The hope is that recipients will click on a link in the e-mail which directs them to a website that installs a malicious programme on their machine.
Criminals can then gain access to highly sensitive company secrets, such as financial details, news of impending product releases, results of recent research and other information that may enable them to make money on the stock market.
Among the firms known to have been targeted by the scam, which is a variation on well-known phishing e-mails that have hit banks, are those in the arms and energy industries.
In the case of sensitive industries such as defence, those responsible for sending the e-mails may include not only cyber-criminals but foreign governments, experts said.
"You never really expect to see that scenario, which is straight out of Hollywood fiction, but in the case of weapons companies, there probably is some espionage element," Mary Landesman, a senior researcher at ScanSafe, the security firm, said.
In the latest example, chief executives at more than a hundred companies based in the San Fransisco area were sent a personally addressed e-mail commanding them to appear before a grand jury in a district court.
The e-mail specified the date and time of the court appearance, contained reference to specific "Federal Rules of Civil Procedure", and was written in apparently convincing legal language, including expressions such as "this subpoena shall remain in effect until you are granted leave to depart by the court or by an officer on behalf of the court".
The correspondence was also configured so that it came from an address that ended in 'cacd-uscourts.com', a quite close approximation to the typical internet domain for American courts — courtname.uscourts.gov.
Whaling e-mails have for the most part targeted US executives, but security experts said that the scam would almost certainly "jump the pond" and warned senior management in the City to be vigilant.
"If you're an executive in a FTSE 100 company in a sensitive industry, then you need to be very cautious about e-mail and understand that you're a target," Ms Landesman said.
In some cases the e-mails have also made reference to known family members of the executive, gleaned for instance from social networking sites, where members will often post information about what their friends or relatives do for a living.
"Networking sites are starting to play a big role in online scams," Guy Bunker, chief scientist at Symantec, another security firm, said.
"It's on those sites that criminals are learning, for instance, that so-and-so works in accounts at such-and-such a company."
"Social engineering", the practice by which criminals exploit human curiosity to gain access to information — for instance by pretending they are an employee at a company — is an area of increasing focus for the security industry and was a big theme at the InfoSec conference in London this week.
Greg Day, a security analyst for McAfee, the antivirus company, said: "As we spend more and more time on the internet, our digital fingerprint is simply getting bigger and bigger, and that makes for greater opportunities for people to gather information about us."
Industry sectors news at a glance. Interactive heatmap, video and podcast
Everything the Business Traveller needs to know to make a better trip
Get ready for the winter sports season, with our resort guides and snow reports
We are backing British business, what is the confidence of the nation and what businesses are succeeding?
Growing demand for energy, oil that is harder to reach and the rise of carbon dioxide emissions. We examine the energy challenge
Enjoy further reading from Travel to Fashion, Business to Sport, discover more
Shortcuts to help you find sections and articles
36-month car lease
on contract hire for
£359.99 plus VAT pm
12 months for the price of 11 and a 5% discount.
Offer ends 31/11/09
The UK's leading alternative to showroom finance.
Finance packages tailored to your needs.
Minimum loan of £15,000
Car Insurance
£12,578 per annum
The Independent Housing Ombudsman
London
Competitive
Barclaycard
Not Specified
The Sheppard Trust
London
£80-95,000
Clay McGuire Executive Selection
Moments from Battersea Park.
For sale with Winkworth.
See your free Experian credit report beforehand
Book now & save over £100pp.
11 cool resorts, lowest prices... Early Booking offers 15 Nov.
20% off selected Azores holidays taken in October with Sunvil Discovery
Get covered on your travels with a superb range of policies at great prices. Visit InsureandGo.com
World Class Golf, Spa and preferential Beach Club. Private estate overlooking West Coast
Villas from £275 per night inclusive of Golf
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times, or place your advertisement.
Times Online Services: Dating | Jobs | Property Search | Used Cars | Holidays | Births, Marriages, Deaths | Subscriptions | E-paper
News International associated websites: Globrix Property Search | Milkround
Copyright 2009 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.