Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Security Education Videos Scams & Phishing Your Security Mobile Security Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
Gift Cards Being Used For Payment In BEC Scams, And What You Need To Know
Facebook   X   LinkedIn   Email

Gift Cards Being Used For Payment In BEC Scams, And What You Need To Know

February 24, 2024

Over the years, gift cards have become an enormous “go to” way of giving. Mageplaza found the purchase of gift cards this year will reach nearly $450 billion globally. And like many things involving monetary value and being human, cyber-scammers are exploiting gift cards for profit. They’re now combining gift card fraud with the world’s most lucrative cybercrime, business email compromise (BEC) attacks.

Typical BEC attacks target organization employees with emails appearing to be from a C-level or other high-ranking company executive. The emails often request urgent wire transfers and provide the account number for the transaction. The end result? The employee unknowingly sends funds to the scammer’s account. The exec has no idea about the transfer, and maybe worse, finds the crime done in their name.

BECs Adapt and Trend

According to researchers at Cofense, organizations are getting hip to more traditional BEC tricks and have bolstered protections against them. As a result, fraudsters needed a new lure and turned their attention to gift cards. Their cash-outs are hard to track, providing payoffs and anonymity for the criminals.

Cofense learned most scammers go for a quick, same-day turnaround to avoid the 72-hour anti-money laundering (AML) “safety window” for some cases. They sell the ill-gotten cards locally at about a 50% discount or unload them online at exchanges for 80-85% of their value, often selling them for payments in cryptocurrency.

FYI…scammers are picky about the gift cards they steal. They prefer amounts from $100-$500, specifically from stores as opposed to those from financial companies like Visa and American Express.

From Wire Transfers to Gift Cards

Cofense found adapting BECs from wire transfers to gift cards is a seamless transition. Instead of directing an employee to make financial transfers into an account setup for the BEC, the scammer emails the employee, asking if they can “help out” by purchasing gift cards for them.

The email lures, also the reasons they give for needing the cards, range from employee holiday or birthday gifts, a “Thank You” for a client, and anything else sounding plausible. Once on the hook, the scammer (posing as the executive) has the victim scratch-off the card code and send pictures of the cards to them. At that point, the dirty deed is as good as done.

Phishing Successfully

Scammers get a lot of the information they need to impersonate a C-Level from the internet. LinkedIn is a treasure-trove of information for them. Specific details such as company names, titles, contact information, and a lot more are readily available. Contacts of those people are “linked” and easy enough to find. That information alone can make a spoofed email message easy for a scammer. So, everyone should limit what information is made available on social media or anywhere on the internet—even on the company website. The more information listed there, the more realistic a scammer can make an email with the goal of a BEC payout.

Policies should be in place to ensure wire transfers don’t go out to thieves. And now, a policy may need to be added to never pay for anything in gift cards. Keeping up with the latest, trending cybercrimes isn’t easy. But those who run a business should make it their business to know about cyberthreats like BECs; and gift card scams are just the latest reason why.


Accounts Drained By Zelle Smishing Scam

Mobile Security

Accounts Drained By Zelle Smishing Scam

From time to time, scammers come up with a new tactic using new technology, new events, or whatever they can to continue tricking us into giving up our personal or confidential information. Over the past few years and with the increasing use of texting and SMS messaging, a newer one in the bag of tricks has been coined as “smishing.” Because it’s text, it often catches people off guard and causes them to react quickly, which is exactly what you shouldn’t do. READ FULL STORY

You've Won A Free Gas Card And Fraud, For A Small Fee

Scams & Phishing

You've Won A Free Gas Card And Fraud, For A Small Fee

We are all kind of tired of the high gas prices right now, no matter where we live or what we drive. Most visits to the fuel pump can tick up more than $100 per tank. Then, a couple of weeks later for most of us, we have to fill up again and it’s likely to be even more. Coupled with high food prices and high pretty much everything else, we would all love some financial relief for the things we need to make it through the week. Scammers are counting on us all getting fed up with high fuel prices and are luring us into fraud with a new fuel gift card scam. READ FULL STORY

Money Mule Scams Are More Common Than You Would Expect

Education

Money Mule Scams Are More Common Than You Would Expect

A money mule scam is when someone sends money to you and asks you to send a portion of it to someone else. They often ask you to use gift cards or wire transfers. The money they are providing you is likely stolen. Drug trafficking and human tracking are also common sources of the money, and they're lying about the reason they need you to send it. The relationship, job, prize or other reason they use is not real and they are only using you to launder money.  READ FULL STORY

Protect Yourself From Phishing Scams: 8 Steps To Better Security

Scams & Phishing

Protect Yourself From Phishing Scams: 8 Steps To Better Security

Since the mid 1990’s, email phishing scams have been on the rise. Like most cybercrimes, hackers have improved and refined their phishing methods over time. Now, there’s been a massive increase in targets due to the continuing coronavirus epidemic. Email phishing continues to be the method of choice for many cybercriminals to enter your device, steal your data, identity, finances, and more. A study by Tessian finds that 96% of phishing attacks arrive via email, showing the threat is very real. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...