Detecting fraud From <-> Reply attempts
Posted: 26 Jul 2016 05:59
I am getting more and more of these coming in and they are specifically targeting accounts staff and ceo/gm members.
Emails where the From Address shows up like this in Outlook.
From : "ceo's name" [mailto: "ceo's email address"]
But the hidden Reply address is some anonymous webmail service somewhere.
The users though, see "CEO" and hit reply and don't look at the reply address to see "Hey that's not his email address" and then reply with the requested details. Usually bank balances and transfer limits, had an accounts staff member almost transfer a large sum of money thinking the ceo had requested it, sanity & logic prevailed though. But it is an issue when staff are not truly computer literate and are just following a repeated process.
The question.
I want to flag as spam or even just bounce emails that the From domain doesn't equal the reply domain.
Anyone see any holes in that or suggestions?
Tips on implementation would be great as well.
Emails where the From Address shows up like this in Outlook.
From : "ceo's name" [mailto: "ceo's email address"]
But the hidden Reply address is some anonymous webmail service somewhere.
The users though, see "CEO" and hit reply and don't look at the reply address to see "Hey that's not his email address" and then reply with the requested details. Usually bank balances and transfer limits, had an accounts staff member almost transfer a large sum of money thinking the ceo had requested it, sanity & logic prevailed though. But it is an issue when staff are not truly computer literate and are just following a repeated process.
The question.
I want to flag as spam or even just bounce emails that the From domain doesn't equal the reply domain.
Anyone see any holes in that or suggestions?
Tips on implementation would be great as well.