https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Security


CryptoFX/Shutterstock

SVB Collapse Prompts New Wave of Cyber Threats

  • Written by Edward Gately
  • March 14, 2023
The fallout from Signature Bank’s failure likely will lead to similar cyber threats.

Last week’s collapse of Silicon Valley Bank (SVB) has given cybercriminals an opportunity to take advantage of the ensuing chaos.

SVB was closed by the California Department of Financial Protection and Innovation on March 10. The FDIC then was appointed receiver. On Monday, the FDIC transferred all deposits – both insured and uninsured – and substantially all assets of the former bank to a newly created FDIC-operated “bridge bank” to protect all SVB depositors.

Sounil Yu is JupiterOne‘s CISO. He said the SVB situation creates a “tremendous opportunity” for attackers to launch fraudulent vendor email compromise (VEC) and business email compromise (BEC) attacks. They’ll try to convince finance teams to switch banking details over to an attacker-controlled account.

JupiterOne's Sounil Yu

JupiterOne’s Sounil Yu

“Given SVB’s breadth of exposure across the startup ecosystem, we should expect to see many finance teams receiving an unusually high number of updates about new banking relationships and wire instructions,” he said. “Attackers are likely to indiscriminately impersonate vendors regardless of whether the vendor previously banked with SVB or not.”

Finance teams should confirm that the updated details of any of their vendors are indeed correct, Yu said.

SVB Collapse Prompts Social Engineering Attacks

Ashley Allocca is intelligence analyst at Flashpoint.

Flashpoint's Ashley Allocca

Flashpoint’s Ashley Allocca

“Financially motivated threat actors will often act opportunistically, seeking to take advantage of newsworthy events,” she said. “These events may influence the theme of various social engineering tactics used to gain initial access to compromise victims.”

Generally speaking, threat actors are likely to execute SVB-themed social engineering attacks, Allocca said. They’ll focus on phishing scams and malware lures.

What Flashpoint is seeing now is the potential use of newly registered domains that can be used in phishing attacks, Allocca said. They aim to collect sensitive information or coerce victims into sharing information or sending funds to actor-controlled accounts.

Threat actors have been registering new domains to look like legitimate pages affiliated with SVB, she said.

“For example, on March 11, the day following the SVB collapse, new domains like login-svb[.]com, svbbailout[.]com, svbdividendpayout[.]com, and svbfail[.]com were registered,” Allocca said. “That day, at least 16 other domains using SVB were registered.”

Registrants may not leverage all of those domains for malicious purposes, she said.

“But it is clear in the case of login-svb[.]com that that page will likely resolve to a login page for SVB affiliates, malicious or otherwise,” Allocca said.

Domains for SVB Competitors Cropping Up

Similarly, newly registered domains for known SVB competitors have been and will likely continue to crop up, Allocca said.

“For example, we have seen domains mimicking Revolut, a British-Lithuanian financial services company, including customer-revolut[.]com, logon-revolut[.]com, and revolutbank[.]net,” she said. “This may portend social engineering attacks with themes of transferring a financial relationship from one bank to another.”

A victim could be anybody who clicks on a malicious link, Allocca said. This could occur as part of a spear phishing campaign. That’s when a threat actor sends a personalized email to a specified targeted person, business or organization. The email generally impersonates a trusted source, such as an executive. And it contains either malware-infected documents or links to malicious websites.

There are many concerns about the interconnectedness of financial accounts, she said. Therefore Flashpoint recommends extra due diligence with any requests to update bank account information.

“There are many companies taking rapid action to update their payment information away from SVB, which presents a prime opportunity for cybercriminals to capitalize on this crisis situation, Allocca said.

Similar Threats Likely from Signature Bank Failure

It’s likely that the fallout from Signature Bank’s failure will lead to similar cyber threats, Allocca said. Financially motivated threat actors will act opportunistically. They’ll use the same low-level initial access techniques like phishing to prey upon those most impacted by the failure.

James Liolios is senior threat intelligence researcher at Arctic Wolf.

Arctic Wolf's James Liolios

Arctic Wolf’s James Liolios

“Threat actors can leverage phishing emails which could contain new banking wire information, instructing an employee to make changes to benefit the threat actor in this scenario for financial gain,” he said. “Threat actors may also target employees’ social media accounts, such as LinkedIn, where they can identify individuals working at startups or other affected organizations.” 

Arctic Wolf Labs has multiple detections in place for suspicious activity on email accounts associated with BEC and account takeover attacks, Liolios said.

Arctic Wolf continues to monitor for tactics, techniques and procedures (TTPs) associated with campaigns that may arise from these events.

Want to contact the author directly about this story? Have ideas for a follow-up article? Email Edward Gately or connect with him on LinkedIn.
Tags: MSPs VARs/SIs Best Practices Cloud Regulation & Compliance Security Technologies

Most Recent


  • Trophy
    Channel Partner Awards: SolarWinds, GoTo, Darktrace, Juniper Networks, IGEL, More
    Schneider Electric, Varonis and more also handed out awards.
  • people chains
    Vernick, Jones Join Upstack Leadership Team, Reject 'Roll-Up' Stereotype
    "The writing is on the wall. The superagent is the evolution of this channel," J.R. Vernick told Channel Futures.
  • Cloud
    Ingram Micro Earns AWS Migration Competency, Helps Partners Migrate Workloads
    The distributor said it will assist partners to “accelerate the customer cloud adoption journey.”
  • Baseball swing
    VMware Partner Connect Now in Full Swing Worldwide
    "This is the complete end state” of VMware’s channel program, per Tracy-Ann Palmer, and will hold for years.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Making Waves
    8 Channel People Making Waves This Week at T-Mobile, Kaseya, Google Cloud, Atlassian, More
  • Money Growth
    10 Findings from Channel Futures' MSP Quarterly Survey: Profit Outlook Positive Despite Macro Challenges
  • Layoff written in metal
    Wipro Layoffs Hit 120 Workers in Florida Due to Lack of Work
  • MSP News Roundup
    MSP News Roundup: 11:11 Systems, CompTIA, GoodSuite

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Channel Partner Awards: SolarWinds, GoTo, Darktrace, Juniper Networks, IGEL, More

March 21, 2023

Vernick, Jones Join Upstack Leadership Team, Reject ‘Roll-Up’ Stereotype

March 21, 2023

VMware Partner Connect Now in Full Swing Worldwide

March 20, 2023

Industry Perspectives

View all

10 Strategic Smart Enterprise Drivers for 2023

March 16, 2023

Does Your Company Have a Virtual Water Cooler?

March 13, 2023

How Hybrid Work Poses Major Cybersecurity Risks

March 1, 2023

Webinars

View all

Equipping the Hybrid Workforce: What It Takes to Execute

March 28, 2023

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Real-Life M&A: Advice for a Successful Channel Deal

Coffee with Craig and James Episode 120: Ronnell Richards

March 3, 2023

XDR Technology: Latest Breakthroughs, How to Talk to Customers

March 1, 2023

Coffee with Craig and James Episode 119: Alliance of Channel Women

February 22, 2023

Twitter

ChannelFutures

Upstack's newest CX leaders say their appointment is a sign of Upstack's agent-friendliness. dlvr.it/SlDvMV https://t.co/srsiKpzJ7K

March 21, 2023
ChannelFutures

With the @awscloud Migration Competency, @IngramMicroInc will help partners to “accelerate the customer cloud adopt… twitter.com/i/web/status/1…

March 21, 2023
ChannelFutures

.@HPE acquiring @OpsRamp to add capabilities to @HPE_GreenLake. #cloud dlvr.it/SlCFz9

March 20, 2023
ChannelFutures

The relationship between technology advisor (agent) firms, technology service distributors (TSDs) and suppliers is… twitter.com/i/web/status/1…

March 20, 2023
ChannelFutures

.@citrix channel marketing exec Tricia Atkinson is joining @Equinix to lead global partner #marketing.… twitter.com/i/web/status/1…

March 20, 2023
ChannelFutures

.@bizITsolutions announced a partnership with New Charter Technologies. dlvr.it/SlBh09 https://t.co/xpqbQcKC6y

March 20, 2023
ChannelFutures

.@VMware has finalized #PartnerConnect and plans to keep it as-is (minus simplification changes) for years to come.… twitter.com/i/web/status/1…

March 20, 2023
ChannelFutures

Our latest #GatelyReport includes a Q&A with @HuntressLabs, massive ILS #databreach, new @SECGov cyber proposal,… twitter.com/i/web/status/1…

March 20, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X