ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Hacking the hackers

John Wilson at Fortra explores some of the ways that organisations can take the information security fight to the cyber criminals

 

Over the last five years, business email compromise (BEC) has grown to become the predominant cyber threat facing businesses today.

 

According to a recent report from the FBI, global losses resulting from fraudulent transfers surpassed $43 billion between June 2016 and December 2021. More worrying still is the FBI’s observation of a 65% uptick in reported losses between July 2019 and December 2021 following the mass shift to remote work.

 

Email phishing, credential theft and mailbox hacking are now the activities of choice for threat actors whose sophisticated approaches can fool even the most security-minded employees. Indeed, the UK government recently reported that 83% of UK businesses and charities have been targeted by these types of scams.

 

So, what actions can organisations take to disrupt these criminals and fight back?

 

Changing the risk-reward equation

Today’s organisations are using a variety of passive defence measures such as spam filters, anti-virus solutions and firewalls. While these are vital components of every company’s cyber security posture, they do nothing to penalise the attacker, leaving the bad actor free to try again another day and continue to refine and evolve their approach for optimal results.

 

Many active cyber offensive methods are currently illegal, such as accessing a hacker’s computer without authorisation. However, adopting an active defence strategy that seeks to penalise attackers and increase the risk to their assets, tools, and perhaps even their freedom, is perfectly legitimate.

 

Unlike passive approaches, active defence techniques focus on getting scammers to reveal who they are and their mode of operation. This includes learning as much as possible about how they carry out attacks, identifying their key objectives and targets, and how they plan to ‘cash out’. This tactical and technical intelligence can then be used to thwart attacks and actively hit back, for example, by cutting criminals off from the resources they use to execute an attack.

 

Passive versus active – penalising the attacker

Hackers depend on infrastructure provided by others to pursue their nefarious activities. Organisations that want to go on the offensive will need to gather operational intelligence relating to everything from the email and web hosting services or IP addresses used by an attacker to identify details of the bank accounts and payment instruments they use to take receipt of monies illicitly gained.

 

This information can then be delivered to hosting providers or organisations whose websites have been hacked so they can take action. This includes shutting down email accounts and APIs or taking back control by resetting admin security to restrict a hacker’s access to critical infrastructure and other tools of their trade.

 

Similarly, by providing details to the relevant finance institutions on the bank accounts and other payment instruments that hackers are using – including mule accounts – these too can be shut down and assets frozen.

 

The ultimate goal, however, is to build dossiers containing actionable intelligence, including details of the culprits involved, that can be presented to law enforcement agencies who can pursue an arrest and criminal prosecution of key gang members.

 

Minimising cyber crime gains

Initiating an active defence strategy that looks to detect and shut down phishing sites and mailer programmes, along with the mechanisms used to monetise an attack, requires significant time, resources and specialist expertise and can be difficult to operationalise.

 

However, there are specialist service providers who can undertake a range of active defence activities. These providers initiate baiting operations that encourage hackers to reveal how they are targeting an individual business, which employees they target, how they set up additional infrastructure and how they exploit compromised accounts.

 

Similarly, there are automated tools that can help today’s security analysts accurately assess the high volume of suspicious emails reported by users. These tools identify and suspend look-alike domains and automatically eliminate threats by removing malicious emails before they are even reported.

 

Finally, from an active defence perspective, taking advantage of in-the-moment operational and strategic intelligence that highlights risk factors and attack patterns of known criminal groups, together with technical insights on how attacks are being executed, is a must-have. It is also important to use technical insights on how attacks are being executed for countering specific exploits and vulnerabilities. Armed with this know-how, companies can proactively defend themselves against known and highly targeted threats.

 

Taking arms against an ever-present threat

Today’s threat actors are taking advantage of zero-cost tools including free hosting services and URL shorteners to conduct their BEC campaigns and unleash a tsunami of phishing attacks.

 

By investing in proactive detection methods and services, organisations can unleash rapid remediation tactics designed to counter threats that may make it past their passive security controls, gathering the intelligence they need to identify and repel these types of attacks.

 


 

John Wilson is Senior Fellow, Threat Research at Fortra

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543