Hackers Tricked 3 British Private Equity Firms

enovise.com
Published On 15 Feb 2022
Enovise
Summary
In a highly targeted business email compromise attack, the Florentine Banker group tricked three British private equity firms into wiring $1.3 million — approximately $700,000 permanently lost — using man-in-the-middle tactics and lookalike domains to intercept and manipulate financial communications.
In a recent highly targeted BEC attack, hackers managed to wire up three British private equity firms, with fraudulent access to bank accounts totalling $1.3 million — while officials thought they had closed an investment deal with a startup. According to cyber security firm Check Point, nearly $700,000 of the total transferred amount has been permanently lost to the attackers; the balance was recovered after Check Point alerted the targeted companies in time.
The Florentine Banker Group
Dubbed "The Florentine Banker", the sophisticated cybercrime gang behind this attack "seems to have perfected techniques through multiple attacks spanning at least several years of activity, and has proved to be a resourceful adversary, quickly adapting to new circumstances."
The lookalike domain technique presents a serious threat — not only to the organisation originally attacked, but also to third parties with whom those lookalike domains were used to communicate. Check Point's previous investigations linked the same group to attacks targeting the manufacturing, construction, legal, and finance sectors across the US, Canada, Switzerland, Italy, Germany, and India.
How the Attack Worked
The fraud scheme operated as a carefully planned man-in-the-middle (MITM) attack:
1. Attackers sent phishing emails to gain control over email accounts within the targeted organisations and conducted detailed reconnaissance on the business and key personnel.
2. Attackers tampered with victims' Outlook mailboxes, diverting related emails into an RSS feed folder or another folder not typically monitored.
3. Attackers registered lookalike domains that closely mimicked the legitimate domains of all entities involved in the email correspondence. For example, if correspondence existed between 'Finance-firm.com' and 'banking-service.com', attackers registered 'Finance-firms.com' and 'banking-services.com'.
4. The Florentine Banker sent emails to each counterparty from the spoofed domain, inserting themselves into the conversation. Each email sent by a legitimate party was received by the attacker, who reviewed it, edited content where necessary, and forwarded it from the relevant lookalike domain to its original destination.
5. With this setup in place, attackers injected fraudulent bank account information — linked to accounts in Hong Kong and the UK — into emails to interrupt money transfers and initiate new fraudulent wire requests.
Source: Tech Rander / Check Point Research
You May Also Like
View Blogs
Kenya Threat Landscape Report 2024
The Kenya Threat Landscape Report, prepared by SOCRadar and Enovise, highlights various aspects of the cyber threat environment around Kenya — where public administration, information, and finance sectors collectively account for over 43% of observed incidents.

Enovise Group and SOCRadar Partnership
Enovise has partnered with SOCRadar to deliver advanced, proactive cybersecurity solutions for organisations across Africa, integrating SOCRadar's Extended Threat Intelligence platform with Enovise's Managed Detection and Response services.

Garmin South Africa Hack
Customer data for purchases made through the Garmin South Africa shop has been stolen — including payment card numbers, CVV codes, names, physical addresses, phone numbers, and email addresses — containing all the information required to make fraudulent purchases.

Hackers Stole and Encrypted Data of 5 US Law Firms
Hackers compromised five United States law firms and demanded two 100 Bitcoin ransoms from each firm — one to restore access to the data, one to delete their copy instead of selling it. The Maze group published part of the stolen data, threatening to release increasingly sensitive material unless paid.