WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Passthrough – EPA Office of Inspector General Issues BEC Fraud Alert
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partnerships
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Passthrough – EPA Office of Inspector General Issues BEC Fraud Alert

Author: Chase Snow

Created: Tuesday, February 20, 2024 - 19:38

Categories: Cybersecurity, Federal & State Resources, Security Preparedness

The U.S. EPA OIG issued a fraud alert (attached) to highlight the all-too-common and costly form of phishing known as business email compromise (BEC). In this convincing scam, criminals are using fraudulent emails that appear to come from known and trusted sources to access company email accounts and target organizations that make or receive financial transactions. These emails may originate from lookalike, or spoofed, email accounts or legitimate email accounts compromised through phishing campaigns. Using information obtained from successful phishing campaigns to impersonate a representative of the trusted entity, the criminals deceive personnel into transferring funds or sensitive information under the guise of a legitimate business request.

The EPA OIG offers the following guidance that can help your organization protect against BEC:

  • Create organizational policies for receiving new payment instructions, including a multistep process to verify new payment instructions.
  • Employ email security systems that can detect phishing attempts, domain spoofing, and other cyber threats, and use two-factor authentication to combat account compromise.
  • Train staff regularly on cybersecurity best practices and how to recognize phishing emails and require them to report phishing attempts—even seemingly minor ones.

Similarly, CISA recently shared its “Cybersecurity Emotions” series which details the social engineering tactics that threat actors often use when employing threats such as BEC mentioned above. Each “emotion” is effectively described and explained allowing relatable resources to help train users to recognize these common tactics.

For more details about the Fraud Alert, see the U.S. EPA OIG official site.

Attached Files:

fraud_alert_2-13-24

Related Resources

Tip of the Week – May 14, 2026

May 14, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 14, 2026)

May 14, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

(TLP:CLEAR) Non-Human Identities (NHIs) Are Growing Faster Than Most Security Programs

May 14, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar