WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 Security Awareness Reminder – Business Email Compromise, a Primer on Impersonation Attacks
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Security Awareness Reminder – Business Email Compromise, a Primer on Impersonation Attacks

Author: Jennifer Walker

Created: Thursday, November 12, 2020 - 18:40

Categories: Cybersecurity, General Security and Resilience, Security Preparedness

Given the Abnormal Security’s Q3 Quarterly BEC Report shows that business email compromise (BEC) has recently grown in interest over the last quarter, and the energy/infrastructure industries have experienced a 93% increase in attacks, now is NOT the time to curtail your security awareness reminders on BEC and other impersonation-based scams. Therefore, Agari’s BEC Attacks: What They Are, How to Spot Them, and What to Do couldn’t come at a better time, especially heading into the holiday season when threat actors are notoriously known for spreading bad cheer!

Agari, the email security leader, provides another concise and timely post on this prevalent threat by highlighting seven common impersonation themes and how can they be stopped. The post discusses payment fraud, payroll diversion, vendor email compromise, gift card scams, aging financial accounts scams, transaction diversion, and advanced payment schemes – themes that some WaterISAC members may be intimately familiar. Given the need for security awareness reminders and reinforcements – especially with the upcoming holiday season – members are encouraged to pass this article along as a reminder to all that “BEC groups are master manipulators who use clever social engineering ploys to throw email recipients off kilter just long enough to respond to an email request before ever thinking to confirm its legitimacy.” Whether you have the best controls in place or not, this post is a great sanity check to confirm your defenses are properly implemented, and it may even spark more ideas to protect your users and organization from falling victim. Read the post at Agari.

Related Resources

Members Only

(TLP:AMBER) DHS Office of Intelligence and Analysis Reports (May 21, 2026)

May 21, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – May 21, 2026

May 21, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:GREEN) PEAR Ransomware Claims U.S. Drinking Water Utility as Victim

May 21, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar