Businesses are under constant threat from cyber attacks, from Business Email Compromise (BEC) to malicious browser extensions. But what can companies do to protect themselves?
What Happened
Recently, a malicious Chromium extension was discovered that spoofs Perplexity AI to hijack browser searches. The extension intercepts users' search traffic and routes queries through attacker-controlled servers before forwarding them to legitimate search engines. This type of attack can be difficult for users to detect, as it maintains a normal browsing experience.
In another incident, insurance giant Aflac disclosed a data breach after attackers breached its Japan subsidiary's systems and stole personal and bank account information. The breach highlights the importance of robust cybersecurity measures to prevent such attacks.
Why It Matters
BEC is often described as an email scam, but it's part of a broader operation that requires patience and infrastructure. Attackers need to gain access to a targeted business, gather data, build a communication channel, and access payment infrastructure to monetize the attack.
"Actors are interested mainly in SaaS accounts, such as O365," said Flare researchers. "Corporate leadership and financial employees are the most desired targets."
What Experts Say
To combat BEC, businesses need to be proactive. "The email itself is only one part of the attack chain," said a cybersecurity expert. "Companies need to have a comprehensive security strategy that includes employee education, robust security measures, and incident response planning."
Key Numbers
- 42% of businesses have experienced a BEC attack in the past year.
- $3.2 billion is the estimated cost of BEC attacks in 2022.
Key Facts
- Who: Aflac Japan
- What: Data breach
- When: June 15-25, 2026
- Where: Japan
- Impact: Personal and bank account information stolen
What Comes Next
As cyber threats continue to evolve, businesses must stay ahead of the curve to protect themselves. This includes implementing robust security measures, educating employees, and having an incident response plan in place.
"The new policy in the Teams Admin Center, Manage external bots and their access to meetings, can be assigned to individual users or groups, giving organizations more control and visibility over external bots in their meetings." — Microsoft
Microsoft has introduced a new Teams admin policy that allows organizers to prevent third-party bots from joining meetings without approval. This feature gives organizations more control and visibility over external bots in their meetings.
By staying informed and taking proactive steps, businesses can protect themselves from cyber threats and prevent costly breaches.