In addition to the Nimblr Azure integration, organizations using Google Workspace may now easily integrate with Nimblr’s online training platform designed to strengthen end-user security awareness and minimize the risk of completed attacks. Nimblr combines interactive IT security awareness training with simulated attacks, hands-on exercises, and daily fresh content on the latest threats in a continuous education program. Read more about Nimblr Security Awareness here.
With Nimblr’s new Google Cloud Directory Integration, organizations can synchronize users in Google Cloud Directory with the Nimblr service, giving a fully automated Security Awareness Program. New Google Directory users are automatically deployed and introduced to the Security Awareness training program, while disabled users are automatically removed.
Last quarter, Google Cloud reported an increase of 46% year-over-year for it’s Cloud services including Google Workspace. Organizations, using Google for user management and cloud based directory services, who’s looking for a fully automated Security Awareness training program should definitely check out Nimblr.
Nimblr have been getting more and more reports of organizations who are affected by fraud where payment information sent by e-mail from trusted senders has been modified. The approach is not new, but remains an effective method of stealing both money and goods. Most attacks occur in an Office365 environment, but similar attacks have been noticed in Google Workspace.
The attack is initiated by the attacker gaining access to a users email account, often through a fake login page where the user enters their password in good faith. The attacker uses the password to log in to the victim’s webmail. There, the attacker creates e-mail rules that forward or copy the e-mail communication to an external e-mail address.
In some cases, the rules are based on specific criteria, such as to forward only emails that contain the word “invoice” or “payment”. In some of the attacks that Nimblr has studied, the e-mail does not reach the intended recipient until after the attacker has had the opportunity to modify the content.
Once the insidious email rule is in place, it’s just for the attacker to wait for the right opportunity. By invisibly examining the victim’s communication, the attack can last for a long time, and so when e.g. a delivery address or a payment information is mentioned, the attacker strikes and modifies the details about bank account numbers or the like. Often the attack is not detected until the supplier asks where the payment for a particular order has gone, or when the customer asks for his goods.
As an administrator, it’s a good idea to review the rules that are configured in users email clients. The easiest way is to run a powershell script in an Exchange server or Office 365 instance. The script below lists all users who have forwarding enabled: