Instagram star defrauded over a billion zlotys!
Ramon Olorunwa Abbas, an Instagram star with 2.3 million followers, has been accused of participating in a cybercriminal group that allegedly defrauded companies worldwide of the equivalent of over a billion zlotys. The criminals used email and employees' gullibility to carry out their scams. The frauds could have been prevented if employees of the targeted companies had previously undergone basic IT security training – emphasizes Justyna Puchała from the company DAGMA.
Ramon Olorunwa Abbas, also known on Instagram as Hushpuppi, has been extradited to the US. Within the next few weeks, the influencer will stand trial in Los Angeles on charges of participating in frauds totaling several hundred million dollars. According to the FBI, Abbas was allegedly part of a group organizing so-called BEC attacks. This is a type of fraud in which criminals use real, stolen email accounts of an organization to extort money and data from its employees or contractors.
- A typical example of a BEC attack is a situation in which we receive an email supposedly from one of our contractors, demanding payment of an overdue invoice – obviously fake – and transferring money to a substituted bank account. Criminals are equally eager to impersonate superiors or employees of law firms – describes Justyna Puchała, manager of the Authorized Training Center DAGMA.
The scale of Hushpuppi's frauds
In the case of the charges against Abbas, however, the gigantic scale of the frauds draws attention. His group is credited with, among other things, stealing 100 million dollars from one of the football clubs belonging to the English Premier League. In another attack, they allegedly defrauded as much as 200 million dollars from an anonymous company based in Edinburgh.
How was the influencer caught?
Abbas's arrest was reportedly facilitated by his activity on social media, where he operates under the pseudonym Hushpuppi. On an iPhone belonging to one of the members of his group, messages were found about a planned attack, sent to contacts described as "Hush" and "hushpuppi5". Following this lead, the FBI obtained from the owners of various internet platforms, including Instagram, Snapchat, and Apple, data enabling the determination of Abbas's true identity and allowing him to be linked to the crimes he is accused of.
An underestimated threat that can ruin a company
How did an Instagram star defraud billions through BEC attacks?
As Justyna Puchała from ACS DAGMA points out, Abbas's arrest is a big success, but by no means is it a remedy for the broader phenomenon of BEC attacks. It is still a very serious and widespread threat that does not enjoy as much popularity in the media as, for example, ransomware, and which can cause gigantic damage to a company, primarily financial.
- For many people, a cyberattack is associated with viruses, password cracking, or searching for vulnerabilities in network security. Not everyone is aware that cybercriminals do not necessarily have to break in anywhere, and their most effective weapon often turns out to be simple social engineering tricks. It is precisely because of this lack of awareness of threats like BEC attacks that they remain so widespread, and at the same time so dangerous – explains Justyna Puchała from the Authorized Training Center DAGMA.
According to the expert, the most effective way to protect against BEC attacks is to educate employees about the basic principles of cybersecurity, so that they can recognize an attempted fraud and not fall for the tricks used by cybercriminals. This type of information is provided, among others, as part of the series of training courses 'Teleinformation Security for Office Employees' organized by ACS DAGMA. In addition, however, one should not forget to use antivirus software or data leak protection (DLP) solutions from proven vendors such as ESET or Safetica. Such tools alone will not protect a company from an attempted fraud, but they can significantly reduce its negative consequences.
Summary
Ramon Olorunwa Abbas, known on Instagram as Hushpuppi, has been accused of participating in a cybercriminal group that defrauded companies of the equivalent of over a billion zlotys, mainly through BEC attacks. The scale of the crimes included, among other things, the theft of 100 million dollars from a Premier League club and 200 million from a company in Edinburgh. Abbas's arrest was facilitated by his social media activity and data obtained from Instagram, Snapchat, and Apple. Experts, such as Justyna Puchała from ACS DAGMA, emphasize that the key protection against such frauds is employee education in cybersecurity and the use of antivirus and DLP tools from proven vendors.