Man in the middle attack on email

Man in the middle attack on email Email can be intercepted and read by people you may not want to see what you have sent – This is known as an MITM (man in the middle attack).

 

These MTM attacks can even modify an attachment on your email. If your attachment is an invoice, they may change the Bank account details on your invoice to their own bank details, send on the modified attachment and your customer will pay them and not you!

 

If you receive and email with an invoice to pay, and you have not paid to their account before, before sending payment, phone the sender and check their Account number on the invoice you received matches the
details the sender has.

 

Remember, email and their attachments can be altered by the bad guys along the way, and you could end up paying into the wrong account.

 

With this kind of attack, banks will not refund your money under their internet fraud policies. If incorrect payment does happen, more often than not, the actual sender will still want their payment, so you may end up paying the bill twice.

 

If you need to send sensitive information or attachments, it would be worth considering sending the information or attachments on a secure messaging platform.

 

For example – Signal, Threema, or sending documents or PDF copies of an invoice for example via a secure file transfer service like Transfer Now If you are using iPhone or Mac and are correctly logged into an Apple ID with iMessage turned on and you know the receiver is on iPhone or Mac with their Apple ID setup correctly, then you could send iMessage to iMessage as Apple to Apple uses End to End encryption in Apple messages.

 

Check for blue message bubbles, not green. Blue bubbles are encrypted – IF this sounds all to difficult, go back to Signal! Encryption on Signal is setup for you by default.

 

If email is the only option, consider if your email provider is reputable. We recommend Proton Mail as a secure email provider. Proton emails can be securely encrypted with a password that you will need to tell the receiver.

 

You could phone the receiver and tell them the password, or send them an iMessage text, Signal or Threema message with the password or send them the password on an encrypted transfer service such as Transfer Now So the key here is to stay vigilant with all online transactions and check all details before sending payment to anyone.

 

Finally, if you have been the victim of a MITM attack, we recommend you change the password on your email address and ensure you have two factor authentication setup.

 

Please contact us if you would like more information or to book a time with us to help you on your Cybersafety journey. 

 

Email:   shop@mullummac.com

Web:     https://mullummac.com

 

Ph: 02 6684 6235

 

Return to Main Page