Skip to content
City PM
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
Thursday 04 October 2018 3:21 pm  |  Updated:  Tuesday 21 May 2019 4:24 pm

UK business emails could represent a major cyber security flaw

NULL

Business emails could represent a major security flaw for UK companies, after it was revealed millions of account details are openly available for purchase through criminal networks and on the dark web.

The financial details of almost 5,000 UK companies were found to be exposed in third party breaches and sit within criminal forums, including email addresses and matching passwords, research from cybersecurity firm Digital Shadows will today reveal.

Poor security practices such as not updating back ups have left over 12m email archives, including entire company inboxes, available to buy on networks. Analysts also discovered that sensitive information was freely available via a stockpile of 27,000 invoices, 7,000 purchase orders and 21,000 payment records.

Email addresses for finance departments were particularly targeted, with more than 33,000 emails listed on networks. Such credentials are considered as highly valuable, with one email address and password set fetching $5,000 (£3,843).

Read more: Fewer than one in five households protect cyber security of smart devices

Recent research from the FBI suggested scams resulting from business email compromise, such as fake invoices, have cost businesses $12bn globally over the last five years.

Digital Shadows executive Rick Holland warned it is relatively easy for cybercriminals to find whole inboxes and accounting credentials, and in some cases, bidders actively request them. 

"Phishing continues to be a very serious problem associated with business email compromise but unfortunately, we discovered that is far from the only risk, especially as barriers to entry for this type of fraud are coming down," Holland explained. 

"Millions of companies are already exposed through misconfiguration issues or finance department emails and passwords circulating online."

"Organisations can never mitigate these issues entirely; however, it is within their power to at least tighten up on their own processes to ensure that their data exposure is kept to a minimum."

 

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech

Related Topics

  • Cybercrime

Trending Articles

  • Top Burnham adviser calls for capital gains and inheritance tax hikes

  • A meeting with the breakfast king of Mayfair

  • Clarkson’s Farm and why businesses must stop blaming the weather

  • As it happened: Supreme Court blocks Trump sacking; Andy Burnham vows ‘greater public control’; Comcast spin-off

  • BT tops FTSE 100 after finding new home for international business with Verizon joint venture

More from City PM

  • Gambit Cyber Launches Vizier AI – An Autonomous Security Intelligence Workspace for Continuous Exposure Management

    Business Wire
  • Airspan Networks Joins Oramach and iVent’s ARES Consortium for European Mission-Critical Communications

    Business Wire
  • £4.5bn black market cigarette tax loss should be ‘a major wake-up call’ for Labour

    Tax
    Getty Images logo displayed on a digital screen, symbolizing media and content licensing in a business context
  • Beyond the ‘Dumb Pipe’: How Agentic AI and Sovereign Networks Are Redefining Connectivity

    Business Wire
  • Britain’s first sovereign AI model secures blue-chip backing as Starmer unveils £400m plan

    Tech
    Prime Minister Keir Starmer addressing media at a press conference podium, discussing current governmental policies and in...
  • ‘Safe’ version of Anthropic’s Mythos model hits market

    Tech
    Anthropics AI technology showcased at a tech conference, highlighting innovative advancements in artificial intelligence
  • Catalytic capital is the next phase in philanthropy

    Opinion
    Corporate philanthropy concept with diverse professionals collaborating on sustainable, long-term global health solutions
  • FEINDEF 27 Accelerates Commercialisation, Surpassing FEINDEF 25’s Total Exhibition Area by 25% With One Year to Go

    Business Wire

City PM — European politics, business and analysis.

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Topics

  • Business
  • Markets
  • AI
  • Technology
  • Opinion
  • Energy

More

  • Politics
  • Economics
  • Fintech
  • Legal
  • Sport
  • Life

Company

  • About City PM
  • Editorial Policy
  • Corrections
  • Contact
  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 City PM · Published by CityPM Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
About · Editorial Policy · Corrections · Contact · Privacy