This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Executive Exposure: The Not-So-Secret Backdoor into your Organization

Download resources

About this session

Olga Polishchuk and Lewis Shields of ZeroFox's threat analysis and investigations team explain why executives are the easy way into an organisation and what an intelligence-led program does about it. Polishchuk opens with figures from the executives ZeroFox protects: most have had credentials exposed, often in plain text and reused across personal and work accounts, a majority have PII for sale on underground markets, and social media impersonation has surged. Shields adds why leaders are attractive targets: authority to move money, access to intellectual property, time pressure, travel habits, grievances and bragging rights. Together they walk through business email compromise, an AI voice-cloning CEO fraud, a whaling attack that closed a hedge fund, initial access brokers feeding ransomware crews, and the LockBit compromise of a rail operator's managing director. Sanitised cases show how house blueprints, mapping tools, running apps, obituaries and a pet's name reused as a password become reconnaissance material. Their prescription is a strategic intelligence approach: map each executive's footprint, build an attack scenario that answers 'so what', monitor continuously and remediate exposures before they are used.

Enterprise leadership and high-profile employees are frequent targets of threat actors aiming to exfiltrate data, commit fraud, take over their accounts, disseminate false information, or impersonate them. Such forms of malicious
exploitation often lead to initial compromise, can facilitate costly ransomware attacks, and ultimately result in serious operational, financial, and reputational consequences.

ZeroFox discusses several real-world examples of targeting, and through use cases, will highlight the benefits of an intelligence-based security program to reduce your exposure in a world of finite resources, active dark web actors, and a rapidly evolving threat landscape.  

Key takeaways

  • Check whether executives' work and personal credentials appear in breach dumps, especially in plain text, and break password reuse across banking, social media and email.
  • Extend privacy hygiene to spouses and children: family social media, fitness-app routes and obituaries are the reconnaissance sources attackers actually use.
  • Train finance staff that time pressure and a familiar voice are the signature of CEO fraud, including AI-cloned phone calls, and give them a safe way to pause and verify.
  • Run an executive threat assessment that turns the pile of open-source findings into a concrete attack scenario, then decide what to remove and what risk to accept.
  • Make monitoring continuous with real-time alerting; a one-off assessment ages fast because records, leaks and impersonation accounts keep appearing.

Speakers

Olga Polishchuk
Olga Polishchuk
Sr. Director, Analytics & Investigations · ZeroFox
Olga Polishchuk is a security and intelligence professional with over a decade of experience in executive security, open-source intelligence, threat & risk assessments, and a wide array of physical and information security investigations. Olga… Read moreRead less

Olga Polishchuk is a security and intelligence professional with over a decade of experience in executive security, open-source intelligence, threat & risk assessments, and a wide array of physical and information security investigations. Olga serves as the Senior Director in the Tactical Intelligence Operation Unit at ZeroFox, focusing on tactical investigations and threat assessments. In her current position, she acutely focuses on expanding organizations' understanding of the potential and emerging threats and aids in real-time operational and strategic decisions.

Lewis Shields
Lewis Shields
Cyber Threat Analyst · ZeroFox
Lewis joined ZeroFox in 2020 and is based out of London, England. He previously worked for Deloitte and the UK Civil Service, producing strategic analysis for the highest levels of the UK Government and serving as a subject matter expert in the… Read moreRead less

Lewis joined ZeroFox in 2020 and is based out of London, England. He previously worked for Deloitte and the UK Civil Service, producing strategic analysis for the highest levels of the UK Government and serving as a subject matter expert in the Defence and Security space.

Resources

Tags

More from GoSec 2021

Also from Olga Polishchuk

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.