TeamSystem, one of the main Italian suppliers of management software for companies, has communicated to its customers that it has suffered unauthorized access which affected the Cloud Accounting service, with the consequent theft of personal data present in the software. In the email sent to customers, the company talks about “a sophisticated cybersecurity incident” that led to unauthorized access and exfiltration of personal data, including personal details, bank details, emails and telephone numbers.
What data ended up in the hands of hackers
Interviewed by Adnkronos, the National Cybersecurity Agency (ACN) clarified that the attack suffered by TeamSystem should not affect private citizens and that only companies that use the company’s products could be affected. According to what was specified by the ACN experts, the stolen information falls into three types, namely personal data, contact details and bank details (IBAN), together with data on customers’ accounting operations.
As for the consequences, the concrete danger is limited to possible phishing campaigns aimed above all at financial scams, such as the so-called “IBAN swapping“, i.e. the fraudulent replacement of bank details. At the moment, however, the company has not disclosed the flaw exploited for the intrusion, nor the amount of data stolen or the number of subjects involved. Furthermore, there are no ransom requests or claims. According to the company’s official communication, the users’ credentials and passwords would not have been compromised.
Why a stolen IBAN could be a problem
Ranieri Razzante, university professor and cybercrime expert, spoke on the extent of the episode, again through Adnkronos, according to which the attack is serious precisely because it hit a leading company in the Italian IT sector and structured on the cybersecurity front.
According to Razzante, «Hackers are often helped by the imprudent behavior of the victims or by the lack of attention to security measures data protection. In the case in question, then, with the IBANs and personal data that appear to have been stolen, the recommendation to the holders is to be very careful about bank movements these days and, if there are cards, to block suspicious payments”.
Having got your hands on the IBAN and the history of accounting operations opens up scenarios that are anything but reassuring. Those who know in detail how business relationships between two or more companies work, from the frequency with which invoices are paid to the type of services provided, have everything they need to enter into those relationships with tailor-made messages, with the aim of persuading one of the parties involved to pay the fee for the next consultancy, or the next audit, to different bank details than usual, which in reality belong to the scammers and no longer to the supplier companies.
What are the risks ofEmail Compromise
Last February, CSIRT Italia, the structure of the National Cybersecurity Agency that monitors cyber threats, issued an alert on precisely this type of fraud, known as Business Email Compromise. What emerges from the note is that «once access to the compromised mailbox has been obtained, the malicious actors do not act immediately, but view the conversations to identify any pending commercial exchanges. Exploiting this context, they resort to techniques of Email Thread Hijackingentering into legitimate dialogues between the organization and its customers or partners.”
And once a new lookalike domain has been exploited, «the attacker proceeds to set up an email account with which he pretends to be an employee of the compromised organization. Through this address, he sends a legitimate customer of the company a fraudulent communication requesting the balance of an apparently pending invoice, but indicating new bank details (IBAN) controlled by the attacker.”
How to defend yourself from this type of cyber threat
The countermeasures indicated by the Agency specifically specify not to access internet links or related external content if you are not certain of the reliability of the resource, ensure the legitimacy of the sites that require the insertion of your access data, provide for the immediate rotation of access credentials for all users involved or suspected, ensuring the adoption of adequate complexity criteria in line with current security policies.
At the same time, it is essential to implement strong authentication mechanisms to protect all email accounts, so as to mitigate the risk deriving from the compromise of passwords alone: in these cases, it should always be remembered that in the event of any anomalous request, an out-of-band verification procedure must be adopted, i.e. a check through a channel different from the one through which the request arrived, such as a direct phone call to the supplier or to an already known number, and not to the one indicated in the message.








