speaker-photo

Andi Ahmeti

Associate Threat Researcher
Andi Ahmeti is an Associate Threat Researcher on Permiso Security's P0 Labs team. During his time at Permiso he was focused on hunting hunt through product telemetry to identify evilHe’s also the author of CloudGrappler and co-author of CloudConsoleCartographer.Mr. Ahmeti obtained a Bachelor of Science in Computer Engineering from the University of Prishtina Faculty of Computer and Electrical Engineering (2023).

 

15:40 - 16:00

19 September 2025 Talks

Inbox Under Siege: Real-World BEC Attacks, Tactics & Lessons Learned

Business Email Compromise (BEC) remains one of the most lucrative and evolving cyber threats, costing organizations billions annually. This session takes a deep dive into real-world BEC attacks, dissecting the tactics used by adversaries, from social engineering and credential theft to the abuse of inbox rules for stealthy persistence. Attendees will gain insights into how attackers manipulate trust, bypass security measures, and execute fraudulent transactions—often without triggering traditional alerts.

Using real case studies, we’ll explore how inbox rules play a critical role in concealing fraudulent communications, intercepting emails, and evading detection. The session will also cover detection strategies and actionable defenses to help security teams stay ahead of BEC threats.

Whether you're in threat hunting, incident response, or security leadership, this talk will provide practical takeaways to better protect your organization from BEC attacks.