Help Center
How to Handle Suspicious Accounts in the Company Contacts?
[TOC]

I. What are Suspicious Accounts?

Suspicious accounts refer to accounts where bad actors gain access to the organizational structure due to the company’s poor management, or account members have weak security awareness and are compromised by bad actors. When suspicious accounts exist in the company Contacts, company information may be leaked, and members and customers may fall victim to fraud. In serious cases, the company and its administrators shall also bear legal liability.

II. How Do Suspicious Accounts Enter the Company?

1. Poor company management leading to bad actors infiltrating the organizational structure

● The company allows members to invite others to join the Contacts, but some members may accidentally invite external individuals with unknown identities, creating security risks.

● The company has developed an externally accessible mini program/webpage. After members submit their details and the company verifies and approves them, the system calls the API to add them to the organizational structure. However, if the identity verification mechanism is too simplistic or contains vulnerabilities, malicious actors may gain unauthorized access. For example, simply entering a name, mobile number and employee ID is enough to join the company.

2. Weak security awareness of members leading to account compromise

● Criminals, dressed in work uniforms, enter the company’s office premises claiming to be from a company doing field marketing or map annotation for a mapping service. They ask to borrow employees’ mobiles to perform operations - highly deceptive. In reality, they aim to obtain users’ mobile numbers and verification codes to complete new device verification and log into WeCom.

● In crowded places like colleges and universities, companies, or subways, criminals lure users under the guise of “completing tasks” or “receiving gifts” to scan untrusted QR codes - with the aim of stealing member accounts. When a user scans a QR code, they will authorize the other party to log in to their WeCom accounts.

3. After malicious actors gain access to the company, they may further deceive administrators into granting them administrative permissions

● Malicious actors may forge chat history and use tactics such as falsely claiming that their workspace is malfunctioning and requesting a “super administrator” to scan a QR code to assist them or to grant them “administrator” permissions. The administrator failed to verify the identities of suspicious members and shared the Admin Console SMS verification code after scanning a QR code for access. As a result, attackers compromised the super administrator account and gained control of the Admin Console.

III. Review and Handle Suspicious Accounts

When the company has suspicious members, the WeCom Security Team will ban or disable these accounts and send security alerts to the company’s super admin. When you receive these alerts, you should promptly investigate the suspicious accounts.

1. View accounts of infiltrated bad actors

● For suspicious accounts that have been identified and banned by the platform, you can filter the operation type as “Login blocked” in [Admin Console -> Security and Management -> Management Tools -> Usage Analytics -> Member Operation Records] to view the banned accounts

● For suspicious accounts that have been identified and disabled by the platform, you can filter for “Disabled” members in [Admin Console -> Contacts -> Structure]

2. View accounts at risk of hijacking

Administrators can filter records with operation types “New Device Login”, “Log in to the secondary device”, or “Locked Device” in [Admin Console -> Security and Management -> Management Tools -> Usage Analytics -> Member Operation Records] to investigate if members have logged in on a new device and if accounts have been compromised.

3. Addressing risks posed by suspicious accounts

After the company’s super administrator receives a suspicious account notification from the WeCom security team, they should promptly verify whether the account is being used by a member of the company. If an account is confirmed to have issues, it must be immediately disabled or deleted. At the same time, investigate the channel through which the account entered the organizational structure, and check whether its inviter, the approving administrator, and the operator who modified the information pose any security risks. And take back unnecessary and irrelevant administrator permissions within the company.

● Investigate the channel through which suspicious accounts entered the organizational structure

Determine whether the suspicious account was invited by a colleague, imported by an administrator, or imported via API, and investigate whether the corresponding channel has any issues.
If it was invited by a colleague, confirm whether the “Join the company requires administrator approval” option is enabled, and verify whether the inviting member poses any risk;
If it was imported by an administrator, investigate whether the corresponding administrator poses any risk;
If it was imported via API, investigate whether the Contacts API permissions have been leaked, or whether the system using the API has been compromised;

● Investigate administrators with potential risks within the company

The inviter of the suspicious account, the approving administrator, and the operator who modified the information must all be verified to determine whether they are genuine company administrators

And investigate whether recent Admin Console operations by these administrators were performed by themselves, and roll back their risky operations

● Re-verify the consistency between the WeCom organizational structure and the company HR system, and remove personnel who do not meet expectations

IV. Reduce the Risk of the Company Being Exploited by Malicious Actors

The purpose of malicious actors taking control of company accounts is to profit. Possible channels of profit may include:
● Obtaining confidential company information and selling it or using it for extortion to profit;
● Sending fraudulent messages (e.g., government subsidies) to colleagues or customers of the company, tricking them into transferring money to profit;
● Leveraging the company’s identity as endorsement, tricking victims into adding them as friends to commit fraud and profit;
It is not the thief we fear, but the thief’s intent. By strengthening verification for accessing the company’s Contacts and blocking the channels through which malicious actors profit, the value they can extract from the company will decrease, and the company’s security will be ensured.

1. Enable the “Join Company Approval” feature to reduce the risk of malicious actors joining the company’s Contacts through channels that bypass approval

Enable administrator approval for members joining the company in the Admin Console; Access path: [Admin Console -> My Company -> Join Application Settings].

Member join request and approval path: [Admin Console -> Security and Management -> Management Tools -> Add Members]

2. Regularly audit the usage of “Company APIs” to reduce the risk of malicious actors entering the company’s Contacts via APIs

● Regularly review all records of “API-managed Contacts” to ensure all actions align with expectations. Otherwise, it is recommended to periodically rotate the Secret Key. Setting path: [Admin Console -> Application Management -> Custom Apps -> Edit -> Re-acquire].
● To ensure the security of the company’s Contacts, strict identity verification must be performed when adding new members via API. Recently, some companies were found to have experienced malicious account intrusions into their Contacts due to weak authentication, posing serious security risks. Please be sure to take the following measures and only write to the Contacts after confirming everything is correct:
○ Real-name verification via mobile number;
○ Liveness detection or face recognition;
○ Employee identity verification in conjunction with the company HR system;

3. Assign internal and external communication permissions as needed to block malicious actors from exploiting company member identities to carry out harm

This includes, but is not limited to, permission control for the following scenarios
(1) Permission to view company Contacts
Setting path: [Admin Console -> Contacts -> Contacts Management].

(2) External communication permission settings
Grant only to members who need it (if not set by default, all members will have external communication permission).
Setting path: [Admin Console -> My Company -> External Communication Management].

(3) Configure Contact Customers permissions as needed
Setting path: [Admin Console -> Customers and Partner Space -> Contact Customers -> Permission Settings].

(4) WeChat customer service usage permissions
Review the usage of “WeCom Customer Service”, delete customer service accounts that do not meet expectations, and assign WeCom Customer Service usage permissions as needed. If the company does not actually use “WeCom Customer Service”, it is recommended to disable the relevant features.

(5) Partner Space usage permissions
Review how the company’s Partner Space feature is used, and assign permissions for using, creating, and joining Partner Spaces to employees as required.

4. Strengthen security awareness for administrator and member accounts

● When receiving a request to lift an “abnormal status,” first verify the member’s identity. Do not easily scan QR codes, click risky links, or provide SMS verification codes.

● When malicious actors wearing work uniforms enter the company office premises or retail stores, claiming to be doing promotional activities or marking locations on a certain map, and ask to borrow an employee’s phone to operate, or request members to help complete verifications such as scanning QR codes or face recognition, do not assist malicious actors in completing the above verifications, as this may lead to the theft of member accounts.