Sydney hospital loses $2 million in alleged BEC fraud
A Sydney hospital lost $2M in a BEC scam. Learn how to protect your business with MFA, email authentication, and robust financial controls.
Scam Awareness Week 2024 is here, with this year’s theme, “Share a story, stop a scam”, emphasising the power of shared experiences in boosting awareness and supporting those affected by fraud. As fraud schemes grow increasingly sophisticated, finance leaders must remain vigilant. Eftsure’s fraud detection data from 2023 reveals concerning trends and highlights real-world scams that targeted finance teams across various sectors. This article outlines practical strategies for avoiding fraud, drawing on insights from Eftsure’s expert fraud detection team.
Between February and April 2023, there was a notable surge in fraudulent activities within the shipping container sector, particularly targeting educational institutions. Eftsure detected four cases of fraud that might have otherwise gone unnoticed. Finance leaders in industries dealing with high-value goods or large transactions should enhance their verification processes and ensure thorough vetting of all vendor details before approving payments.
Pro tip: Implement a payment verification solution like Eftsure to detect unusual patterns and verify supplier details, especially for high-risk transactions. Regularly train your team on the importance of following verification protocols, even under time pressure.
Internal fraud is an increasing concern, as demonstrated by two recent cases where internal actors attempted to bypass verification procedures to authorise payments. Eftsure’s system successfully exposed these attempts, underscoring the importance of robust verification processes as both a detection tool and deterrent.
Pro tip: Strengthen internal controls by enforcing mandatory verification processes for all payments. Regularly audit and monitor staff with access to financial systems, and ensure employees understand that verification processes are non-negotiable safeguards.
From May to July 2023, five cases of fraud were linked to compromised emails from both finance teams and their suppliers. Fraudsters are increasingly targeting both ends of transactions, making fraud detection more complex. A staggering 90% of frauds involved compromised or impersonated emails of finance leaders, such as CFOs and Accounts Payable managers.
Pro tip: Implement advanced email security measures and require employees to use multi-factor authentication (MFA). Regularly update cybersecurity protocols and educate your team about sophisticated phishing schemes that target both internal and external communications.
One in two fraud cases involved fraudsters claiming they were closing bank accounts for “auditing purposes”, attempting to redirect payments to fraudulent accounts. Such excuses should be treated as a potential red flag.
Pro tip: Always verify bank account changes directly with the supplier via a known contact, never through the email or phone number provided in the change request. Implement tools like Eftsure that provide an additional layer of verification for bank account changes.
Eftsure detected two instances of identity theft fraud, showcasing the value of exclusive blacklists. These lists provide finance teams with critical information not typically available, aiding in the identification of fraudulent actors.
Pro tip: Leverage blacklists to screen new suppliers and identify potential risks early. Regularly update and expand these lists to stay ahead of evolving threats.
A Sydney hospital lost $2M in a BEC scam. Learn how to protect your business with MFA, email authentication, and robust financial controls.
CFOs, beware: cybercriminals are exploiting DocuSign’s legitimate business tools to deliver fraudulent invoices directly through trusted channels. This scheme is particularly dangerous …
Because LinkedIn is used as a professional networking platform, account holders don’t use the same caution as they would on Facebook or …
Eftsure provides continuous control monitoring to protect your eft payments. Our multi-factor verification approach protects your organisation from financial loss due to cybercrime, fraud and error.