A story of email fraud
We received an email from an existing client authorizing a payment by wire to one of their vendors and including wire instructions. The wire request was for a large amount, but not out of the ordinary for that organization ($1.4 million). The body of the emailed wire request showed a trail of emails below it, showing the conversation between our client and the vendor about a project they were working on. We recognized the other employees of our client’s business in the email conversation and we recognized the project they were working on.
As is protocol for wire payments, we called the client to confirm the wire, using the phone number that we have on file for our client. Come to find out, the client did not authorize this wire payment, knew nothing about it.
Upon investigation, we discovered that our client did not actually send that email to us. The sender’s email address was very similar to our client’s email address; the only difference was that the criminal had added one letter to the domain name. It was barely noticeable.
Furthermore, they had tapped into this business’ secure email account. They were able to determine our email account as the appropriate recipient to send wire requests. And they were able to access actual email conversations with real employee names, email addresses, and the valid project names, which they used to forward to us to add credibility to the request.
From this story, you can see the extents that criminals go to commit email fraud, also known as Business Email Compromise (BEC).
What can you do about email fraud?
Of course, having proper security in place to help prevent security breaches in the first place is important to prevent becoming a victim of email fraud. Further, having systems and procedures in place to confirm wire payments is essential, if a security breach does occur. It’s important to take a holistic approach at the situation and ensure you’re as well protected from email fraud as possible.
W’d love to offer you an accounting system review to see where there may be cracks in your accounting system that could be exposing you to potential fraud in your organization. You can schedule an appointment here.
Related Posts on Redmond Accounting CA
-
A case of check fraudA case of check fraud We will periodically post summaries of our experiences with other small businesses in an effort to share problems and solutions and learn from each other. The Problem: A growing company with 50+ employees suddenly discovered that they were the victims of check fraud. The on-staff bookkeeper had forged the principal's signature on several checks made payable to…
5 Ways Your Accountant Can Help You Prevent Fraud5 Ways Your Accountant Can Help You Prevent Fraud Has your business been a victim of fraud? A couple of years ago, a cloud accounting client forwarded us an email that they had just received from a Police Officer in another state. That police department was investigating a check that an individual was trying to cash that was…
Case Study: Employee Fraud Happens. 2 Things To Avoid ItUnfortunately, employee fraud happens. One day we got a call from a business that had been referred to us. They were a growing company with 50+ employees. They needed a new accounting department. It was urgent, they said. Their employee bookkeeper had just quit the last day of the month. One of her duties was printing the checks for the…
-
New Year, New YouNew Year, New You These last few weeks of the year are the perfect time to implement improvements in your business processes so you can start the new year on the right foot. Move to QuickBooks Online to leverage improved access and integration Automate data entry with bank feeds Go paperless with your bill pay process Take the hassle out…
-
Connecting Apps with ZapierConnecting Apps with Zapier There’s so much information circulating at our fingertips via social media, email and push notifications. I can’t possibly read all the articles I’m interested in and still get all my work done. When I see an article or website that I want to read when I don’t have time, I click the Zap extension on my browser.…
-
$2 Tip$2 Tip Check fraud is a very real threat that can cripple a small business. 70% of organizations experienced check fraud last year. We've helped victims of it strengthen their security protocols. Common check fraud techniques include photocopying valid checks to deposit multiple times, creating fraudulent checks with stolen bank account information, and soaking stolen checks in chemical washes to…
-
RAI wins top award!RAI wins top award! Last week we were awarded Top Client Accounting Services ProAdvisor by Insightful Accountant (IA). IA is an industry news organization. Their annual awards are announced each year at the Scaling New Heights accounting technology conference, an internationally-renowned, in-depth training conference for accountants and other small business advisors. The first year IA awarded these titles in 2014,…