business e-mail compromise fraud · 2021. 3. 8. · a business email compromise (bec) fraud is an...

2
A business email compromise (BEC) fraud is an online scam where the scammer impersonates a business representative and tricks you into transferring money or sensitive information. We advise you to take note of the following tips so that you protect yourself: The email was unexpected. For example, the invoice came from a supplier you have not dealt with in a while, or the payment amount differs from previous amounts. The email asks for an urgent payment or threatens serious consequences if payment is not made. The email was sent from someone in a position of authority, particularly someone who would not normally send payment requests. The email address does not look quite right. For example, the domain name does not exactly match the supplier’s company name. Doublecheck by looking at previous correspondence. The supplier has provided new bank account details. Teach your team to recognise and deal with phishing attacks as well as to report emails that request any sort of financial transaction. Promote refresher training frequently. eSkills eSkills Malta Foundation www /ESkillsMalta @eSkills_Malta eskills.org.mt Business e-Mail compromise fraud

Upload: others

Post on 14-May-2021

5 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Business e-Mail compromise fraud · 2021. 3. 8. · A business email compromise (BEC) fraud is an online scam where the scammer impersonates a business representative and tricks you

A business email compromise (BEC) fraud is an online scam where the scammer impersonates a business representative and tricks you into transferring money or sensitive information. We advise you to take note of the following tips so that you protect yourself:

The email was unexpected. Forexample, the invoice came from a supplier you have not dealt with in a while, or the payment amount di�ers from previous amounts.

The email asks for an urgent payment or threatens serious consequences if payment is not made.

The email was sent from someone in a position of authority, particularlysomeone who would not normally send payment requests.

The email address does not lookquite right. For example, the domainname does not exactly match thesupplier’s company name. Doublecheckby looking at previous correspondence.

The supplier has provided new bankaccount details.

Teach your team to recognise anddeal with phishing attacks as wellas to report emails that request anysort of �nancial transaction. Promoterefresher training frequently.

eSkillseSkills Malta Foundation

www/ESkillsMalta @eSkills_Malta eskills.org.mt

Business e-Mail compromise fraud

Page 2: Business e-Mail compromise fraud · 2021. 3. 8. · A business email compromise (BEC) fraud is an online scam where the scammer impersonates a business representative and tricks you

eSkillseSkills Malta Foundation

Business e-Mail compromise fraud

Always verify. It always pays tocon�rm details with the partiesinvolved, especially when it comes tomessages that involve fund transfers.

If possible apply impersonation detection protection. This instantly scans all aspects of an email: header, sender, attachments and key words, paying special attention to new domains and external addresses, and establishes controls to thwart look-alike domains.

Instead of clicking on Reply, usethe Forward feature and type in orselect from your contacts list thee-mail address of the person you arereplying to. This is to ensure that youare not replying to a spoofed address.

Use two-factor authentication toverify any change made to accountinformation or wire instructions.

Check the full email address on anymessage and be alert to hyperlinksthat may contain misspellings of theactual domain name.