Could One Fake Email Cost Your Business $500,000?

The $500,000 Email: Could One Fake Payment Request Fool Your Business?

The email looks legitimate.

It appears to come from a vendor your company works with regularly. The message explains that their banking information has changed and asks your accounting department to send the next payment to a new account.

The employee follows the instructions.

Days later, the real vendor calls asking why their invoice hasn't been paid.

The money is gone.

This type of fraud, often referred to as business email compromise (BEC) or social engineering fraud, has become a serious risk for organizations of every size. And unlike the image many people have of a cyberattack, criminals don't necessarily need sophisticated software to get inside your business.

Sometimes they simply need one convincing email.

How Business Email Compromise Works

Business email compromise typically involves a criminal impersonating someone the recipient trusts.

That could be your:

  • CEO or business owner
  • Employee
  • Vendor
  • Contractor
  • Accountant
  • Attorney
  • Customer

The criminal may request a wire transfer, change payment instructions, ask for sensitive information, or create a false sense of urgency.

Today's scams can be especially convincing because criminals may research businesses, employees, vendors, and leadership online before making contact.

With AI-generated writing, voice cloning, and other technology becoming more accessible, identifying fraudulent communications based solely on how they "look" or "sound" is becoming increasingly difficult.

Would Your Insurance Cover the Loss?

This is where businesses can encounter an unpleasant surprise.

A business may have cyber insurance, a commercial crime policy, or other coverage and assume any computer-related fraud is automatically protected.

That isn't necessarily the case.

Coverage for social engineering, fraudulent instructions, computer fraud, funds transfer fraud, and cyber incidents can differ significantly depending on the policy and endorsements.

Limits and exclusions can also vary.

Rather than waiting until after money disappears to determine how your policy responds, these exposures should be discussed during your risk assessment.

Your Best Defense May Be a Phone Call

Insurance provides an important financial backstop, but proactive risk mitigation should begin before a transaction occurs.

One of the simplest controls businesses can establish is independent payment verification.

If a vendor emails new banking instructions, don't verify the change by replying to that email.

Instead, call the vendor using a phone number already stored in your records or obtained through a trusted source.

Businesses should also consider procedures such as:

  • Requiring two people to approve large transfers
  • Establishing transaction limits
  • Using multi-factor authentication
  • Training employees to recognize unusual requests
  • Creating written procedures for changing vendor payment information
  • Immediately reporting suspicious activity

A five-minute verification process could prevent a devastating financial loss.

Ask the Question Before You Send the Money

Technology can help protect your business, but cybersecurity isn't solely an IT responsibility.

It's a business risk.

Your accounting procedures, employee training, vendor relationships, cybersecurity controls, and insurance coverage should work together as part of a larger risk-management strategy.

The goal isn't simply to have insurance available after fraud occurs.

The goal is to make your organization harder to fool in the first place.

Could Your Business Spot a Fake Payment Request?

Ask your team this question: If a trusted vendor changed their banking instructions today, what would we do before sending the money?

If the answer isn't clear, you've identified a risk worth addressing.

Contact one of the Risk Advisors at Fortis Risk Group for a comprehensive policy and risk review. We'll help you evaluate your cyber and financial fraud exposures, identify potential insurance gaps, and discuss proactive risk controls that can help protect your business before one fraudulent email becomes an expensive mistake.

Category
blogs and articles

Latest insights and trends

Could an Employee Lawsuit Put Your Business at Risk?

Employment Risk

Is a Certificate of Insurance Enough for Subcontractors?

Contractor Verification

SEO Title: Employees Using AI? 5 Business Risks to Review Now

Ai Exposure

7 Cybersecurity Controls Your Business Should Review

Cyber Readiness

Your Employee Uses Their Own Car for Work. Is Your Business Actually Protected?

Driving Exposure
Join us

Let’s Build Your Protection Strategy

Begin a strategic conversation with advisors committed to understanding and supporting your business.