woman sitting at desk working on computer

Avoiding Phishing Scams: Lessons from the CrowdStrike Incident

Imagine the chaos when a single software update paralyzes systems worldwide. That vision recently became a reality. A significant IT outage caused by a buggy software update from cybersecurity company CrowdStrike recently disrupted Windows computers globally. This event led to delays and closures in various sectors, highlighting the vulnerabilities that cybercriminals quickly exploit.

The CrowdStrike outage was another reminder of the crucial role that accounts payable (AP) professionals play in safeguarding their organizations against cyberattacks. Following the outage, fraudsters launched various scams, including phishing emails and fake websites, attempting to deceive individuals and gain access to sensitive information. The financial and reputational consequences of falling victim to these phishing schemes and other cyber threats can be severe.

This article provides strategies for mitigating the risk of cyberattacks.

“Never Let a Good Crisis Go To Waste”

Cybercriminals are adept at leveraging significant events to deceive people. Following the CrowdStrike outage, fraudsters initiated phishing campaigns and created fake websites to exploit the situation. These websites pretended to offer IT support and solutions for the outage but distributed malware disguised as software updates. Downloading these files installs malicious software on your PC, granting cybercriminals access to sensitive data.

Protecting AP from scams

The CrowdStrike incident reminds AP professionals to be vigilant. Bad actors always seek opportunities to exploit confusion and urgency for nefarious purposes.

Here are some steps to help protect your organization’s financial assets from cyberattacks:

  • Be aware of potential threats. Keep AP staff informed about ongoing threats and urge them to be cautious of any communications. Cybercriminals can use various methods to perpetrate their schemes, so AP staff must maintain heightened awareness.
  • Do not download unverified files. Remind AP staff never to download files or attachments from sources that they do not recognize or to click on any links in emails. If they are unsure about a file, have them consult your organization’s IT department for guidance and solutions.
  • Scrutinize unexpected communications. Ensure staff exercises caution with unforeseen calls, emails, or messages that demand immediate attention, even if they appear to be from trusted parties such as a supplier or an executive within your organization. Cybercriminals often create a sense of urgency to manipulate AP staff into making hasty decisions. Verify the authenticity of such communications through official channels before responding.
  • Validate sources of information. Ensure that any instructions or updates regarding your systems come from trusted and verified sources. Rely on official communications from your organization or directly from the technology provider rather than third-party sources.
  • Report suspicious activity. Instruct staff to immediately report any suspicious websites, emails, or messages. Prompt action can help mitigate risks and prevent further incidents.

Vigilance and skepticism are crucial defenses against cyber threats. Always think critically before clicking on links or downloading files, especially during times of disruption and uncertainty. Doing so can help safeguard your organization’s financial assets from malicious attacks.

Staying secure in a digital world

In our highly interconnected digital environment, IT outages can have widespread impacts. While technology providers work to resolve these issues, cybercriminals can seize the opportunity to exploit the chaos. Encouraging your AP staff to stay informed and cautious and follow cybersecurity best practices is essential to protecting your organization from phishing schemes and other cyberattacks.

Share This Post