woman sitting at desk working on computer

Cyber Fraud Risks Rise

Beware Executive Impersonation

Multiple Cyber Techniques Try To Beat Payment Controls

The risk to electronic payments is rising. Cybercriminals now employ multiple technical tools to attack organizations’ payment protocols through business and executive impersonation, with help from artificial intelligence (AI).

Fraud perpetrators use tools including email, SMS text messaging, collaborative meeting applications like Zoom and Microsoft Teams, and AI-generated deep-fake voice and video. AI-generated deep fakes can include persuasive audio and video imitations of CEOs and CFOs. Executive impersonation scams have resulted in several successful payment diversions, some costing millions. But a few simple practices, done consistently, can stop them.

FTC Prohibits Impersonation

The Federal Trade Commission notes that in 2023, it received more than 330,000 reports of business impersonation scams. These scams use all methods available to them for just such impersonations, whether pretending to be the IRS, FBI, the bank, your CEO or a vendor. In response to the alarming increase in such fraud, in March 2024, the FTC implemented a new Trade Regulation Rule on Impersonation of Government and Businesses, prohibiting the impersonation of government, businesses and their officials or agents in interstate commerce.

AI has made deep-fake voice and video impersonation increasingly convincing. Scammers also use AI to generate social-engineering content—persuasive messaging intended to get someone to act on payment instructions, leading to misdirected funds. Such messaging plays on human emotions and intent to do the right thing.

The multiple front threats drive home the need for organizations to deploy a multifaceted defense, including IT screening systems, sound financial controls, data analysis and regular staff training on specific anti-fraud processes and practices.

Organizations must develop solid onboarding and payment processes and consistently follow them. Companies must train and remind employees what to look out for. Staff must consistently follow controls, including verifications and confirmations. Confirmations are vital, and bank account verification is a crucial part and final backstop to perpetrators’ efforts.

Cases

The following are examples of impersonation frauds or attempts.

ARUP: As reported here recently, a finance worker in the Hong Kong office of a renowned international design firm—initially anonymous but recently revealed to be ARUP—was caught off guard by a deep fake, leading to a $25 million loss. The Hong Kong employee was initially skeptical of the email from the company’s UK-based CFO requesting a confidential transaction. But he followed instructions to join a video call. The CFO led the video call, and others whom the staffer recognized were on the call. All agreed on the payments. Seeing is believing, so he made the payments, totaling $25 million in U.S. dollars. But the video conference was a deepfake.

WPP: The largest advertising and public relations firm in the world was the target of a deep fake fraud attempt that utilized deepfake videos and AI voice software to imitate the CEO. The aim was to extract money and information from several executives. Perpetrators set up a Microsoft Teams meeting that supposedly included the CEO and WPP executives. One of the executives and other alert staff were not misled and avoided the fraud.

Sefri-Cime: A couple of years ago, the French property group made several transfers totaling 38 million Euros to various European accounts. In that case, a fraud perpetrator posing as a lawyer had called a firm accountant requesting the payments, saying they were for an acquisition, per the CEO. Then, a fake email arrived, purporting to be from the CEO with confirmation. The accountant found out too late that it was a scam.

Ferrari: An executive at the Italian car maker received a message from CEO Benedetto Vigna instructing him to be ready to move quickly on a confidential acquisition. A few more messages laid the groundwork for expectations. Then, the exec received a phone call, apparently from the CEO. The voice and southern Italian accent sounded right, though the call number was different. The caller explained that the unusual number was due to the confidential nature of the acquisition.

The “CEO” then asked the executive to conduct a currency hedge transaction. The unusual nature of the communications and a slight peculiarity in the sound of the CEO’s voice led the exec to say, with apologies, that he needed to confirm the CEO’s identity. He asked the posing CEO for the name of a book the actual CEO had recently recommended. The caller hung up at that point, and Ferrari dodged the fraud.

Authority, Confidentiality and Urgency Require Scrutiny

While perpetrators use various technologies to execute the fraud, including various phishing techniques, email compromise and deep fakes, they rely on a couple of common factors to manipulate their marks.

They create urgency and insist on confidentiality. The aim is to get the victim to circumvent normal process controls. The perpetrators try to manipulate their targets by appealing to emotions, whether making them feel “in” on a special operation or gaining recognition by the CEO or CFO for efficiently carrying out instructions and “getting it done.”

Protections

If criminals can get a person to act quickly and without hesitation, they’ll win. While many of us think we would not fall for such a scam, we can all be susceptible sometimes. This points to the importance of training. However, according to a report in the Wall Street Journal, training has not proved very effective. More is required. Organizations must create a culture of awareness. But even that isn’t easy to sustain at a high level over time.

Controls are critical, and compensatory controls must be in place in exceptional circumstances. Some practices can save an organization from falling victim.

One grows out of awareness and has effectively stopped fraudsters by asking a question that only the real CEO or CFO would know. To do so takes presence of mind and courage, but what CEO won’t praise you for protecting the organization’s cash? Of course, this works when you know something about the CEO that is not generally known. An executive might. An accounts payable manager might not.

Bank account verification is another crucial practice that can serve as a critical backstop. You can stop misdirected payments by verifying that the bank account to which you are instructed to send funds matches what you have in your records or that the proper owner owns it.

Finance employees cannot rely on their eyes and ears alone. Checks must be carried out in every case, especially when there is urgency. Bank account verification consistently applied—as when automated—is one crucial check.

For information on how VendorInfo’s automated bank account verification can protect you, contact us.

Share This Post