woman sitting at desk working on computer

Webinar: Expose Phony Banking Change Requests

Transcript

Hello everyone, and welcome to today’s webinar, “Don’t Fall for Fake: Expose Phony Bank Account Change Requests Before They Expose You.” Today’s webinar is sponsored by VendorInfo. I’m Mark Brousseau, President of Brousseau Associates, and I’m pleased to be your co-presenter. Joining me is Phil Binkow, Chief Executive Officer of Financial Operations Network, the owner of VendorInfo. 

Thank you, Mark.

Today, businesses are under siege from bad actors attempting cyber attacks and payment fraud. Fraud attacks are at an all-time high, and the way many organizations collect, manage, and verify bank account details from suppliers is leaving them vulnerable. We’ll discuss schemes used to perpetrate fraud, shortcomings of traditional approaches to validating bank account changes, and tools and tweaks to improve your bank account verification process and mitigate fraud risks.

But first, a poll question:

How do you believe your organization’s risk of payment fraud has changed compared to three years ago? Do you think it’s significantly higher, slightly higher, unchanged, significantly lower, or slightly lower? Take a moment to respond, and we’ll discuss the results shortly.

Phil, when talking to accounts payable leaders, what do they say about payment fraud?

Most often, they talk about the time and effort spent verifying bank account ownership information. It’s a tedious but necessary process for every vendor going on EFT, ACH, or wires, and for any vendor making a bank account change.

We asked our attendees about their perceived risk of payment fraud compared to three years ago. 33% believe their organization’s risk of payment fraud is slightly higher, while 38% believe it’s significantly higher, making 71% who feel their risk has increased. Phil, what has accounts payable leaders nervous?

The vulnerability of email systems, especially through business email compromise. Fraudsters get into vendor emails, monitor transactions, and devise ways to divert funds to their accounts. AP departments, as the last control point before cash leaves the company, are rightly concerned.

What does senior management think?

They’re concerned but might not realize the risk’s magnitude. AP leaders prevent fraud through manual efforts, but the events aren’t reaching senior management, making them unaware of the scale.

Let’s do another poll:

How many times has your organization experienced attempted or actual payment fraud within the past year? None, 1-3 times, 4-7 times, 8-11 times, or 12 or more? Take a moment to respond.

Phil, how big is this problem?

The prevalence of attempted frauds is 1-2% of all bank account change requests. The amounts involved range from $50,000 to high six figures, with no sign of slowing down.

We asked how many times attendees’ organizations experienced attempted or actual payment fraud in the past year. 59% reported 1-3 attempts, 23% reported 4-7, and 10% reported 12 or more. The risk is growing. A study by the Institute of Finance and Management found most believe their risk of fraud has increased compared to a few years ago, with 40% experiencing multiple attacks. And 25% of those have faced 12 or more attacks. Fraud is taking a toll. Interpol, the FBI, and States Attorneys General are raising alarms, as remote work has disrupted processes for onboarding suppliers, approving invoices, and more, creating vulnerabilities. 

Phishing schemes are common, including email phishing, business email compromise, and account takeover, where bad actors infiltrate systems and perform malicious actions. Artificial intelligence tools like Worm GBT are also being used to create convincing emails and letters, contributing to a $51 billion loss from BEC attacks since 2013. The average cost per attack is over $5 million, with only 14% recovering all losses. 

The toll extends beyond financial losses to include administrative expenses, regulatory penalties, and even partner dissatisfaction, leading to vendors choosing other clients. This total cost of fraud is crucial when considering mitigation solutions.

We asked another poll: How have the risks associated with your organization’s bank account verification process changed compared to three years ago? 21% said slightly riskier, 17% said significantly riskier, making 38% feeling it’s riskier overall. 17% said unchanged. Phil, what’s the issue with most organizations’ verification methods?

It’s largely manual, involving delays and difficulty finding valid contacts. Even with trusted contacts, convincing them of legitimacy can be challenging, making verification take weeks.

To those who feel their verification process is riskier, Phil advises an automated system for standardization and security, reducing manual intervention and checking against reputable databases.

Only 14% of organizations use automated approaches, while 50% use manual, and 36% use semi-automated, including methods like penny tests, emails, and calls, which are insufficient. Fraudulent bank account information is the greatest risk in vendor onboarding for 71% of AP and procurement leaders surveyed, due to reliance on paper and PDFs, inconsistent manual processes, and limited monitoring.

That’s why more organizations are deploying self-service portals with built-in automated bank account verification, providing real-time checks and comprehensive reporting.

Phil, what do these solutions offer?

A customer-branded portal where vendors complete forms and upload documents, with information verified in real time against databases, including 8 data points associated with bank accounts, as well as tax IDs, addresses, and sanctions lists. This integrates into the organization’s review and approval workflow for consistency, security, and transparency.

Key features include ease of use for vendors, comprehensive verification, real-time results, and integration into workflows. Benefits include time and cost savings, standardization, elimination of manual steps, improved security, and streamlined operations.

To recognize phony change requests, look for urgency, spelling and grammatical errors, issues with logos or letterhead, mismatched bank locations, and non-US date formats.

Phil, what’s the single biggest message you want to leave today?

Automated verification is crucial for security and standardization, reducing manual steps and ensuring transparency.

Now for the Q&A:

Allison asks if this works with global bank accounts. Phil confirms it does, with global verifications on the way.

Gil asks how VendorInfo verifies accounts. It’s connected to a national database updated by banks.

Shelly asks about accuracy. It’s highly accurate, with varying coverage based on the vendor base.

Raj asks about response time and handling phony requests. Responses are instant, with clear visibility on matches and discrepancies.

Rachele asks about OFAC and sanctions screening, which can check frequently and provide visibility into potential discrepancies.

Marlene asks how to get started. Phil suggests contacting VendorInfo to discuss specific needs.

Phil, thanks for sharing your insights. Thank you all for joining us, and we hope to speak with you again soon.

Share This Post