Search

Is Your Business Prepared? 6 Low-Cost Ways to Help Protect Your Business from Fraud Risks

March is Fraud Prevention Month, offering the perfect opportunity to catch up on the latest in fraud trends, tactics and prevention tips that can help keep businesses safe.
email fraud

In a recent conversation, Michael Argast, co-founder and CEO of Kobalt.io offers a snapshot of the current fraud landscape, a review of how Canadian businesses are faring and easy-to-implement measures that can go a long way toward protecting your business from today’s biggest threats.

Today’s trends in business fraud

The most common fraud attacks in play today are largely not new. Rather, fraud tactics have evolved in step with technology and in response to business’ enhanced vigilance and prevention processes. Here are the top trends in business fraud:

    1. Business Email Compromise (BEC): Business Email Compromise is when a fraudster attempts to trick a financial decision-maker into transferring funds or revealing sensitive data that can in turn lead to financial losses. “BEC is no longer new, but it definitely continues to be one of the underlying trends over the last 12 months,” Argast explains. He adds that losses tend to fall within the $100,000 – $250,000 range, representing a major hit to a SME’s bottom line.

    2. Commercialization of AI: There have been a few high-profile incidents in the news this past year, where Artificial Intelligence (AI) was used to impersonate a senior executive, resulting in significant financial losses. Perhaps most notably was when an employee of a Hong Kong company received a request from their Chief Financial Officer to make a confidential transaction. During a follow-up video call, an AI-generated deepfake of the CFO validated the transaction, which resulted in the firm losing more than $25 million USD.

      While small and medium-sized business owners may think they’re not targets for sophisticated attacks, AI tools have made it easier for fraudsters to go after more businesses, including smaller ones. “Sophisticated mechanisms are cheap enough and available enough that it has become easy for cyber criminals to impersonate executives. There is definitely a rise in the use of these more sophisticated tools by intermediate-level fraud actors,” says Argast.

    3. Insider fraud: While insider fraud is nothing new, Argast explains that during challenging financial times, there tends to be an uptick in financial misconduct. “We don’t see any slowdown in insider fraud – things that have always been an issue continue to be an issue,” he says. “But in tough financial periods, we tend to see more of it. And, many organizations don’t always followed best practices because as they get busier, it’s easier to rely on one or two key individuals to handle their financial transactions – this creates an environment where fraud is more likely to occur.”

    4. MFA phishing: Here’s the good news: Argast has noted that roughly 80 percent of Canadian organizations are using Multi-Factor Authentication (MFA) – a security process that requires users to provide two or more verification factors to access an account or system. Now for the bad news: While MFA is a strong security control, it is not the silver bullet many businesses may believe it to be. “It is important for employees and users to understand that Multi-Factor Authentication can be phished. While it reduces the risk of being compromised, attackers can phish those credentials at the same time as they collect your username and password, which allows them to get in through the back door,” cautions Argast.

Read on our interview with RBC