Hawkesbury small businesses are being urged to strengthen their payment procedures after research commissioned by the Australian Banking Association found four in five surveyed small and medium-business respondents had encountered an attempted scam during the previous year.
The warning coincides with Scams Awareness Week, which runs from August 24 to 28 under the theme “No one’s just a number”. (scamwatch.gov.au)
Australian Banking Association chief executive Simon Birmingham said criminals deliberately exploited the time pressures faced by business owners and employees.
“Small businesses are a prime target for scammers, with criminals actively looking to exploit vulnerabilities in everyday systems and processes,” Mr Birmingham said.
“Scammers target small businesses because they know owners and staff are flat out managing competing priorities.”
Fake and altered invoices
One of the principal threats is business email compromise, which can include altered invoices, supplier impersonation and fraudulent payment instructions.
A criminal may gain access to a supplier’s email account, imitate its email address or create a convincing invoice containing the business’s name, logo and ABN. The legitimate payment details are then replaced with an account controlled by the scammer.
In other cases, a criminal may impersonate a business owner or senior employee and direct accounts staff to make an urgent transfer.
Because the business may be expecting the invoice or payment request, the fraud can be difficult to detect. Scamwatch recommends independently checking any change to supplier payment details. (scamwatch.gov.au)
Businesses should telephone the supplier using a number taken from an existing record, previous genuine invoice or official website—not a number contained in the email requesting payment.
Remote-access scams
Criminals may also pretend to represent banks, technology companies or software providers.
They may claim a computer has a security problem or that a bank account has been compromised, then persuade an owner or employee to install remote-access software.
Once connected, the criminal may obtain banking credentials, passwords, customer records and commercially sensitive information. They may also attempt to make payments or conceal their activity behind a false screen.
A legitimate bank will not ask a customer to reveal a password, install remote-access software or transfer money into a supposedly “safe” account.
Anyone receiving an unexpected request for access to a business computer should end the contact and telephone the organisation using a verified number.
Businesses being impersonated
Scammers can also impersonate legitimate businesses to steal money from their customers.
They may create fake websites, email addresses or social-media accounts, or send fraudulent invoices carrying the name and branding of a real business.
Businesses should monitor for unauthorised use of their identity, explain how they normally contact customers and provide a straightforward way to verify invoices and payment details.
Customers should be warned promptly if a business email account or payment system has been compromised.
Confirmation of Payee
Participating banks have introduced Confirmation of Payee, an industry-wide service developed by Australian Payments Plus.
For eligible payments using a BSB and account number, the service compares the account name and number entered by the customer with the details held by the receiving bank. It then provides a match result before payment. (auspayplus.com.au)
A close or non-matching result should prompt the customer to stop and independently verify the recipient.
A matching result does not prove that an unexpected payment request is genuine. Businesses should still verify changes to established arrangements.
Simple controls
Businesses can reduce their exposure by:
- requiring two-person approval for large or unusual payments;
- independently checking changes to supplier banking details;
- restricting who can create payees or alter supplier records;
- using multi-factor authentication;
- keeping computers, phones and security software updated;
- limiting remote access;
- training permanent, casual and temporary employees;
- regularly checking bank accounts; and
- maintaining secure backups.
Urgency, secrecy and instructions to bypass established procedures should be treated as warning signs.
If money has been sent
A business that believes it has transferred money to a scammer should contact its bank immediately. Fast reporting may improve the chance of stopping or recovering the payment.
If remote access was provided, disconnect the affected device from the internet or business network, end the session and obtain assistance from a trusted IT professional. Passwords should be changed from a separate, known-safe device.
The incident should be reported to Scamwatch. Business email compromise, account compromise and other cybercrime should also be reported through ReportCyber. (cyber.gov.au)
Mr Birmingham said banks would continue strengthening their security systems, but businesses remained an important part of their own defence.
“Your best line of defence will always be to stop, check and protect,” he said.
