How it happens
There are a variety of methods cybercriminals rely on, ranging from impersonation scams where information is willingly handed over to thieves, to hacking into accounts by guessing passwords or through installed malware. Tim Murphy, Director of Fraud Transaction Monitoring at Wintrust Financial Corporation, explains that while artificial intelligence (AI) helps to make thieves’ tactics more powerful, they’re not necessarily new, and most prevention methods hold true in combating these crimes. “Social engineering is not going away, and AI makes it easier—creating better scripts for criminals,” says Murphy. “AI is the cause of some of the fraud, but it’s the same old tactics that come into play.”
Social engineering
Whether through impersonations, phishing, or texting scams, cybercriminals pretend to be from credible institutions to persuade people into revealing compromising information. Thieves thrive on the ability to rush or scare people into action.
Murphy explains that cybercriminals use a variety of tactics, such as pretending to be your bank, the government, or a company you work with, or asking if you’ve made a specific transaction they’ve created. When you inevitably don’t recognize this transaction, it’s easy to be caught off guard. Often, this is the point where you’ll be asked for your username and password or to share a one-time passcode.
“When you receive an impersonation call, these cybercriminals instill fear and anxiety by making you believe you’re going to lose something,” explains Murphy. “Then they’re right there to ‘help’ fix their manufactured panic.”
Murphy continued, “I try to coach people using a three-step process: pause, think, and verify. Don’t just react. If you didn’t initiate the call, hang up and call your bank directly.”
Social engineering doesn’t always initially involve rushing. Sometimes, even a seemingly harmless question can help unlock key information. Scammers harvest this information and play the long game, continuing to uncover more and more information, building bit by bit. For instance, a scammer may call and pose as a salesperson, asking whom you use as a vendor for a specific service and pretending to have a more competitive offer. What seems like an innocuous answer helps them down the road when they pose as that service provider and send a phony invoice, possibly gaining important account credentials.
Credential stuffing
This is where strong passwords—and updating passwords—come into play. Thieves systematically test passwords for specific usernames and oftentimes can successfully log in to accounts. Recently, AI has been used to decode credentials based on personally identifiable information.
For instance, with a phone number, email address, and mother’s maiden name, a hacker could generate a username, then spoof the phone number to receive a verification code and use the mother’s maiden name as an answer to a security question. Business bankers working with security advisors offer guidance with multi-layered security defense controls to combat these types of fraudulent attempts.
Data breaches
Data breaches allow thieves access to customer information, which then gives them better luck at credential stuffing or social engineering. Now they don’t even need to pose as a competitor to your current vendor to discover who your vendor is; that information has already been uncovered. Thieves will take this information and build fake websites, pose as tech support, mimic a financial institution—the list goes on.
Malicious software
Text, emails, and freeware can all be infected with malicious software that captures keystrokes to steal usernames and passwords. Never click on an unexpected link or attachment.
Dumpster diving
In the digital age, this may seem like an outdated form of theft, but thieves still search for sensitive documents that haven’t been shredded. This information can then be used to log into online accounts.
What can you do?
Take a proactive approach. Provide your staff with training, and not just the staff handling books. Remember, scammers often play the long game through social engineering tactics, and any employee can play a role in accidentally helping them to uncover pertinent information.
“Social engineering training that involves simulated phishing examples can provide excellent coaching for employees,” says Murphy. “People get tired of hearing about social engineering until they get hit.”
Fraud awareness training is linked to faster detection and lower losses. The Association of Certified Fraud Examiners (ACFE) notes that organizations that did not provide training lost nearly twice the amount of money.
“It’s so important for businesses to educate themselves on regulations—particularly Regulation E and the lack of protection for businesses—and to know the difference between a push and pull payment,” says Brian Mivelli, Vice President, Senior Manager Fraud Investigation at Wintrust Financial Corporation.
Push payments are initiated by the sender, who is essentially “pushing” the payment through, controlling the amount and timing, whereas pull payments occur through automated systems for recurring payments, initiated by the recipient who is “pulling” funds after receiving prior authorization. Think ACH direct debits, recurring subscriptions, monthly memberships, etc.
“You’ll also want to make sure you’re taking advantage of the security resources offered by your bank’s Treasury Management department.” Dual control, ACH origination—these types of tools can help protect your company.
“When you’re making payments, security needs to come before convenience,” says Murphy. “Having dual authentication is key—one person originates the payment, someone else confirms that payment.”
Wintrust offers robust i-BusinessBanking®1 products, with an online treasury management system2 designed for businesses to manage cash flow, payments, and account services. Resources include Positive Pay and Reverse Positive Pay to stay ahead of fraudulent checks, as well as ACH Positive Pay, an automated bank fraud detection service that allows businesses to review and either approve or reject incoming ACH (Automated Clearing House) debits before they clear the account. Companies can proactively block unauthorized ACH transactions by establishing authorized vendor lists and setting filtering criteria (like dollar limits or frequency).
With sophisticated business banking solutions and a dedicated team of experts supporting your account, we can help you keep your business safe. “Wintrust really provides white-glove service, with bankers calling about unusual business payments or a change in historical payment accounts,” says Mivelli. “You’ll know exactly who you’re working with and can call your banker directly if you’re ever concerned about an unexpected transaction.”