The shortest useful page we can write about email fraud. Three moves, for any office that moves money, in any industry.
1. Verify money instructions on a different channel
Any message that tells you where to send money, or changes where it was going, gets checked on a second channel before anyone acts on it. If it came by email, pick up the phone. If it came by phone, write to the address in your records, or walk down the hall. Use a number you already had, from your files, from before today; a number supplied by the message answers to whoever wrote the message. Familiar names get checked too, because looking familiar is the whole trick. Your IT provider may call this out-of-band verification. You can call it the phone call.
2. MFA on email, no exceptions
Every mailbox gets multi-factor authentication, so that a password by itself opens nothing. Email is where the money conversations live, and passwords leak without ceremony and without notice. The exceptions list is the weak point: the owner who found the prompts annoying, the shared inbox nobody got around to, the assistant who signs in as the boss. An attacker doesn’t need every mailbox in the building. One is plenty.
3. Slow the money down
No single person should be able to add a payee, change an account number, and release a payment alone. Put a second person on every change to where money goes. Keep the rule when things get busy, especially when things get busy, because fraud is built for speed and for one rushed approver. A second reader an hour later catches what the first one was hurried past.
Do all three this month.
If you want a hand putting them in place, ask us.