Business Fraud 101
Fraud is an ongoing risk for businesses of every size. As more payments, banking activity, invoices, and day-to-day business operations move online, criminals have more opportunities to target businesses through email, compromised credentials, fraudulent payments, and other common scams.
One of the most important things we encourage business owners to remember is that fraud prevention works best in layers. Technology can help, but strong internal processes, employee awareness, and careful oversight of your accounts are just as important.
Understanding where your business may be vulnerable is a good place to start.
Common Types of Business Fraud
Business Email Compromise
Business email compromise occurs when a fraudster impersonates someone your employees trust, such as an executive, vendor, client, or other business partner. They may request an urgent wire transfer, ask that payment instructions be changed, or provide new account information for an invoice.
These messages can be convincing because fraudsters may imitate a legitimate email address, writing style, or existing business relationship. A simple verification process can make a significant difference. Before changing payment instructions or sending money based on an email request, confirm the request using a trusted phone number or another communication method you already have on file.
Check Fraud
Checks remain a target for fraud. Fraudsters may steal legitimate checks, alter the payee or dollar amount, create counterfeit checks using a business's account information, or attempt to deposit the same check more than once.
Businesses that issue a significant number of checks should regularly review account activity and consider tools such as Positive Pay designed to help identify potentially unauthorized transactions before they are paid.
ACH and Wire Fraud
Electronic payments make it easier for businesses to move money efficiently, but they can also create significant exposure if login credentials or payment instructions are compromised. Fraudsters may attempt to gain access to business online banking, convince an employee to initiate a payment, or provide fraudulent account information.
Because electronic payments can move quickly, prevention is especially important. Limiting payment permissions, requiring additional approval for certain transactions, and reviewing activity regularly can all help reduce risk. Within Baker Boyer’s Online Banking platform, we have many tools within our AACH origination services that can better help protect your accounts from ACH fraud such as special alerts, dual controls or notifications that you can set up.
Phishing and Credential Theft
Phishing messages are designed to trick employees into clicking a malicious link, opening an attachment, or providing login credentials.
These attacks may appear to come from a bank, software provider, delivery company, coworker, or other familiar organization. Once credentials are compromised, criminals may use them to access email, financial accounts, or other business systems. Employees should be cautious with unexpected login requests and navigate directly to trusted websites rather than using links in unsolicited messages.
Invoice and Vendor Fraud
Fraudsters may impersonate a legitimate vendor and tell your business that its banking information has changed. If the change is accepted without independent verification, future payments could be redirected to an account controlled by the criminal.
Establish a standard process for changes to vendor payment information. Whenever possible, verify the change directly with a known contact using information already on file rather than contact information included in the request.
Card and Online Payment Fraud
Businesses that accept card payments may also encounter stolen cards, fraudulent online purchases, card testing, or chargeback abuse.
Watch for unusual purchasing patterns, repeated declined transactions, inconsistent billing and shipping information, or multiple transactions using different cards but the same customer information. Payment processors may also offer verification and fraud-monitoring tools that can provide an additional layer of protection.
Warning Signs to Watch For
Fraud does not always look the same, but certain activity should prompt a closer look.
Be cautious when you encounter unexpected or unusually urgent payment requests, sudden changes to vendor banking information, payments that fall outside a client's or vendor's normal pattern, multiple failed login or payment attempts, unfamiliar transactions, or requests to bypass your company's normal approval process.
One of the most common tactics used by fraudsters is creating a sense of urgency. A message insisting that money must be sent immediately or that normal procedures should be skipped is a reason to verify the request, not a reason to move faster.
Steps You Can Take to Protect Your Business
1. Use More Than One Person for Important Payments
Whenever practical, use dual control approvals. Requiring a second review for ACH transactions, wires, vendor changes, or other significant payments can help prevent both fraud and accidental errors.
2. Protect Your Online Banking Credentials
Use unique passwords and enable multi-factor or two-factor authentication wherever it is available. Employees should never share banking credentials, verification codes, or security tokens.
Access should also be limited based on an employee's responsibilities. Not every user needs the ability to create, approve, or transfer funds.
3. Verify Changes to Payment Instructions
Treat any unexpected request to change account or payment information carefully.
Before updating instructions, call the vendor, client, or employee using a trusted number you already have. Do not rely solely on the phone number or contact information included in the message requesting the change.
4. Monitor Your Accounts Regularly
Reviewing activity frequently can help your business identify suspicious transactions sooner.
Consider using account and transaction alerts so your team can be notified of activity that may require attention. The sooner suspicious activity is identified, the sooner you can contact your bank and begin determining what happened.
5. Consider Fraud-Prevention Tools
Talk with one of our Advisors about tools available to help protect your business accounts.
For businesses issuing checks or processing electronic payments, solutions such as Positive Pay and ACH controls can provide another layer of oversight by helping businesses identify transactions that do not match expected activity.
Technology should complement, rather than replace, your internal review and approval procedures.
6. Keep Employees Informed
Your employees are an important part of your fraud-prevention strategy.
Provide regular reminders about phishing, suspicious payment requests, password security, and your organization's verification procedures. Employees should know that it is appropriate to question an unusual request, even when the message appears to come from a manager or executive.
7. Have a Plan Before Fraud Happens
Determine in advance who employees should contact if they notice suspicious activity and what steps your business will take.
Your response plan should include notifying the appropriate people within your organization, contacting your financial institution promptly, securing potentially compromised accounts or credentials, and documenting what occurred.
Fraud Prevention Is a Team Effort
There is no single product or security measure that can eliminate fraud risk. The strongest approach combines secure banking tools, thoughtful internal controls, well-trained employees, and consistent account monitoring.
At Baker Boyer, we work with business clients to understand how money moves through their organizations and identify banking tools and practices that can help reduce their exposure to fraud.
If you have questions about protecting your business accounts, reviewing your current payment processes, or fraud-prevention tools available through Baker Boyer, reach out to us. Taking a few preventative steps today can help protect your business from a much larger disruption tomorrow.