Protecting Your Company Against Executive Impersonation Fraud
Nov 28, 2019
A company’s employees are generally expected to strive to protect the organization from a cybersecurity breach. Yet, thousands of team members unknowingly allow imposters to infiltrate businesses and steal millions of dollars by falling victim to executive impersonation fraud.
Surveying the Landscape
A variant of business email compromise (BEC), executive impersonation fraud entails a skilled criminal—or group of criminals—crafting an email that looks to be from one of the company’s key executives. The domain of the email address may be identical to the company’s domain except for one or two letters (e.g., [email protected]victimco.com vs. [email protected]vicitmco.com). Conversely, the email address might even be “spoofed” so that it appears legitimate — until the recipient hovers the cursor over the address to reveal the real sender.
The criminals do their homework to make their scheme convincing. They typically scour the company’s website and social media accounts to carefully investigate the executive they are impersonating. Additionally, they research their intended target, who will ideally be someone with the authority to initiate or approve transactions such as wire transfers.
Spotting Potential Threats
According to the FBI, executive impersonation fraud and other BEC scams have struck more than 22,000 victims worldwide and exposed more than $3 billion in losses. Given the magnitude of these effects, it is critical that employees are aware of – and recognize – the following warning signs:
- An email that looks to be from a senior executive comes from an address that varies from the official, company-issued domain
- The sender conveys urgency or secrecy by asking to communicate only through email (perhaps due to supposed regulatory restrictions)
- Payments are directed to foreign bank accounts, especially where the company has never done business
- Requests may occur when the key executive is traveling or unavailable
Creating a Defense Against Cyber Criminals
Executive impersonation fraud relies on employees’ willingness to bypass normal financial controls when asked to do so by an executive. Companies can dramatically reduce their risks with the following basic precautions.
- Create a culture of skepticism. Skepticism can be an important internal control. Employees should know that questioning authority — especially in regard to initiating financial transactions — is not only allowed, but also strongly encouraged.
- Build employee awareness of the latest email scams. Employees are a company’s first line of defense against any form of fraud. In addition to companywide cybersecurity education, all employees who have the authority to request, approve, or execute wire transfers should receive regular, specific training on whaling and other various types of social engineering attacks.
- Implement and enforce a social media policy. Employees should be careful about what they share on social networking sites, especially details about key executives’ travel itineraries.
- Strengthen controls around wire transfers. First, restrict authority for initiating or approving financial transactions to a few individuals. Then, design and implement procedures to verify the origin of all wire transfer requests. Many companies require verbal confirmation from someone calling from a company-issued phone number followed by secondary verification from another individual via another phone call using an authorization code.
- Document all of these steps. In the event that these controls fail and a security breach occurs, your incident response plan and documentation will be invaluable for showing regulators and prosecutors that your company implemented reasonable and appropriate safeguards to mitigate data loss.
Let CRI Be Your Cybersecurity Defense Ally
In a world where even an email from your chief executive could be corrupt, it can feel like threats are everywhere. However, defending against executive impersonation fraud requires you to objectively assess your organization’s threats, vulnerabilities, and internal controls. Please contact a CRI cybersecurity professional for more insights on protecting your company from cyber fraud.
New Businesses Face Challenges When Proving Damages Based on Lost Profits
In the Know: Pass Through Entity Tax (Georgia House Bill 149)In...
It’s Too Early for CECL Fatigue
Crypto Quick Reference Guide
CECL: It’s Not Just About Financial Institutions
Cryptocurrency: What’s a Community Bank to do?￼
A High-Yield Investment Class: Novice to Proficient
Increase Your Chances of an Efficient Financial Statement Audit
Employee Versus Contractor: A Crucial Distinction for Every Organization
Bolster Cash Flow With a Cost Segregation Lookback Study
Cryptocurrency Fundamentals for Financial Institutions
Is Your Rental Real Estate a Business?
GASB Pronouncement Effective Dates
Local Governments & The Final Rule: Coronavirus State and Local Fiscal...
S3:E7 – The Transaction Timeline: The 5 Stages of Selling Your...
What is Section 1071, and Why is it Important for Your...
5 Tips for Lessening Stress with Nonprofit Audit Preparation
Knowing When to Claim Social Security
Coronavirus State and Local Fiscal Recovery Funds
Manufacturing Inventory Accuracy Counts
3 Benefits of Creating a Captive Insurance Company
S3:E6 – Common ACFR Errors
Protect What Matters: Estate Planning in Uncertain Times
A Comparison of Education Tax Credits for 2022￼
Is it Time for a Business Valuation?
Give Your Small Business a Jolt of Efficiency with Cloud-Based Accounting
S3:E5 – Heads up, Grant Professionals!
How Has COVID-19 Affected Business Valuations?
A New Significant Victory for Micro-Captives: IRS Notice 2016-66 Vacated!
Reporting Computer-Security Incidents: Is your Community Bank ready?
What Does a Cash Balance Plan Mean for You?
The Name’s Bond, Government Bond
Setting Nonprofit Executive Compensation
Promises to Give: Not-for-Profit Accounting Primer
Does Working Remotely During the Pandemic Mean You Owe More Income...
Still Confused About Whether to Deduct That Business Meal?
New HITRUST Assessments Give Companies More Options for Security Reporting
ICBA Live 2022 Conference Recap
You Could Owe “Nanny Taxes” Even If You Don’t Have Kids
You Overfunded a 529 Plan. Now What?
Nonprofit Board Review of Form 990
Managing ESG Risks in the Oil and Gas Industry
Charitable Lead Trust vs. Charitable Remainder Trust: A Comparison
S3:E4 – SSAE No. 21 | Direct Examination Engagements
Going Concern Issues for Nonprofits
Improve Medical Practice Productivity with Non-Physician Providers
Five Internal Controls to Prevent Fraud in Nonprofits
Safeguard Your Assets During a Divorce — Before You Get Married
Differences in Public Charities and Private Foundations
S3:E3 – Panic! At the IRS Disco
Top 5 Accounting Questions to Ask Your CPA
Report Fundraising Events on Form 990
3 Grant Writing Tips to Help Not-For-Profit Organizations
Health Savings Accounts Offer Big Tax Benefits Now and in Retirement
Short on Cash? Gift-in-Kind Donations Can Also Help Support Charities
Estate Planning FAQ
Transfer Your Wealth Using a Dynasty Trust
Two Types of Charitable Trusts You Should Know About
New Guidance on Gifts In-Kind for Non-Profit Entities
S3:E2 – Count Yourself in to a Career in Tax Accounting
Captive Insurance Taxation
S3:E1 – Fill Me in On NIL (Name, Image, Likeness)
Tax Alert: Received a Letter from the IRS? Hold Onto It!
Top 5 Priorities for Small and Mid-Sized Organizations in 2022
A Look at Internal Controls and Processes for Evaluating Vendors
Getting the Most Out of Your Remote Audit
Moving to a New State? Don’t Make These Tax Mistakes
Coronavirus Relief Funds – Getting Ready for Your Single Audit
IRS Extends Federal Tax Filing Deadline for Victims of December Kentucky...
Does Your Organization Need an Internal Audit?
2022 Cost of Living Adjustments Chart
What a Single Audit Means for Your Organization
Straddling the Fence: Should You Co-Source or Outsource Your Internal Audit?
Help Your Business Finish Strong with These 10 Year-End Tasks
IRS Clarifies Rules on 100% Deduction for Per-Diem “Meals”
COVID-19 Funding Best Practices, Accounting Treatment, and Single Audit Implications
Have You Completed These 5 Year-End Financial Planning Tasks?
Cybersecurity Trend to Watch in 2021: Cyber Supply Chain Risk
Outsourced Accounting Reference Guide: How Collaborating Can Help You Reach Your...
Fiduciary Matters: How to Be the Best Trustee for Your Organization’s...
It’s a Marathon, Not a Sprint: Going the Distance for Outsourced...
2021 Year-End Tax Planning for Businesses: Strategize, Optimize, Maximize
2021 Year-End Tax Planning for Individuals & Families: Strategize, Optimize, Maximize
Conference Recap – AICPA 2021 National Conference on Banks and Savings...
CECL: It’s Getting WARM in Here Webinar
Credit Memorandum Best Practices and “The 5 C’s”
It’s a Marathon, Not a Sprint: Going the Distance for Outsourced...
Keeper of the Vault: A Business Owner’s Guide to Cybersecurity
Federal American Rescue Plan Act of 2021 (ARPA)
COVID-19 Quick Hits: American Rescue Plan Act Overview
Risky Business: Comparing Risk Levels of MRBs
Employee Retention Credit Information Sheet
IRS Employee Tax Forms: A Checklist for Small Businesses
IRS Income Tax Forms: A Checklist for Small Businesses
Digital Transformation Starts With Process, Not Technology
What’s New from GASB: An Update on the Latest Standards
Homeowner Assistance Fund – What Tribes and Applicants Need to Know
CECL: It’s Getting WARM in Here
Homeowner Assistance Fund – You Don’t Know the HAF of it!
American Rescue Plan for Governments: The Resources Available
Potential Proposals on the Horizon: It’s Time to Prepare Your Estate...
Anti-Money Laundering (AML) and Cannabis Banking: Is Your Financial Institution Ready?
It’s a Marathon, Not a Sprint: Going the Distance for Outsourced...
Strategic Use of ARP Government Funds for Long-Term Success
Time to Pivot? How Your CPA Can Help You Adapt to...
Compliance Management System (CMS) – A Refresher
The Basics of Grantor Retained Annuity Trusts
Tax Considerations for Buyers Contemplating Mergers & Acquisitions
What Role Does Life Insurance Play in Estate Planning?
Taking a Fresh Look at Bankruptcy
2021 Insurance Update: What’s Next?
Start From the T.O.P Down: Ways You Can Improve Your Organization’s...
The Basics of Spousal Lifetime Access Trusts
When E-Commerce Sellers Would Benefit from Hiring an Accountant
Internal Controls: Governmental Challenges and Opportunities
IRS Clarifies Temporary 100% Deduction for Restaurant-Purchased Meals
Hired Any Recently Unemployed Workers? Let Them Know About New Exclusion...
Make Better Business Decisions with Financial Modeling
Succession planning is a difficult, but necessary, subject for a contractor
Rate Reform – Why is LIBOR Going Away, and What Will...
Clear Vision: Moving Your Business Forward with Confidence
Five Overlooked Tax Breaks for Contractors and Manufacturers
Exit Strategies: Preparing Your Manufacturing Business for Transfer of Ownership
How Contractors Can Bridge the Age Gap
Enhance Your Technology Tool Kit for Improved Productivity
Tax Strategies for Special Needs Families
Healthcare 2021: The State of Our Industry
Why Profits Do Not Always Lead to a Positive Cash Flow...
IRS Provides Guidance on Cafeteria Plan Balance Carryovers
Updates to the AICPA’s SAS No. 134 through SAS No. 140
SSAE No. 21 – Direct Examination Engagements
Not-For-Profit Revenue Recognition
Don’t Jeopardize Your S Corporation Status
Fiduciary Activities & Leases: A Tale of Two Standards – GASB...
Now or Later? Weighing 15-year Depreciation vs. 100% Bonus Depreciation for...
How to Spot Three Common Tax Scams
Insurance Companies and the IRS: What’s on the Horizon?
The Anti-Money Laundering Act of 2020: An Overview
Federal Audit Clearinghouse Extended Submission Dates FAQs
When Can You Deduct Data Breach Costs?
Boost Your Cash Flow with Net Operating Loss Carrybacks
What’s Next for Hemp-Related Businesses?
Considering a Conversion from Traditional IRA to Roth? Think Twice.
Making Intrafamily Loans with Intentionally Defective Grantor Trusts
The IRA: A Solid Estate Planning Tool in Times of Uncertainty
How MaaS Is Revolutionizing Manufacturing
Export Tax Incentives for Manufacturers
Meals & Entertainment
Credit Risk Management in an Unpredictable Environment
Insurance Companies and the IRS: A Downward Trend in Examinations
Exempt Organizations: IRS Issues Final Rules on 21% Excise Tax on...
Coloring Inside the Lines of Nonprofit Governance
How Does Your Industry Affect Your Cybersecurity Risk?
USDA Issues Final Rules on Hemp Production
Not-So-Safe Harbor? Navigating the QBI Rules for Rental Real Estate Businesses
Current FDICIA Regulatory Relief – What You Need to Know Now...
Disasters Never Rest, So Take Time Now to Protect Key Documents...
5 Things to Remember About Substantiating Charitable Donations
Considerations for Banking Cannabis-Related Businesses
Yes, Operational Planning Is Still Important
Does Your Home Office Qualify for a Tax Deduction?
Shutting Down a Business? Updated Resources Available from IRS
Lending Money to Family? Be Sure to Stay on the Right...
Updates to the Long-Anticipated Compliance Supplement Addendum
Preparing for Third-Party Payer Audits
Virtual Panel – Accounting & Business Outsourcing: Success Stories
Surviving in a Tough Economy: Cash Protection Strategies During an Economic...
Five Ways to Make Invoice Processing More Effective
COVID/CARES Act: How to Account For It and Pass the Single...
Is It Time for Cloud Accounting?
Watching the Horizon: Do You Have the Data You Need to...
Real-Time Results: How Dashboards Can Help You Move Your Small Business...
Key Factors that Drive Reimbursement in the PDPM Model
Pooled Income Funds Benefit Both Donor and Charity
What’s Behind the Hype About Donor-Advised Funds?
Don’t Get Ready for Fiscal Year-End. Stay Ready.
Accounting & Business Outsourcing: How to Become a Results-Focused, Data-Driven Organization
CECL: Impact to Date and the Road Ahead
Businesses Face Challenges When Expanding Their Remote Workforce
Helpful Tips for Completing Medicare Cost Reports
5 Savvy Black Friday Weekend Shopping Tips to Put In Your...
Technology Innovations Impacting the Insurance Industry
10 Anti-Fraud Recommendations for Community Associations
Hospital Price Transparency
Tax Implications of Debt and Equity Financing
Building Your Ideal Captive Board
Don’t Sleep on CECL
Social Engineering Attacks: Considerations for SMBs
Smarter Giving: Four Things to Know When Considering Charitable Contributions
Security Implications of a Remote Work Environment
How Important is Compliance with Government Regulations to a Firm’s Accounting...
Contractors Should Take A Closer Look at Site-Level Profitability
Assembling an Effective Financial Team
Contractors Can Remain Profitable in Down Market
The Pitfalls of Underbidding Projects
PRF Requirements Summary
Provider Relief Fund Recipient Q&A
Prepare, Recover, Emerge Stronger: A Roadmap for Financial Perseverance in Times...
CARES Act and Provider Relief Fund Single Audit
Back to Profitability: How Small Businesses Can Emerge Stronger from Crisis
Five Steps to Elevate Self Pay Patient Collections in Medical Practices
Planning for Possible Workforce Reductions
Drafting a Business Continuity Plan (BCP)
Tax Concerns for Self-Employed Individuals
Contractors Should Juice Up Working Capital in Volatile Times
When Essential Business Is Risky Business: Workers’ Comp & OSHA Considerations...
Getting Ahead of a Possible Recession – A Case Study
Virtual Meetings: Tips for Choosing the Right Technology and Conducting a...
Calculating Your Business Interruption Loss
Maintaining Financial Controls in a Disrupted, Remote-Work Environment
How to Increase Your Chances of a Successful Financial Statement Audit
Healthcare Organizations: Are You Ready for New Revenue Recognition Rules?
Managing Your Costs: It’s Tougher Than You Think
How to Maintain Proper Financial Controls when a Remote Work Environment...
Business Interruption Losses: Making an Insurance Claim
Business Interruption: Planning Your Next Steps and Setting Expectations
Cybersecurity Tips for Working From Home
Understanding the Basics of Business Interruption Claims
Stabilizing Your Business: Improvise, Adapt, Overcome
Government Entities: Plan, Protect, Adapt, Overcome
Make the Most Out of Your P&L
How to Arrange a Medical Practice Buy-Sell Agreement that Minimizes Disputes
Is a Captive Right for Your Organization?
Spring Cleaning Now Improves Business Performance All Year
Forensic Audits vs. Annual Audits: Taking a Proactive Approach to Protecting...
Automated Bank Reconciliation: An Instant Analysis for Your Business
5 Reasons Business Owners Prefer Outsourced Accounting
Unique Compliance Aspects of Risk Retention Groups
Thriving Under COVID: How the Best Companies Do More Than Just...
Improve Manufacturing Company Profitability
What’s Your Company’s Cash Flow?
Record Retention Schedule
Preparing for a Single Audit: Understanding the Requirements
A Grant Overview
Understanding Your Responsibilities Within Service Organizations
When Does a Hobby Become a Business?
Make Digital Assets Part of Your Estate Plan
What You Need to Know About the Home Office Deduction
Keeping a Close Eye on Medicare Fraud
Captive Insurance Basics
Privacy Policies and Data Security Keep Contributions Flowing for Not-for-Profit Organizations
8 Action Steps for Avoiding Nonprofit Online Presence Tax Traps
Building an Effective Nonprofit Audit Committee
Impressing Donors with Nonprofit Financial Information
Two Types of Government Termination Benefits
The Growing Threat of Cyberattacks in Manufacturing and How to Prevent...
Is Your Manufacturing Business Ready for the New Revenue Recognition Standard?
A Blueprint for Nonprofit Revenue Recognition Implementation
Protecting Your Company Against Executive Impersonation Fraud
Qualified Opportunity Zones: A Resource Guide
Clarifying Compliance: A Resource Guide for Healthcare Organizations
Living in a Post-Wayfair World
Citizen Centric Governmental Reporting
How Does Industry Affect Fraud Risk?
Cost-Effective Fraud Protection
Municipal Bond Arbitrage, Billy Ray Valentine, and What They Have in...
Disaster Recovery: Protect Your Assets With the Right Insurance
Don’t Let These 7 Tax Terms Scare You
Three Actions to Help Improve Your Collections Process
Acknowledgments of Nonprofit Donations
UPMIFA – That’s Not a Text
Balance Sheet Reconciliations: Focus on Internal Controls over Financial Reporting (ICFR)
Charitable Donation Documentation: 6 Answers to Know
Should Your HITRUST CSF Assessor Be a CPA Firm?
Closing a Nonprofit Organization
For Strong Data Security, Give Your Employees Some Backup
Understanding the Benefits of Engaging in a NIST CSF Assessment
Transfer Pricing and Not-For-Profits
Why Fair Value is Becoming a Popular “Celebrity” in the Accounting...
Bracing for Disaster? Prepare to Deduct Casualty Losses
Natural Disasters Can Affect Your Financial Statement, Too
The Importance of Conducting a Valuation of Your Small Business
How the SEC Bridges the Divide between GAAP and Non-GAAP Financial...
Use a Governmental Performance Audit to See If You Measure Up
Risk Management: Avoiding Crisis & Staying Afloat
Using Internal Controls to Keep a Record of Your Inventory: Storing...
The Fine Line Between Nonprofit Lobbying and Advocacy
4 Things the IRS Looks for in a Federal Tax-Exempt Application
Using Nonprofit Financial Statements for Future Planning
Implementing Nonprofit ERM Strategies
3 Common Questions & Answers: Nonprofit Audit Committee
Love, Marriage, and Uncle Sam: How Getting Married Affects Your Taxes
7 Benefits of Outsourcing a Not-for-Profit Organization’s Essential Bookkeeping and Payroll...
How the Internet Mystifies the Taxability of Qualified Sponsorship Payments
Tax Planning Reasons to Potentially Establish a Private Foundation
5 Exercises to Rehabilitate Retirement Funds
Manufacturing Product Costing
Financial Statement Preparation: 4 Steps to Power Up Business Performance Tracking
What to Consider When Deciding Between a Calendar Year and a...
4 Benefits of a Government Audit Committee
Best Practices for Nonprofit Volunteer Management
Differentiating Between Independent Contractors and Employees
Captive Insurance Overview: Healthcare Provider Industry Highlights
Form 990 Marketing: Spotlight Your Nonprofit’s Efforts and Achievements
The Arm’s Length Principle: Protecting from the Rays of Transfer Pricing...
How to Properly Organize Your Tax Records
Where to Start When Creating a Business Plan
Small Business Compliance: Are You Sticking to the Law?
Five Steps to Prepare a Disaster Plan for Your Business
Restructuring Organizations Through Tax-Free Business Splits
Taking a Bite Out of Payroll Taxes
How to Protect Yourself from Tax Identity Theft
Anti-Money Laundering (AML) Implications of Human Trafficking
How Manufacturers Should Account for Excess Capacity
3 Questions to Find the Balance of a Seasonal Product Cycle
Opportunity Zones: Open for Business
How to Be Prepared With a Business Continuity Plan
What is a Governmental Component Unit?
4 Steps on the Path to Timely Payments
Understanding the Management’s Discussion and Analysis (MD&A) Disclosure
Six Common Nonprofit IRS Audit Triggers
The Evolution of the Bank Secrecy Act
Business Valuation Can Avoid a Merry-Go-Round During Divorce Proceedings
The Continued Importance of Risk Assessment for Financial Institutions
The Bank Secrecy Act/Anti-Money Laundering (BSA/AML) Audit Revisited
Opportunity Zones are Knocking: Should You Answer?
It’s Time to Review and Update Your Partnership Agreement
Using Internal Controls to Keep a Record of Your Inventory: Costing...
Clear Reliable Insights: GASB 87
How to Manage Supplier Costs and Keep Your Business Balanced
3 Ways Public Companies Can Iron Out Their SEC Audit Processes
Travel Guide for Your Start-Up’s Journey to Success
How to Become the Boss of Your Digital Assets
Steering Clear of Bookkeeper Liability Hazards
Four Must-Have Features When Selecting an Auditor
Will Your Cybersecurity Defense System Protect Your Organization?
“Yours, Mine, or Ours?”: Identifying and Valuing Marital Property
One Taxing Situation: South Dakota vs. Wayfair, Inc
IRS Correspondence Letter: Your New Pen Pal the IRS
Is Your Bank’s Audit Committee Reaching the Summit of their Potential?
Will Your Cost Segregation Methodology Hold Water With the IRS?
Understanding Terms Found in Common Business Interruption Policies
Business Interruption Claims Can Help Businesses “Resume Flight” Following Unexpected Disaster...
How the SEC Bridges the Divide Between GAAP and Non-GAAP Financial...
An Origin Story About Captives
Sail Smoothly Through Those Saving or Shredding Decisions
The Opportunities of Effective Risk Management
Keeping the “Business” in “Family Business”
How the Pooling Method Can Help Bring Your Property Value to...
Boost Your Bottom Line by Understanding Your Internal Audit
Why Strong Internal Controls Are Necessary for a Healthy Business
3 Governance Policies Every Business Should Have in Writing
Prescribing the Right Internal Controls for Your Business
Avoid the Punch of Ransomware
4 Business Seasons When You Should Consider a Virtual CFO or...
Whaling Cyberattacks: What You Need to Know
The Importance of Diversifying Your Customer Base
3 Reasons to Differentiate Between Controllable and Non-Controllable Costs
How to Maximize Business Sale and Successfully Exit
4 Simple Solutions to Improve Financial Reporting Timeliness without Breaking the...
8 Steps for Cleaning Up a Tax Return Identity Theft Train...
Unearthing Occupational Fraud in Your Business
Life Insurance Tax Strategies: Maximizing this Multi-Use Tool
Watch for These 3 Signs of Employee Fraud
Join Our Conversation
Subscribe to our e-communications to receive the latest accounting and advisory news and updates impacting you and your business.