Funds Transfer Fraud Has Increased 35% Since the Onset of COVID-19

Stu Sjouwerman | Sep 14, 2020

CEO-Fraud-ReleaseWith reported losses from thousands of dollars to well over $1 million, funds transfer fraud represents 27% of cyber insurance claims in 2020.

The bad guys are in search of one thing and one thing only – figuring out a way to make money. Some go the ransomware route and others steal data and sell on the dark web. But, according to cyber insurer Coalition’s H1 2020 Cyber Insurance Claims Report, the interest in funds transfer fraud has not only grown since COVID started, but has also increased 35% this year over 2019.

Nearly a third of the funds transfer fraud-related cyber insurance claims (29%) came from the Consumer Discretionary sector (which includes automotive, household durable goods, textiles & apparel and leisure equipment - among others), with Financial Services in second place.

According to the report, 45% of cases were unable to recover the funds transferred, demonstrating the importance of catching the fraudulent activity early on. In cases where the fraud is detected quickly, 84% of funds were able to be recovered.

Coalition point out that most funds transfer fraud claims involve the following social engineering techniques:

  • Invoice Manipulation – This usually involves either using a compromised third-party email or having specific pending transaction details enough to fool the victim.
  • Look-alike Domains – Impersonation is often used where the cybercriminal uses a domain with an added/subtracted/swapped character in the name to trick the victim into believing the email requesting funds is legitimate.
  • Email Spoofing – This is the simplest form, as in the CEO credit card scam (where the email purports to be from the CEO’s personal email address). Sometimes just looking like it *could* be from someone legitimate is enough to fool the victim.

Users that are involved in any way with your organization’s finances should undergo new school Security Awareness Training to educate themselves on how the bad guys attempt to fool them, what real-world scams look like, and steps they can take to keep from being the next victim.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.