Email Account Compromise What Is It And How Can Your Business Protect Itself From It?

[ad_1]

By: Attorney Heather J. Macklin

Scams, phishing, pharming, vishing – people in the business world are well aware that hackers and other fraudsters have developed a myriad of schemes to obtain sensitive personal information and money. These schemes lead to significant financial losses for companies every year. The FBI estimates that by 2020, corporate email compromises (BEC) and email account compromises (EAC) caused losses of $1.86 billion. To combat these schemes, companies spend thousands of dollars to secure their computer systems and train their employees to spot fraudulent schemes and prevent them from succeeding. But regardless of the preventive measures companies take, hackers and fraudsters manage to stay one step ahead with new, creative programs.

A recent fraud that businesses have unfortunately experienced is EAC, where hackers gain access to and use legitimate business email accounts from vendors and service providers to force customers to send money to unauthorized accounts. EAC affects businesses of all sizes and can appear in any industry, including financial institutions, real estate, contractors, and law firms. In a typical EAC scenario, hackers gain access to a person’s actual email account and track incoming and outgoing correspondence to learn business practices, customer information, and payment terms. At an opportune time, the hackers use the email account to send payment instructions to a customer who legitimately owes money to the alleged authoring company. The customer receiving the email has likely communicated with the company and its employees before and, with no reason to suspect the hacking, follows its instructions and sends payments (from thousands to millions) to a fraudulent account. By the time everyone realizes what happened, the hackers and the money are long gone.

Because EAC is a relatively new fraud phenomenon, very few courts have had a chance to consider and decide which of the parties involved will ultimately bear the loss. Published legal rulings show that courts tend to hold liable the party that was better able to prevent the fraud in a given factual scenario.

However, now that the legal doctrines in force have been established, companies are left to figure out how best to protect themselves from EAC and the resulting losses. Fortunately, there are plenty of protections against EAC schemes available. Three of the easiest are: (1) documentation, (2) communication, and (3) insurance.

Documentation

Before doing business with each other, suppliers and their customers must establish the terms of their relationship in written contracts. In addition to the typical terms expected in contracts (e.g. scope of work, agreed price and timelines, etc.), authorized payment methods and risk allocation must be included. By agreeing in advance how and where payments are to be made, the parties can ensure that any future EAC communications regarding payment are promptly flagged and investigated. In addition, by defining who bears the risk of loss, computer systems must affected and payments are diverted, the parties will understand the duties and obligations they have to each other and hopefully take the necessary steps to protect their systems.

Communication

When payments are due and intercompany money transfer is necessary, all emails received with instructions for payments to specific accounts or through certain methods must be verified before the funds are released. The employee responsible for initiating the transfer should not simply trust the email, even if it appears to have been sent from a legitimate and verified email account. Instead, they must personally contact the person who supposedly sent the email, either in person or via phone call, to confirm that the instructions are legit and that the bills actually belong to the company ultimately entitled to the payment. . Only after the authenticity of the payment instructions has been successfully verified, the person is allowed to initiate the transfer.

Insurance

Businesses can and should purchase cybersecurity insurance policies (which are not automatically part of standard business insurance policies) that cover losses caused by EAC and other information security breaches. Such policies provide an additional layer of protection for businesses when fraud is not detected or prevented in a timely manner. All businesses should ask their insurance agents to confirm which cybersecurity insurance options are available to them.

While EAC and other information security fraud will unfortunately continue to plague the business world, by adopting these best practices, companies can often prevent and/or protect the significant consequences they would otherwise encounter.

Heather Macklin, a partner at Davis & Kuelthau, has over 20 years experience representing companies in complex commercial disputes and advising them on risk assessment and avoidance.

This article is expected to appear in the January issue of The business news.

Sources

1/ https://Google.com/

2/ https://www.dkattorneys.com/publications/email-account-compromise-what-is-it-and-how-can-your-business-protect-itself-from-it/

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts