Skip to content

Commit

Permalink
XS ◾ Fixing Do you know how to prevent phishing for payments? URI for…
Browse files Browse the repository at this point in the history
…mat (#9863)

* Update rule.md

Fixing wrongly formatted URI (spaces instead of dashses)

* Auto-fix Markdown files

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
  • Loading branch information
JeanThirion and github-actions[bot] authored Feb 6, 2025
1 parent 5f03fce commit a0b3641
Showing 1 changed file with 10 additions and 10 deletions.
20 changes: 10 additions & 10 deletions rules/phishing-for-payments/rule.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
seoDescription: Phishing for Payments.
type: rule
title: Do you know how to prevent phishing for payments?
uri: phishing for payments
uri: phishing-for-payments
authors:
- title: Jimmy Chen
url: https://ssw.com.au/people/jimmy-chen
Expand All @@ -17,11 +17,11 @@ archivedreason: null
guid: c72fa325-be7f-4490-afee-8374cf9ecc92
---

According to the Association of Certified Fraud Examiners' 2024 report, organizations lose an estimated 5% of their revenue to fraud each year.
According to the Association of Certified Fraud Examiners' 2024 report, organizations lose an estimated 5% of their revenue to fraud each year.

In Australia, cybercriminals are increasingly targeting businesses, leading to global losses of up to $2.9 billion annually.
In Australia, cybercriminals are increasingly targeting businesses, leading to global losses of up to $2.9 billion annually.

Accountants and accounts payable professionals are prime phishing targets due to their access to financial transactions, and some may lack cybersecurity awareness.
Accountants and accounts payable professionals are prime phishing targets due to their access to financial transactions, and some may lack cybersecurity awareness.
Scammers exploit this through fake invoices, compromised emails, and fraudulent bank detail changes

<!--endintro-->
Expand All @@ -38,13 +38,13 @@ See SSW Rule - [Do you know how to recognize phishing URLs?](https://www.ssw.com

Attackers often hack business emails to send fake payment requests or change bank details.

**Enable MFA** - Be careful to manage your passwords and always use Multi-factor authentication
**Enable MFA** - Be careful to manage your passwords and always use Multi-factor authentication

See SSW Rule - [Do you use MFA and avoid typing passwords?](https://www.ssw.com.au/rules/using-mfa/)

**Use security tools** - Use email security tools (e.g., Microsoft Defender).
**Use security tools** - Use email security tools (e.g., Microsoft Defender).

**Verify changes by phone** - Always call a known contact using a verified number before processing any changes. Never trust phone numbers from emails requesting updates.
**Verify changes by phone** - Always call a known contact using a verified number before processing any changes. Never trust phone numbers from emails requesting updates.

::: greybox
Paying a supplier - confirm the bank details by calling the creditor's verified number for the first payment (over $1,000) or if there is a change in bank details.
Expand All @@ -53,15 +53,15 @@ Paying a supplier - confirm the bank details by calling the creditor's verified
Figure: Good Examples
:::

**Monitor email forwarding rules** - Hackers may set up auto-forwarding to steal sensitive information. Regularly review and disable unauthorized forwarding.
**Monitor email forwarding rules** - Hackers may set up auto-forwarding to steal sensitive information. Regularly review and disable unauthorized forwarding.

3. Adding an Invoice Disclaimer to Prevent Fraud

Including a disclaimer on invoices can help prevent phishing attacks that aim to alter billing details.

Authorized domain only - Clearly state that all official communication, including billing and invoices, will only come from a specific domain (e.g., @company.com).
Authorized domain only - Clearly state that all official communication, including billing and invoices, will only come from a specific domain (e.g., @company.com).

Changes only come from verified channels - Any changes in payment details will only be communicated through verified channels, such as a notification with the company seal or a direct phone call from an authorized representative
Changes only come from verified channels - Any changes in payment details will only be communicated through verified channels, such as a notification with the company seal or a direct phone call from an authorized representative

::: greybox
**Example:**
Expand Down

0 comments on commit a0b3641

Please sign in to comment.