Business scam awareness is an operating control, not an annual presentation. Scammers exploit authority, urgency, secrecy, unfamiliar payment methods, and routine process gaps. A trained employee still needs verification rules and a safe way to stop a transaction.
Common scams targeting businesses
| Scam | Typical approach | Control |
|---|---|---|
| Invoice or bank-change fraud | Altered invoice or impersonated supplier | Callback to a known number plus dual approval |
| Executive impersonation | Urgent confidential payment or gift-card request | Independent confirmation outside the message |
| Directory or award scheme | Invoice for an unwanted listing or “renewal” | Purchase-order and contract match |
| Fake check | Overpayment followed by a refund request | Do not rely on provisional bank availability |
| Tech support | Fake alert requesting remote access | Use the approved internal support channel |
| Phishing | Credential or malware link | MFA, filtering, reporting, and domain verification |
Recognize manipulation signals
- Pressure to act immediately or keep the request secret
- A new account, payment method, domain, or phone number
- Gift cards, cryptocurrency, wire, or refund requests outside normal process
- An attachment or sign-in page that arrives unexpectedly
- Small spelling changes in a familiar domain
- A request that bypasses approvals because an executive is “unavailable”
Design controls that work under pressure
Maintain verified contact and bank-detail records. Require a known-channel callback for changes, dual authorization above thresholds, separation of vendor maintenance and payments, least-privilege access, multifactor authentication, bank alerts, and prompt reconciliation. Give employees explicit authority to pause without punishment.
Third-party account changes are especially risky in same-day international payments, where recovery windows can be short.
Verify without using the suspicious message
- Stop and preserve the request.
- Find contact details from a contract, approved master file, or official website—not the email.
- Confirm the requester, purpose, amount, and account using a separate channel.
- Obtain required approvals and document verification.
- Report the attempt so related accounts and transactions can be checked.
Respond to a suspected incident
Contact the financial institution immediately and request recall or hold options. Notify internal security, legal, finance, and leadership under the incident plan. Preserve messages, headers, logs, telephone details, approvals, and transaction references. Reset exposed credentials through a known-good device, revoke sessions, and inspect forwarding rules. Report to relevant law-enforcement, regulatory, insurer, and affected-party channels as advised.
Do not delete evidence or quietly correct the ledger. The organization needs a factual timeline and control improvement. If credentials may be sold or reused, consult the dark web threats guide.
Training that changes behavior
Use role-specific examples, short recurring exercises, and a one-click reporting route. Measure reporting speed, verification compliance, repeat weaknesses, and time to contain incidents—not only who clicked a simulated message.
Frequently asked questions
Can caller ID or a familiar email prove identity?
No. Identifiers can be spoofed or accounts compromised. Verify material requests through an independently trusted channel.
Does a deposited check mean the money is final?
No. Funds may appear available before a fraudulent check is discovered and reversed.
What should happen after a bank-detail change?
Use independent verification, approval, alerts, and heightened review of the first payment.
Sources reviewed
Last reviewed: August 15, 2026. If money or data may be at risk, contact the relevant institution and qualified incident-response or legal professionals promptly.