Bank impersonation fraud has evolved beyond phishing emails and fraudulent payment requests. Today's fraudsters increasingly target treasury environments through sophisticated social engineering campaigns that exploit one of banking's strongest assets: trust.
While these attacks may appear focused on sending fraudulent payments, the true objective is often access. Criminals seek to gain control of treasury platforms, enabling them to create users, modify permissions, redirect notifications and establish persistent access before ultimately executing fraudulent transactions in an even less detectable manner.
As a result, fraud prevention can no longer focus solely on transactions. Organizations must also protect access, administration and control.
The Call That Looks Legitimate
Imagine a business owner receives a text alert about suspicious account activity. Shortly afterward, a call comes in from someone claiming to be with the financial institution’s fraud department. The caller appears knowledgeable, professional and concerned about protecting the account.
Everything feels legitimate, except it isn't.
Modern bank impersonation fraud relies on social engineering rather than technical compromise. Whether delivered through phone calls, texts, emails or spoofed websites, these attacks are designed to exploit trust and persuade victims to grant access or disclose authentication information.
Why These Attacks Work
Fraudsters exploit urgency, authority and fear. Common tactics include:
- Claims of suspicious account activity,
- Unauthorized login attempts,
- Compromised credentials or
- Pending wire transfers requiring immediate action.
The deception becomes even more convincing when criminals coordinate messages across multiple channels. Combined with caller ID spoofing and publicly available company information, it can be difficult to distinguish a legitimate financial institution representative from a fraudster.
Why Businesses with Treasury Products Are Prime Targets
The online banking admins at these businesses often control wire transfers, ACH activity, online banking access, user administration and payment approvals. Because they manage both funds and the controls governing those funds, they are highly attractive targets.
Fraudsters increasingly recognize that the greatest value lies not in a single payment but in gaining control of the systems and permissions that enable future payments.
The Real Objective: Control the Environment
A common misconception is that fraudsters simply want a victim to send money. In many cases, their true goal is to gain control of the entire online banking treasury environment.
After obtaining credentials, multi-factor authentication (MFA) codes or other access, criminals may:
- Create users,
- Elevate permissions,
- Alter approval workflows,
- Register new devices,
- Add payees,
- Modify notification settings and
- Initiate transactions.
The fraudulent payment is often the final step; control is the primary objective.
Once attackers control the environment, executing fraudulent transactions becomes significantly easier and less risky.
Two Critical Post-Compromise Risks
- Creating New Users: Administrative access can enable fraudsters to create additional user profiles, providing persistence and reducing dependence on the originally compromised credentials. These accounts can remain available for future fraudulent activity even after the initial compromise is discovered.
- Redirecting Notifications: Many organizations depend on alerts for new users, entitlement changes, payment activity and security events. If criminals redirect or disable notifications, they can significantly extend the time they remain undetected.
Together, these capabilities allow attackers to act undetected, a combination that can lead to substantial financial and operational losses.
Reclaiming Control
Organizations should adopt an access-centric approach to fraud prevention. Key practices include:
- Treat credentials, MFA devices and administrative privileges as high-value assets.
- Monitor user creation, entitlement changes, device enrollments and administrative modifications.
- Review all changes to notification settings and alert recipients.
- Independently verify requests involving access, credentials or authentication.
- Conduct regular reviews of users, permissions, approval workflows and registered devices.
Final Thoughts
The greatest threat posed by modern bank impersonation fraud is often not the unauthorized transaction; it is the unauthorized control that occurs first. A fraudster who can create users, alter permissions and suppress notifications has gained the ability to operate inside the treasury environment as a legitimate user.
In today's threat environment, transaction verification alone is no longer enough. Organizations must also verify who controls the profiles, permissions and systems behind those transactions. Protecting payments remains important, but protecting control may be even more critical.
|
|
Join EPCOR and NEACH virtually September 22–23 for the End-User Payments Fraud Symposium to connect with fraud leaders, uncover the latest payment fraud trends and gain actionable strategies to help combat evolving threats. Register today to save your spot. Plus, financial institution registrants can invite unlimited business clients at no additional cost!
|