Understanding the Data
A recent survey by the Association for Financial Professionals reveals that 79% of organizations faced attempted or actual payments fraud last year. Despite significant investments in defenses, this figure remains steady. More concerning is that only 22% of organizations recovered more than three-quarters of stolen funds, down from 41% the previous year.
The data highlights two main issues. First, your fraud controls aren't evolving as quickly as criminal tactics. Second, once funds are lost through social engineering or payment manipulation, recovery is unlikely. Prevention is your most viable strategy.
Key Findings
Business email compromise (BEC) is a major threat. BEC remains prevalent, but tactics are changing. Attackers now spoof vendors and third parties, exploiting trust in supplier relationships. The U.S. Office of the Comptroller of the Currency breach shows the risks: hackers accessed thousands of sensitive emails for over a year after compromising one account.
Wire transfers are a prime BEC target. Attackers redirect wire transfers after compromising email communications. Large sums move in one transaction, and recovery is tough once you've authorized the transfer. Your wire transfer approval process must include verifying payment requests outside email channels.
Checks are a significant vulnerability. 63% of respondents faced fraud attempts involving checks. This issue isn't limited to small businesses. Many organizations still use checks, and attackers take advantage. Check fraud requires minimal technical skill, just access to mail and basic image editing software.
DNS controls are underused. Domain Name System controls block malicious domains, preventing phishing emails and access to harmful websites. They protect your network devices and routers, securing your attack surface before an attacker gains entry.
Recovery rates are dropping despite better detection. The decline from 41% to 22% in fund recovery suggests attackers are moving money faster or using advanced laundering techniques. Your incident response speed is crucial.
Implications for Your Team
You're facing an adaptive threat. Attackers evolve as your controls do, and past fraud data may not predict future attacks. The shift from executive impersonation to vendor spoofing shows this clearly. Once your team verifies executive payment requests through secondary channels, attackers target weaker verification workflows.
The declining recovery rate means you can't depend on law enforcement or banks to recover funds after an attack. Your fraud prevention strategy must assume any lost funds are gone for good. This should influence your risk tolerance for payment authorization controls.
If you're still using checks significantly, you're accepting a known vulnerability. The question isn't about convenience for vendors, but whether that convenience justifies the fraud risk.
Action Steps
Deploy DNS filtering network-wide. Implement DNS controls to block known malicious domains at the network level. This adds a defensive layer before phishing emails reach inboxes and before employees access harmful websites. Ensure DNS filtering covers all network devices and routers. Test by attempting to access known malicious domains from different network segments.
Establish out-of-band verification for payment changes. Require voice verification using a known phone number for any request changing payment details, increasing amounts, or requesting expedited processing. Document the verification before releasing funds. This addresses executive impersonation and vendor spoofing.
Map and transition check usage. Identify all workflows using checks. Document why checks are used, typical payment amounts, and recipient willingness to accept alternatives. Prioritize moving high-value, high-frequency check payments to ACH or virtual card programs. Set a deadline to eliminate checks for payments over a specific amount.
Audit vendor communication channels. Review how vendors communicate payment information. Require that changes be submitted through a vendor portal or authenticated system, not email alone. Train your accounts payable team to reject emailed changes and direct vendors to the proper channel.
Limit wire transfer authorization. Review who can authorize wire transfers. Implement split knowledge requirements where two people independently verify and approve transfers. Consider time delays for transfers to new beneficiaries, allowing time to detect social engineering.
Test your team's ability to spot spoofed emails. Conduct exercises simulating vendor email compromise. Present your team with realistic spoofed emails requesting payment changes. Measure compliance with verification procedures and refine training based on results.



