Irish small and medium-sized enterprises (SMEs) have lost nearly €19 million to email-related fraud over the past two years, according to new figures released by FraudSMART. The losses, averaging over €22,000 per business impacted, highlight a growing threat to the backbone of the Irish economy. This surge in business email compromise (BEC) schemes is prompting a new awareness campaign aimed at bolstering defenses against increasingly sophisticated tactics.
The figures, published as part of a joint initiative between FraudSMART – an organization developed by the Banking & Payments Federation Ireland (BPFI) – and ISME, the Irish SME Association, reveal that invoice redirection and CEO impersonation scams are the most prevalent dangers. More than two-thirds (67%) of SMEs reported being targeted by a financial scam in the last 12 months, with 78% receiving at least one suspicious, urgent request, according to a recent survey conducted by BPFI and ISME.
Invoice redirection scams currently represent the largest proportion of these deceptions. These schemes typically begin with a seemingly legitimate email, often from a known supplier, but one whose email account has been compromised or closely replicated by fraudsters. The email doesn’t usually request immediate payment, but rather informs the business of a change in bank account details, requesting that future invoices be paid to the new account. This subtle shift is often enough to divert funds into the hands of criminals.
While less common, CEO impersonation scams can be even more damaging. In these instances, fraudsters pose as a senior executive within the company, attempting to convince employees to disclose sensitive information or authorize unauthorized financial transactions. The urgency and authority associated with a CEO’s request can override standard security protocols, leading to significant financial losses.
Niamh Davenport, Head of Financial Crime at BPFI, described the scale of the problem as “deeply concerning.” She noted that fraudsters are increasingly employing a multi-channel approach, combining email with follow-up phone calls or text messages to create a heightened sense of urgency and legitimacy. “They’re layering the communication to make it sense more real,” Davenport explained. However, she also highlighted a positive trend: 80% of businesses receiving suspicious requests are taking steps to independently verify the information before taking action.
The Vulnerability of SMEs
Despite this proactive response from some businesses, a significant gap remains in preparedness. According to the BPFI/ISME survey, over half (53%) of SMEs do not have formal fraud awareness guidelines or training in place for their employees. This lack of internal safeguards leaves them particularly vulnerable to these increasingly sophisticated attacks. Neil McDonnell, CEO of ISME, emphasized that falling victim to scams is not merely a financial blow, but also erodes trust within the business and with its partners.
“Employees are often the first line of defense, and therefore need to be equipped with the knowledge and tools to identify and report suspicious activity,” McDonnell stated. He added that preventative measures don’t need to be complex. Simple controls, such as verifying changes to supplier bank details, implementing dual approval for larger payments, and ensuring all staff are aware of the warning signs, can significantly reduce risk.
Common Scam Tactics and Prevention
FraudSMART outlines several key preventative measures businesses can take. These include:
- Verification of Bank Account Changes: Establish a robust process for verifying any changes to supplier bank account details, requiring confirmation through a separate, known communication channel.
- Dual Authorization: Implement a system requiring two individuals to approve any third-party electronic payments, particularly those exceeding a certain value.
- Employee Training: Provide regular training to all staff on identifying and reporting phishing emails and other fraudulent communications.
- Invoice Review: Thoroughly review all invoices for irregularities, such as discrepancies in amounts, account numbers, or contact information.
- Software Updates: Ensure all computer and mobile operating systems are up-to-date with the latest security patches, and set them to update automatically.
- Social Media Awareness: Limit the amount of personal and business information shared on social media platforms.
The most common channels used by fraudsters are email (88.4%), followed by phone calls (51.2%) and text messages (48.8%), demonstrating the need for vigilance across all communication platforms. FraudSMART has developed a free guide offering detailed information and tips on protecting businesses from fraud.
Looking Ahead
The ongoing evolution of these scams necessitates a continuous commitment to education and adaptation. The BPFI and ISME plan to continue their collaborative efforts, providing resources and support to facilitate SMEs strengthen their defenses. The next scheduled update from FraudSMART regarding scam trends and preventative measures is expected in early November, providing a crucial checkpoint for businesses to reassess their security protocols.
This issue demands ongoing attention and proactive measures. Share this information with your network and let us know in the comments what steps your business is taking to protect itself from email fraud.
Related reading
