Data, IT and risk management

Business Email Compromise Payment Fraud

Business mail fraud does not necessarily depend on viruses, and the attackers may be impersonating the owner, client or supplier to induce changes in the collection account.

ZhiHua Tech Original Course2 minutes 25 secondsFAQs and solutions in enterprise informatization

This video is used for enterprise-infomatic knowledge learning and internal discussions.

DIRECT ANSWER

Let's see what we can do.

Business mail fraud does not necessarily depend on viruses, and the attackers may be impersonating the owner, client or supplier to induce changes in the collection account.

VIDEO NOTES

The video content of this issue is read

The following are structured textual interpretations of the video for the current period, which allow for quick reading, internal discussion and search; it is not verbatim subtitled. Around “Financially, there is no virus, why a mail can still cheat the price”, it is suggested that a distinction be made between the appearances, business causes and system improvements before deciding whether process adjustments, data governance, system integration, automation or customization development are required.

Common ways of commercial mail fraud

Business mail fraud does not necessarily depend on viruses, and the attackers may be impersonating the owner, client or supplier to induce changes in the collection account. The identity of the business cannot be verified by the poison software alone.

2. How changes in payment information are verified

Business mail fraud does not necessarily depend on viruses, and the attackers may be impersonating the owner, client or supplier to induce changes in the collection account. The identity of the business cannot be verified by the poison software alone.

3. How technology controls fit with operational systems

Business mail fraud does not necessarily depend on viruses, and the attackers may be impersonating the owner, client or supplier to induce changes in the collection account. The identity of the business cannot be verified by the poison software alone.

WORKFLOW DESIGN

What should we do with this scene?

Covers recurring failures, privileges, files, backup recovery, mail fraud, warranty compliance and the cost of software assets. Around “financials do not point viruses, why a mail can still cheat the purchase price”, real input, expected output, tool privileges, manual clearance, unusual handling and operational acceptance indicators should be defined before deciding whether to use rules, scripts, API, Codex or other AIAgent.

01Common ways of commercial mail fraud

The verification of conditions, liability, data sources and exceptions is done using real samples, and the presentation is not used as a substitute for production evidence.

02How changes in payment information are verified

The verification of conditions, liability, data sources and exceptions is done using real samples, and the presentation is not used as a substitute for production evidence.

03How technology controls fit with operational systems

The verification of conditions, liability, data sources and exceptions is done using real samples, and the presentation is not used as a substitute for production evidence.

IMPLEMENTATION PATH

Suggested paths for improvement

  1. 1
    Inventory systems, data, account numbers and risk liability

    Selecting recent and representative tasks and anomalies, identifying participants, input outputs, time and current costs.

  2. 2
    Design minimum privileges by character and business scene

    Distinction between actions that are self-executing, that require manual confirmation and that prohibit automatic processing.

  3. 3
    Establishment of monitoring, change, backup, recovery and compliance desk accounts

    Start with the draft, a copy or a limited scene, and keep the abnormal transferer and retreat.

  4. 4
    Regular exercises and spot checks on the effectiveness of the certification system

    Continuous observation of accuracy, adoption, processing cycle, error and real business results.

ACCEPTANCE

How to automate the receipt and inspection is really effective.

The acceptance cannot be based solely on whether a single demonstration runs. The following results should be observed continuously using independent samples and real anomalies, and pre-modification baselines of the same calibre should be maintained:

  • The failure is due to the failure of the factors and precautions
  • Auditability of authority and sensitive operations
  • Whether the backup is rehearsed
  • Is the license, account number and software cost sustainable and manageable?

The authorization, approval, audit and manual takeover must also be verified when it comes to the amount, customer commitment, privacy, compliance, production change or deletion operations.

RELATED RESOURCES

Continue to learn about the programmes