Fraud attacks on businesses are at an all-time high and the problem is only getting worse, according to John Cradden, who looks at ways firms can stay ahead of the scammers.
While cyberattacks or hacks are about targeting data and systems to steal data, fraud arguably represents a greater financial risk to Irish SMEs because it relies on human deception rather than complex technical breaches.
According to FraudSMART, the fraud awareness initiative run by the Banking and Payments Federation (BPFI), almost €19 million alone was lost over the last year by SMEs to email‑related scams over the past two years, with invoice‑redirection fraud and CEO impersonation the two most common types.
“As a bare minimum, a verification process for when any requests come in to change supplier bank accounts is highly recommended”
Speaking earlier this year, the BPFI’s head of financial crime, Niamh Davenport said: “According to a recent survey we conducted with ISME, 67% of SMEs say they’ve been targeted by a financial scam in the last 12 months while 78% have received an unexpected or urgent request that raised suspicion.
“Most attempted scams are coming through email (88.4%) as well as phone calls (51.2%) and text messages (48.8%). Increasingly, fraudsters combine these channels – for example, following up an email with a phone call or text message – to create a greater sense of urgency and legitimacy.”
What is making the fraud onslaught so potent these days is the rapid adoption of AI tools by scammers, finding and exploiting vulnerabilities at unprecedented speed and thereby gaining a huge advantage against potential victims.
Deep fake deception
According to PwC, advanced AI will enable more convincing and scalable social engineering, with hyper-realistic, personalised targeting across audio, video, and text that mimics genuine human communications.
For example, audio or video deepfakes where fraudsters clone a CEO’s voice using short clips from public videos to call finance staff to authorise money transfers or fake transactions.
Traditional spam filters that look for spelling mistakes, repetitive phrasing or broken English will be largely ineffective when AI can now generate very convincing unique and well-written messages instantly by scraping employees’ corporate and social media profiles.
Synthetic identity fraud is another fast-growing threat. This is where criminals build a fake persona using a stolen ID or social security number mixed with fake details like a made-up address and name. The danger for businesses is that these personas can bypass traditional digital security onboarding.
Account takeover is where cyber attackers gain unlawful access to a legitimate personal or business accounts. Once inside, they can change contact details, add new payment methods or drain funds instantly.
Warning signs for all employees
The BPFI reports that most businesses have some security measures in place such as verification processes for new bank account details, what’s lacking is specific fraud awareness guidelines and training programmes for employees.
Among the main warning signs all employees should be aware of include:
- Unexpected requests to change bank details
- High-pressure urgency or demands for immediate action ‘or face consequences’
- Convincing looking emails or messages purporting to come from your CEO or a senior executive urging a confidential transfer or payment
- Requests that shift abruptly from invoice systems to email, text or WhatsApp.
As a bare minimum, a verification process for when any requests come in to change supplier bank accounts is highly recommended, according to FraudSMART tips for SMEs.
Another step is to consider dual or two-person authorisation for any third-party payment done by electronic means.
Reviewing invoices thoroughly to ensure no irregularities is another way to stay vigilant to frauds.
And in a nod to the increasing weaponisation of social media profiles by AI, it’s also recommended that you avoid sharing too much personal information on social media, particularly if it relates to your work.
Defend against fraud
What works in terms of fraud awareness and training can vary from company to company, but any programme should include modules that define fraud clearly, highlights behavioural red flags, explains personal liability (that fraud is a real offence), and highlights all the safe reporting channels.
If your business is the victim of fraud, notify your bank or financial institution immediately to freeze accounts, stop any pending transfers or flag compromised card and login details. Then notifiy the Gardai, either to your local station or the Garda National Economic Crime Bureau. Keep copies of emails, text messages, or transaction records. IT teams should also save server logs.
As well as FraudSMART, your bank will have resources dedicated to preventing fraud. Bank of Ireland’s Security Zone, for instance, has podcasts, checklists and booklet publications on a number of the most relevant areas.
If you’re in the market for solutions that go a bit further, it’s well worth checking out the vibrant Irish cybersecurity eco-system of established companies and start-ups.
👉 No tech background needed to bring your business into the AI age! Secure your scholarship to complete the certification at no cost. Apply now and get started!
-
Bank of Ireland is welcoming new customers every day – funding investments, working capital and expansions across multiple sectors. To learn more, click here
-
For support in challenging times, click here
-
Listen to the ThinkBusiness Podcast for business insights and inspiration. All episodes are here. You can also listen to the Podcast on:
-
Spotify
-
SoundCloud
-
Apple




