Employees’ Social Media Use Puts You At Risk of Fraud: 5 Things Finance Must Know
An after-hours Facebook post from Bob in Development could be putting your company at risk of fraud. The same goes for salesperson Kiay’s Instagram reel.
More than 80% of security and IT professionals in a Mimecast survey said employees put their companies at high risk of fraud by oversharing company information on social media. Social shares and posts potentially expose them and their employers to online fraud, phishing and other cyber threats.
Risk in Action
“Employees don’t necessarily need to share confidential documents to reveal useful information about a business. Sometimes it can be the small details that add up,” said John Pepper, CEO and Founder of Managed247. “A photo from the office, a post about a new client or even an update about an upcoming project could give someone outside the organisation a better understanding of how that business operates.”
Innocuous actions can put your company, finances, data, clients and future at risk.
While you don’t want to monitor employees’ social media presence and posting, your business might want to pay closer attention to what they’re sharing.
Here are five ways employees’ oversharing can put your company at risk of fraud. Pepper recommends practical tips for reducing or eliminating those risks.
1. Impersonation
Cybercriminals can — and will — find a wealth of valuable information on employees and their employers, including names, job titles, places of work, company locations, colleagues, clients and professional responsibilities. They use that to impersonate an employee and make convincing requests for money, confidential or sensitive information or access to systems.
Pepper suggests, “Businesses should think about employees’ digital footprints as part of their wider cybersecurity strategy and make sure staff understand what information could potentially be useful to someone outside the organisation.”
2. Targeted Scam
Criminals can monitor employees’ social media activity to learn a lot about an organization — such as who works there and who they regularly interact with. The more they know about interactions, the easier it is for them to engineer social activity to make fraudulent messages appear genuine.
For example, an employee might post about a new role, project or business relationship. That can inadvertently give criminals enough information to create a congratulatory message that appears to come from a colleague, customer or supplier.
Pepper suggests you remind employees regularly: “If (anyone) receives an unusual request involving money, confidential information or access to a system, it’s always worth checking through another trusted channel before taking action.”
3. Deepfakes
Beware: Scammers need just three seconds of audio to clone a person’s voice, according to research from McAfee. Online videos and publicly posted photos make it easier for scammers to create AI-generated images and deepfakes.
What that means to you: Cyber criminals might attempt to impersonate employees, directors or other company representatives seeking financial information at your fingertips.
According to Pepper, it’s a real possibility these days: “The important thing is not to panic, but to have sensible processes in place so that unusual requests are independently checked, particularly when money or sensitive information is involved.”
4. Reputation
Employees can also open the gate to trouble through reputational risks — intentional or not. Their personal accounts often have some association with where they work: Almost everyone on LinkedIn has their employer listed, and Facebook has a setting for your workplace.
A disgruntled employee might write a reputation-damaging post. Or a perfectly happy employee might share views that others see as offensive — and you’re guilty by association.
“Employees are often seen as representatives of a business whether they intend to be or not, so it’s worth thinking about how personal social media activity could be perceived,” said Pepper.
You probably can’t dictate what employees can or can’t personally post, but you can ask them to be aware that posts can have a much longer life and reaction than they expect.
5. Security
Sometimes, the seemingly most harmless post can be a great risk. When employees overshare from inside your walls, you’re at risk. Those posts can reveal security systems, access points or screens and documents that hold private financial information. Posts about upcoming projects might disclose confidential business plans. Posts that announce new clients, suppliers, software systems or company locations could give attackers useful information about your operations.
Your company (and probably your marketing team) doesn’t want to go silent on socials. But you might create a policy that nothing is posted from within your finance area.
Free Training & Resources
Webinars
Provided by Yooz
Further Reading
Two U.S. nationals were sentenced for their roles in facilitating North Korean remote IT workers posing as U.S. residents to obtain work at...
You can’t be too careful out there! Fraud is a risk in every area of finance — even the auditor hired to analyze data and file ...
Many companies are turning to even faster payment methods, such as embedded finance solutions and banking as a service products. In fact, a...
Fraud has become an increasing concern for AP teams, and the financial impact is quite significant. Criminals are taking advantage of vario...
Does it feel like the cost of nearly everything is on the rise or not coming down? Just when a commodity comes down in price, another one c...
Heads up: Companies can avoid criminal prosecution and million-dollar payouts for serious violations and mistakes by taking advantage of th...