• FREE RESOURCES
        • Accounts Payable
          Finally! The trick to securing greater T&E compliance
          Benefits
          Rooting out folks who don’t belong on your health plan: A 6-point dependent audit checklist
          IT
          3 costly misconceptions about biz email compromise
          Credit and Collections
          Collecting via email: 4 must-make moves in your subject line
          Accounts Payable
          5 Tough-to-spot signs that an invoice is fake
  • PREMIUM CONTENT
        • Staff management
          120 Proven Communications Tips for Today’s CFO
        • Payroll
          Handling Nonexempt Employee Pay: Stay Compliant and Avoid DOL Audits
          Accounts Payable
          T&E Best Practices: Complete Guide to Ensure Compliance
          Payroll
          Payroll Best Practices: 4 Ways to Save Time and Money
        • Staff management
          Email Best Practices: A 6-Question Quiz
          Staff management
          Innovative Communications Strategies: An Email Case Study
          Staff management
          A 5-part Framework for Successful Workplace Communications
        • SEE MORE
          PREMIUM RESOURCES
  • CORONAVIRUS RESOURCES
  • LOG IN
  • SIGN UP FOR FREE

Resourceful Finance Pro

  • FREE RESOURCES
        • Accounts Payable
          Finally! The trick to securing greater T&E compliance
          Benefits
          Rooting out folks who don’t belong on your health plan: A 6-point dependent audit checklist
          IT
          3 costly misconceptions about biz email compromise
          Credit and Collections
          Collecting via email: 4 must-make moves in your subject line
          Accounts Payable
          5 Tough-to-spot signs that an invoice is fake
  • PREMIUM CONTENT
        • Staff management
          120 Proven Communications Tips for Today’s CFO
        • Payroll
          Handling Nonexempt Employee Pay: Stay Compliant and Avoid DOL Audits
          Accounts Payable
          T&E Best Practices: Complete Guide to Ensure Compliance
          Payroll
          Payroll Best Practices: 4 Ways to Save Time and Money
        • Staff management
          Email Best Practices: A 6-Question Quiz
          Staff management
          Innovative Communications Strategies: An Email Case Study
          Staff management
          A 5-part Framework for Successful Workplace Communications
        • SEE MORE
          PREMIUM RESOURCES
  • CORONAVIRUS RESOURCES
  • Accounts Payable
  • Credit and Collections
  • Payroll
  • Accounting
  • Benefits
  • Finance Technology
  • Sales & Use Tax
  • More
    • Employment Law
    • Strategy
    • Policy and Culture
    • Fraud
    • Budgeting and Forecasting
    • Banking
    • Staff Management
    • Cost Control
  • Credit and Collections
  • Fraud
3 minute read

The $790M cash threat that’s blindsiding Finance

Jared Bilski
by Jared Bilski
November 12, 2015
  • SHARE ON

impostor fraud

Impostor fraud. Business email compromise. Supply chain fraud. Call it whatever you’d like, but the reality is this: Criminals are finding ways to impersonate company execs or trusted vendors and steal employers’ cash with alarming ease.

Here’s just one example: A fraudster hacks into a company vendor’s email, reads back and forth emails, learns about the vendor’s invoicing process and then makes a move on a vulnerable staffer such as an A/P clerk.

Because the fraudster is familiar with the company’s processes, he doesn’t have much trouble convincing the A/P staffer that the vendor’s payment instructions have changed and getting money diverted into his own account.

Authorities estimate impostor fraud costs U.S. businesses an alarming $789.9 million annually. And that’s probably a low-ball figure, considering this type of fraud is often under-reported.

After being the target of impostor fraud, Andrew Ubel, the chief intellectual property counsel for Valspar Corporation, worked with his bank to create a safer, more secure system where vendor accounts couldn’t be changed and exploited by fraudsters.

At the 2015 Association for Financial Professionals Conference in Denver, Ubel hosted a presentation on the steps his company and its bank took to prevent fraud.

No value in account numbers

Ubel saw a number of data field and automatic processes where vendors’ account numbers were at risk — and he didn’t see the value in having those account number in the vendor master file to begin with.

So the company identified every place in the system that stored vendor bank account numbers, analyzed the employees who had access to those fields and data, and conducted a penetration test to check the security.

What the company found: There were a number of username/passwords in the database that could potentially get access to payments as well as several processes where this could take place. Because the company’s payments were encrypted, a protection A/P assured Ubel made the process extremely safe, fraudulent payments would’ve looked like standard vendor payments and could’ve easily been missed.

To fix this vulnerability, Ubel worked with his banking institution to remove the risk. The company deleted all vendor bank account numbers from its system. In place of the account numbers, vendor identification numbers — numbers that weren’t linked to bank account info — were created and A/P sent the bank secure payment files.

Back in the bank’s hands

Thanks to the change, the company’s bank — not the company’s employees — was then charged with handling every change to a vendor’s account.

When there’s a change, the bank put a number of safeguards in place. First, the bank will confirm the vendor’s identity by requesting the special vendor ID. Next, the bank sends a physical letter to vendor about the change. From there, the vendor must visit a secure portal where the bank makes the change itself.

Thanks to these procedure changes, the company has virtually eliminated its chances of falling victim to the type of impostor fraud that is wreaking havoc on so many of its peers.

Adapted from “Valspar Tackles Impostor Fraud Head On,” by Andrew Ubel (Valspar Corporation) and Angela Melzark (Wells Fargo), as presented at the 2015 Association for Financial Professionals Conference in Denver.

 

 

Get the

Resourceful Finance Pro Logo

Newsletter

With Resourceful Finance Pro arriving in your inbox, you will never miss critical stories on accounting, benefits, payroll & employment law strategies.

  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • This field is for validation purposes and should be left unchanged.
Resourceful Finance Pro Logo
  • ABOUT
  • CONTACT
  • WRITE FOR US
  • ADVERTISE WITH US

Resourceful Finance Pro, part of the SuccessFuel Network, provides the latest Finance and employment law news for Finance professionals in the trenches of small-to-medium-sized businesses. Rather than simply regurgitating the day's headlines, Resourceful Finance Pro delivers actionable insights, helping Finance execs understand what Finance trends mean to their business.

Privacy Policy | Terms of Service
Copyright © 2022 SuccessFuel

WELCOME BACK!

Enter your username and password below to log in

Forget Your Username or Password?

Reset Password

Lost your password? Please enter your username or email address. You will receive a link to create a new password via email.

Log In

During your free trial, you can cancel at any time with a single click on your “Account” page.  It’s that easy.

preloader