• FREE RESOURCES
        • Accounts Payable
          Finally! The trick to securing greater T&E compliance
          Benefits
          Rooting out folks who don’t belong on your health plan: A 6-point dependent audit checklist
          IT
          3 costly misconceptions about biz email compromise
          Credit and Collections
          Collecting via email: 4 must-make moves in your subject line
          Accounts Payable
          5 Tough-to-spot signs that an invoice is fake
  • PREMIUM CONTENT
        • Staff management
          120 Proven Communications Tips for Today’s CFO
        • Payroll
          Handling Nonexempt Employee Pay: Stay Compliant and Avoid DOL Audits
          Accounts Payable
          T&E Best Practices: Complete Guide to Ensure Compliance
          Payroll
          Payroll Best Practices: 4 Ways to Save Time and Money
        • Staff management
          Email Best Practices: A 6-Question Quiz
          Staff management
          Innovative Communications Strategies: An Email Case Study
          Staff management
          A 5-part Framework for Successful Workplace Communications
        • SEE MORE
          PREMIUM RESOURCES
  • CORONAVIRUS RESOURCES
  • LOG IN
  • SIGN UP FOR FREE

Resourceful Finance Pro

  • FREE RESOURCES
        • Accounts Payable
          Finally! The trick to securing greater T&E compliance
          Benefits
          Rooting out folks who don’t belong on your health plan: A 6-point dependent audit checklist
          IT
          3 costly misconceptions about biz email compromise
          Credit and Collections
          Collecting via email: 4 must-make moves in your subject line
          Accounts Payable
          5 Tough-to-spot signs that an invoice is fake
  • PREMIUM CONTENT
        • Staff management
          120 Proven Communications Tips for Today’s CFO
        • Payroll
          Handling Nonexempt Employee Pay: Stay Compliant and Avoid DOL Audits
          Accounts Payable
          T&E Best Practices: Complete Guide to Ensure Compliance
          Payroll
          Payroll Best Practices: 4 Ways to Save Time and Money
        • Staff management
          Email Best Practices: A 6-Question Quiz
          Staff management
          Innovative Communications Strategies: An Email Case Study
          Staff management
          A 5-part Framework for Successful Workplace Communications
        • SEE MORE
          PREMIUM RESOURCES
  • CORONAVIRUS RESOURCES
  • Accounts Payable
  • Credit and Collections
  • Payroll
  • Accounting
  • Benefits
  • Finance Technology
  • Sales & Use Tax
  • More
    • Employment Law
    • Strategy
    • Policy and Culture
    • Fraud
    • Budgeting and Forecasting
    • Banking
    • Staff Management
    • Cost Control
  • Accounts Payable
  • Fraud
2 minute read

Purchase order cyberattacks: 7 due diligence steps to take with all vendor emails to A/P

Brian Bingaman
by Brian Bingaman
March 7, 2023
  • SHARE ON

Increasingly clever cybercriminals are out to take your company’s money. They’d even stoop so low as hacking you with a purchase order that looks real.

For example, emails with an attachment disguised as a purchase order can contain links to a bogus site that looks real enough to trick users into sharing sensitive account information.

Because of the volume of email your team handles, and because sometimes these emails can slip though both spam filters and your external sender email warning filter, you could be vulnerable to an attack (or a fraudulent billing scheme) that’ll cost a lot of money to mitigate.

Purchase order attachment best practices

Some important security reminders to pass along to finance staffers:

  1. Remember that malicious links can easily be hidden in Word documents and PDFs. The only truly safe attachment format is a .txt file.
  2. Double-check email sender details. If the sender is unfamiliar or if something seems off about the address, it could be suspicious.
  3. Remember that organizations like Microsoft, your company’s energy suppliers, IRS, the U.S. Postal Service and many more, generally don’t send emails to ask you to open a website to restore some setting or open a purchase order or an invoice.
  4. If an email attachment comes from someone you know, but normally doesn’t send purchase orders, hold off on opening it and call the sender to verify that it came from them.
  5. Be suspicious of any email that asks you to open an attachment, or click on a link, to specifically avoid a negative consequence (e.g., a late fee) or to gain something of value (e.g., an early payment discount).
  6. Be suspicious of any attachment that asks you to open an embedded link because scripting or editing is disabled.
  7. Don’t open personal emails on company-owned devices and vice-versa.

Finance also needs to watch for these

Speaking of links to malicious sites, your team needs to take extra care with their Google searches. The FBI’s Internet Crime Complaint Center has issued a warning about cybercriminals taking advantage of search engine advertising to impersonate brands and fool unsuspecting users into clicking on links that host ransomware and steal login credentials and other financial information.

Also, a purchase order warrants a closer look if any of these are involved:

  • Unexpected changes in pricing
  • Staffers processing on behalf of vendors outside of their normal job duties
  • Vaguely defined services
  • It’s been amended after the invoice has been submitted (An after-the-fact purchase order might just be a requisitioner, buyer or vendor that’s out of policy, and not necessarily committing fraud.)
  • Identical items purchased in different amounts simultaneously, or within short periods of time, or
  • Recurring purchases that fall just under your review/authorization thresholds.
Brian Bingaman
Brian Bingaman
Brian researches and writes about accounts payable and CFO management trends. He was a newspaper journalist in suburban Philadelphia for nearly 20 years.

Get the

Resourceful Finance Pro Logo

Newsletter

With Resourceful Finance Pro arriving in your inbox, you will never miss critical stories on accounting, benefits, payroll & employment law strategies.

  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • This field is for validation purposes and should be left unchanged.
Resourceful Finance Pro Logo
  • ABOUT
  • CONTACT
  • WRITE FOR US
  • ADVERTISE WITH US
  • Accounting
  • Benefits
  • Payroll
  • Policy and Culture
  • Employment Law
  • Fraud
  • Finance Technology
  • Sales & Use Tax
  • Accounts Payable
  • Credit and Collections
  • Strategy
  • Budgeting and Forecasting
  • Banking
  • Staff Management
  • Cost Control

Resourceful Finance Pro, part of the SuccessFuel Network, provides the latest Finance and employment law news for Finance professionals in the trenches of small-to-medium-sized businesses. Rather than simply regurgitating the day's headlines, Resourceful Finance Pro delivers actionable insights, helping Finance execs understand what Finance trends mean to their business.

Privacy Policy | Terms of Service
Copyright © 2023 SuccessFuel

WELCOME BACK!

Enter your username and password below to log in

Forget Your Username or Password?

Reset Password

Lost your password? Please enter your username or email address. You will receive a link to create a new password via email.

Log In

During your free trial, you can cancel at any time with a single click on your “Account” page.  It’s that easy.

preloader