We are often asked about email security and what can be done to prevent compromise. You will never be able to get 100% security, simply because the fraudsters pry on individuals to make mistakes by tempting them with emails that appear to be genuine. In many cases, the emails are extremely convincing, and many businesses have lost a great deal of money because of it!
Business email compromise is a type of fraud where either a business email account is hacked or a very similar email address is set up with subtle differences (such as the same company name but with a hyphen or number added), making it difficult to spot.
For example, a fraudster may email your business appearing to be an existing supplier, requesting payment for an invoice to new bank account details. This account will be under the fraudsterâs control.
So the doâs and donâts
- Never assume that an email received from a known email address (or with a previous email trail) is genuine. Check the email address carefully for discrepancies.
- Always check requests to pay funds to a new payee or different account details for an existing payee by using a known telephone number. Never verify by replying to the email and do not call the number on the email, this could have been edited by the fraudster.
- Enable Two Factor Authentication (2FA) – this is where a second verification is required, usually after you have entered your password. It is often in the form of a secure code provided to you by SMS or an authentication app.
- Never open unexpected file attachments or click links. Make sure you back up your data regularly and store it separately, either offline or in a different location. Also, scan your data backups for malware, as ransomware can be on a network for a period of time before being executed.
In summary, if in doubt âCheck it Outâ!

