Small Town Tech, Inc.
  • Home
  • Services
  • Online Store
  • Rates
  • Pro+Tech
    • Free Trial
  • Partner Client
    • Backup Solutions
Chat
Picture
Easy to understand and relevant technology articles

Categories

All
Backup
Business
Facebook
Guides
Hardware
Online Security
Safety
Windows

Archives

November 2021
October 2021
September 2021
August 2021
July 2021
June 2021
May 2021
April 2021

Fake Invoice Attacks Are on the Rise - Here’s How to Spot (and Beat) Them

6/14/2021

Comments

 
Picture

Fake Invoice Attacks Are on the Rise - Here’s How to Spot (and Beat) Them

Businesses around the world are being struck with a cyber-attack that sends victims a fake invoice that looks real enough to fool to most employees. It’s an old scam that used to see bills faxed or mailed in, but it’s made its way into the digital world and instances are on the rise.

Chances are you’ve already seen some of the less effective attempts, like an email advising your domain is expiring, except it’s not from your host and your domain is nowhere near expiration. These new attacks are more advanced, in that they look completely legitimate and are often from contractors/suppliers you actually use. Logos are correct, spelling and grammar are spot on, and they might even refer to actual work or invoice numbers. The sender name may also be the normal contact you’d associate with that business, or even a co-worker, as cybercriminals are able to effectively ‘spoof’ real accounts and real people. While it’s worrying that they know enough about your business to wear that disguise so well, a successful attack relies on you not knowing what to look for, or even that fakes are a possibility. With that in mind, here are two types of invoice attacks you might receive:

The Payment Redirect
This style of fake invoice either explicitly states payment should be made to a certain account, perhaps with a friendly note about the new details, or includes a payment link direct to the new account. Your accounts payable person believes they’re doing the right thing by resolving the invoice and unwittingly sends company money offshore. The problem usually isn’t discovered until the real invoice from the real supplier comes in or the transaction is flagged in an audit. Due to the nature of international cybercrime, it’s unlikely you’ll be able to recover the funds even if you catch it quickly.

The Malware Click - Rather than go for the immediate cash grab, this style of attack asks your employee to click a link to download the invoice. The email may even look like the ones normally generated by popular accounting tools like Quickbooks or Xero, making the click seem safe. Once your employee has clicked the link, malware is downloaded that can trigger ransomware or data breaches. While an up-to-date anti-virus should block the attack at that stage, it’s not always guaranteed, especially with new and undiscovered malware. If it does get through, the malware quickly embeds itself deep into your systems, often silently lurking until detected or activated.

How to Stay Safe
Awareness is key to ensuring these types of attacks have no impact on your business. As always, keep your anti-virus and spam filters up to date to minimize the risk of the emails getting through in the first place. Then, consider implementing a simple set of procedures regarding payments.These could include verifying account changes with a phone call (to the number you have on record, not the one in the email), double checking invoices against work orders, appointing a single administrator to restrict access to accounts, or even two-factor authorization for payments. Simple pre-emptive checks like hovering the mouse over any links before clicking and quickly making sure it looks right can also help. Like your own business, your contractors and suppliers are extra careful with their invoicing, so if anything looks off - even in the slightest - hold back on payment/clicking until it’s been reviewed. Fake invoices attacks may be increasing, but that doesn’t mean your business will become a statistic, especially now that you know what’s going on and how you can stop them.


If you're looking for a good anti-virus solution that includes local tech team on hand - try our offer! 
Picture
Comments
    More Pro+Tips

    Pro+Tips

    We aim to provide helpful and easy to understand tech articles. 

    Some article relate to products that we sell, so we may link to products or services that we offer.

    Good advice is good advice whether you purchase our products or a competitors.
    ​Our main goal for Pro+Tips is to give you advice and best practices.


    Categories

    All
    Backup
    Business
    Facebook
    Guides
    Hardware
    Online Security
    Safety
    Windows

    Archives

    November 2021
    October 2021
    September 2021
    August 2021
    July 2021
    June 2021
    May 2021
    April 2021

Help & Support

 218-240-8802
304 3rd Street
​International Falls, MN 56649

Ticket Status

Open Monday through Friday 9AM-5PM

Closed Saturday and Sunday

Services

Pro+Tech
Rates
Equipment Rental

Company

About
Careers
Partners
Terms
Privacy
Small Town Tech Inc
Protech Complete Technology Care
  • Home
  • Services
  • Online Store
  • Rates
  • Pro+Tech
    • Free Trial
  • Partner Client
    • Backup Solutions