ISM-1740

Personnel dealing with banking details and payment requests are advised of what business email compromise is, how to manage such situations and how to report it.

Topic
Managing and reporting suspicious changes to banking details or payment requests
Applicable to
all

History

Mar 2022
Personnel dealing with banking details and payment requests are advised of what business email compromise is, how to manage such situations and how to report it.
Business email compromise, a form of financial fraud, is when an adversary attempts to scam an organisation out of money or assets with the assistance of a compromised email account. In dealing with such situations, personnel should have clear guidance to verify bank account details, think critically before actioning unusual payment requests, and have a process to report threatening demands for immediate action, pressure for secrecy or requests to circumvent normal business processes and procedures.