Fraud Blog: Know Your Scams

09/24/2026

Stop Commercial Banking Fraud

Fraud targeting business accounts and payment activity is a significant concern for businesses of all sizes.

While every payment method has some level of risk, criminals tend to focus on certain types of transactions and account activity. At the same time, fraud schemes are becoming more convincing and increasingly incorporate tools such as AI. This makes it especially important for businesses to remain alert, monitor financial activity closely, and establish strong safeguards around their accounts and payment processes.

The Evolving Threat:

Business payment fraud is a significant concern. According to the Association for Financial Professionals’ 2026 Payments Fraud and Control Survey, 76% of businesses experienced attempted or actual payments fraud in 2025. Checks were the most frequently targeted payment method, with 58% of organizations reporting check fraud. Business email compromise was also widespread, affecting 74% of organizations during the year, while ACH and wire fraud affected 30% and 25%, respectively.

The Federal Reserve is also focused on the growing risk to businesses. Federal Reserve Financial Services reported that business email compromise was a leading cause of fraudulent ACH and wire transfers from business deposit accounts. In addition, a 2026 Federal Reserve risk officer survey found that financial institutions continue to see significant fraud involving checks, ACH transactions, wire transfers, account takeovers, and social engineering.

These trends demonstrate why businesses should not rely on a single fraud prevention measure. Strong payment controls, employee awareness, independent verification procedures, transaction monitoring, and timely review of account activity can all play an important role in reducing fraud risk.

 

Common Fraud Schemes and Ways Businesses Can Reduce Their Risk:

Check Fraud:

Paper checks can be particularly vulnerable to fraud on business accounts because a check contains several pieces of information that a criminal can potentially use or alter, including the business name, bank routing number, account number, check number, and signature.

Some of the main reasons include:

  • Checks can be stolen. Checks mailed to vendors or deposited through a mailbox can be intercepted before they reach the intended recipient.
  • Information can be altered. Fraudsters may use techniques such as check washing to change the payee or dollar amount on a legitimate check.
  • Checks can be copied. Criminals can create counterfeit checks using information from a legitimate business check.
  • Account information is exposed. Routing and account numbers printed on checks can potentially be used to create unauthorized transactions.
  • Signatures can be forged. A stolen check provides an opportunity for someone to attempt to reproduce an authorized signature.
  • Businesses often issue many checks. With a higher volume of transactions, an unauthorized check may be harder to notice without regular reconciliation or a fraud-monitoring service.
  • Checks can be intercepted after they are issued. Even when a business follows its normal payment procedures, the check can be altered or redirected after leaving the business’s control.

How to alleviate check fraud: Businesses can take several practical steps to reduce their exposure to check fraud. Keep blank check stock in a secure location and limit access to authorized employees. When mailing checks, use secure mailing practices and avoid leaving outgoing checks in an unsecured mailbox. Whenever possible, consider replacing paper checks with digital payment solutions, which can reduce the risks associated with stolen, altered, or counterfeit checks. Businesses can also use check-monitoring services, such as Positive Pay, to compare checks presented for payment against those the business has authorized, helping identify discrepancies before fraudulent items are paid.

ACH Fraud:

ACH transactions provide an efficient and convenient way to move funds electronically, but they can still be targeted by fraudsters. Unauthorized ACH debits may occur when criminals obtain account information or otherwise gain access to payment details. Fraudulent ACH activity can be difficult to identify before processing and, depending on the circumstances, recovering funds after an unauthorized transaction may be challenging.

Common indicators of potential ACH fraud include unfamiliar or unexpected ACH transactions, requests to change established payment information, communications urging immediate action, suspicious or slightly altered email addresses or domains, and attempts to circumvent established authorization or approval procedures. Customers should carefully verify payment instructions and promptly report any ACH activity they do not recognize.

How to alleviate ACH fraud: Businesses can reduce their exposure to ACH fraud by implementing strong controls over the authorization, initiation, and monitoring of electronic payments. Payment instructions and changes to account information should be independently verified through a trusted method rather than relying solely on email. Businesses should restrict ACH access to employees with a legitimate business need and regularly review account activity. Transaction monitoring services, such as Positive Pay, can provide an additional layer of protection by allowing businesses to review, approve, or reject ACH transactions that do not meet established criteria before funds are withdrawn.

Account takeover fraud:

Business account takeover fraud occurs when an unauthorized individual gains access to a business’s online banking, payment systems, email, or other financial accounts, often through compromised login credentials, phishing schemes, malware, or social engineering. Once access is obtained, the fraudster may alter passwords, security settings, user access, or contact information to prevent legitimate users from accessing the account. The criminal may then use the compromised account to initiate unauthorized payments, transfer funds, add or modify users, or make other changes designed to facilitate fraudulent activity.

Account takeover can be particularly difficult to identify when the unauthorized activity appears to originate from a legitimate user or trusted device. Businesses should be alert to unexpected changes to account settings or user permissions, unfamiliar login activity, new devices or locations, and password or contact information changes that were not requested

 How to alleviate account takeover fraud: Businesses can reduce their chances of account takeover fraud by using layered security controls and limiting access to financial systems based on each employee’s role and responsibilities. Strong, unique passwords should be required, and shared login credentials should be avoided. Employees should be trained to recognize phishing emails, suspicious links, social engineering attempts, and other methods used to obtain login credentials. Separating payment preparation from payment approval and requiring dual authorization for certain transactions can provide an additional safeguard.

Business email compromise:

Business Email Compromise (BEC) is a form of fraud in which criminals use compromised email accounts, spoofed addresses, or social engineering to impersonate a business owner, executive, employee, or trusted business partner. The fraudster may use the compromised or fraudulent email account to request payments, provide false payment instructions, obtain sensitive information, or persuade employees to bypass established procedures. BEC schemes can be difficult to recognize because the messages may appear legitimate and often reference actual business relationships or transactions. Warning signs include unexpected requests involving money or account information, changes to previously established payment instructions, unusual urgency or secrecy, requests to bypass normal approval procedures, and subtle changes in email addresses or domains.

 How to alleviate BEC: Businesses can reduce the risk of Business Email Compromise (BEC) by establishing clear procedures for verifying payment requests and changes to payment instructions. Employees should independently confirm unusual or high-dollar requests using a known telephone number or other trusted communication method rather than relying on the email itself. Strong email security, multifactor authentication, unique passwords, and regular monitoring for suspicious login activity can help protect business email accounts from compromise.

Vendor fraud:

Vendor fraud involves the use of deceptive practices to obtain unauthorized payments from a business by exploiting its relationships with suppliers, contractors, or service providers. Fraudsters may impersonate legitimate vendors, submit false or inflated invoices, create fictitious vendor accounts, or attempt to redirect legitimate payments to an account they control. In other cases, an individual with access to the business’s purchasing or payment processes may manipulate transactions for personal gain.

How to alleviate vendor fraud: Businesses can reduce the risk of vendor fraud by establishing strong controls over vendor onboarding, invoice processing, and payment changes. Vendor information should be independently verified before a new vendor is added or existing payment instructions are modified, with account changes confirmed using trusted contact information already on file. Regularly reviewing vendor accounts and comparing invoices against purchase orders, contracts, and prior billing can help identify unusual or duplicate charges.


Business Fraud Mitigation Best Practices:

Fraud prevention is most effective when businesses use multiple layers of controls rather than relying on a single safeguard. Here are some additional tips:

  • Establish strong internal controls. Develop clear policies for handling money, payments, sensitive information, purchasing, and financial records. Controls should include defined responsibilities and appropriate approval requirements.
  • Use segregation of duties. Whenever practical, separate the responsibilities for initiating, approving, recording, and reconciling financial transactions. No single employee should have complete control over a financial process.
  • Limit employee access. Provide employees with access only to the systems, information, and financial functions necessary for their job responsibilities. Review access periodically and immediately when an employee changes roles or leaves the organization.
  • Implement strong authentication. Require multifactor authentication where available, particularly for email, financial systems, payroll, and other sensitive applications. Employees should use unique passwords and avoid sharing credentials.
  • Train employees regularly. Provide ongoing education regarding phishing, social engineering, impersonation, fraudulent requests, cybersecurity threats, and other common fraud techniques. Employees should know how and where to report suspicious activity.
  • Maintain strong physical and cybersecurity controls. Protect computers, mobile devices, financial records, customer information, and other sensitive data. Keep software and security systems updated and restrict access to sensitive areas.
  • Control sensitive information. Limit access to customer, employee, financial, and business information. Establish procedures for securely storing, transmitting, and disposing of confidential records.

Yakima Federal is here to help!

At Yakima Federal, we’re proud to support the local businesses that help our community thrive. When you open an Advantage Business Checking account, you’ll have access to a suite of business banking services designed to make managing your finances easier while providing additional tools to help protect your business from fraud. Services such as:

Positive Pay: Positive Pay provides businesses with an added layer of protection by helping identify potentially fraudulent checks and ACH transactions before they result in a loss. For check transactions, the business provides information about checks it has issued, allowing exceptions to be identified when a check presented for payment does not match the business’s records. ACH Positive Pay similarly allows businesses to establish criteria for authorized ACH activity and review transactions that fall outside those parameters. When an exception is identified, the business can review the transaction and determine whether it should be paid or returned. By combining transaction monitoring with business-controlled review and decision-making, Positive Pay can help businesses detect unauthorized activity and reduce their exposure to payment fraud.

Account Alerts: Businesses enrolled in online banking can set up account alerts to stay informed about activity affecting their accounts. Alerts can be delivered by text or email and can notify you when your account balance rises above or falls below a specified threshold, a check clears the account, someone logs in to online banking, or other selected account activity occurs. These real-time notifications provide businesses with greater visibility into their account activity and can help identify unusual or unauthorized activity more quickly.

Cash Flow Central: Cash Flow Central provides businesses with a centralized, digital solution for managing payables and receivables while helping streamline everyday financial processes. Businesses can use the service to manage and pay bills electronically, reducing the need to write and mail paper checks and limiting the amount of check stock kept on hand. Moving more payments to a digital process can help reduce opportunities for checks to be lost, stolen, altered, or counterfeited, while also making it easier for businesses to manage and monitor their payment activity. For businesses that continue to issue paper checks, pairing Cash Flow Central with Positive Pay can provide an additional layer of protection against check fraud.

 

Key takeaways:

  • Fraud can take many forms. Businesses should understand the risks associated with ACH fraud, account takeover, business email compromise, vendor fraud, and other types of financial fraud.
  • Strong internal controls are the first line of defense. Segregation of duties, dual authorization, appropriate access controls, and independent reviews can help reduce opportunities for fraudulent activity.
  • Protect access to financial information. Strong passwords, multifactor authentication, limited user access, and regular access reviews can help protect business accounts and sensitive.
  • Monitor account activity. Account alerts, transaction monitoring, and services such as Positive Pay can help businesses identify unusual or potentially fraudulent activity sooner.

Fraud prevention starts with awareness and is strengthened through layers of protection. By combining sound business practices, employee education, account monitoring, and available fraud-prevention services, businesses can better protect their finances and reduce their exposure to fraud.

07/01/2026

“Your Computer Is Infected” Messages Are Usually a Scam

Have you ever received a pop-up message, text message, email, or phone call claiming that your computer is infected with a virus? These alarming messages are often scams designed to trick you into giving criminals access to your computer, personal information, or money.

 

How the Scam Works

Scammers create a sense of urgency by displaying messages that claim your computer has been infected, hacked, or compromised. The message may instruct you to:

  • Call a phone number immediately
  • Click a link to remove the virus
  • Download software to fix the problem
  • Allow remote access to your computer
  • Send payment to repair the issue

These messages often look official and may even use the names of well-known technology companies. However, their goal is to gain your trust and convince you to act before you have time to think.

 

Protect Yourself

If you receive a message claiming your computer is infected:

Do not call the phone number. Legitimate technology companies do not display random pop-up messages instructing customers to call for immediate support.

Do not click any links. Links may install malicious software or direct you to a fake website designed to steal your information.

Do not give anyone remote access to your computer. Once a scammer gains control of your device, they may be able to access personal information, online banking accounts, passwords, and sensitive files.

Never send money. Scammers often request payment through wire transfers, gift cards, cryptocurrency, or payment apps. They are even known to request cash be mailed to them via UPS or FedEx. Legitimate companies do not require these payment methods to fix computer issues.

 

What Should You Do If You Receive One of These Messages?

  1. Close the pop-up or message.
  2. Disconnect from the internet if you believe malicious software may have been installed.
  3. Run antivirus or security software from a trusted provider.
  4. Contact a trusted technology professional if you have concerns about your device.
  5. Monitor your financial accounts and report any suspicious activity immediately.

 

Remember

A legitimate company will not unexpectedly contact you to report a virus on your computer. If a message or caller pressures you to act immediately, requests remote access, or asks for payment, it is likely a scam.

When in doubt, stop, verify, and contact a trusted source directly before taking any action.

 


 

04/27/2026

The Good, the Bad, and the Ugly of Cryptocurrency: A Fraud-Focused Perspective

Cryptocurrency has moved from niche curiosity to mainstream conversation in less than a decade. For banks, customers, and employees alike, it represents both innovation and risk. While digital assets can offer speed, accessibility, and new financial opportunities, they also create fertile ground for fraud. Let’s dive in to Crypto and take a deeper look at key points that identify the Good, the Bad, and the Ugly.

 

The Good: Innovation with Real Benefits

Cryptocurrency and blockchain technology have introduced meaningful advancements:

  1. Faster Transactions
    Digital currencies can enable near-instant transfers, often with lower fees than traditional wire transfers.
  2. 24/7 settlement and liquidity
    Unlike traditional bank hours, crypto networks operate continuously which improves liquidity management and reduces delay during weekend and holidays
  3. Financial inclusion opportunities
    Cryptocurrencies can reach the unbanked who lack access to traditional financial systems. (Is this even a thing? Who wouldn’t want to bank at Yakima Federal?).

 

The Bad: A Growing Fraud Landscape

Where money flows, fraud follows, and cryptocurrency is no exception. In fact, its unique characteristics can make fraud more difficult to detect and recover from.

  1. Irreversible Transactions
    Unlike credit card payments or bank transfers, most cryptocurrency transactions cannot be reversed. Once funds are sent, recovery is unlikely.
  2. Anonymity and Pseudonymity
    While blockchain transactions are transparent, wallet owners are often anonymous. This makes it easier for fraudsters to hide their identities.
  3. Lack of Regulation in Some Areas
    Although regulations are evolving, gaps still exist. Fraudsters exploit loosely regulated platforms and jurisdictions.
  4. Social Engineering Scams
    Fraudsters frequently impersonate trusted entities—banks, government agencies, or even romantic partners to convince victims to transfer crypto.

Common examples include:

    • Investment scams promising guaranteed returns
    • Romance scams
    • Impersonation of authorities – IRS, Social Security, Law Enforcement
    • Job scams
    • Blackmail and extortion

 

The Ugly: When Fraud Gets Sophisticated

Crypto-related fraud has grown more complex, organized, and damaging.

  1. Large-Scale Investment Fraud Rings
    Criminal networks run highly coordinated operations, often targeting victims over weeks or months. Losses can reach life-changing amounts.
  2. Malware and Wallet Drainers
    Malicious software can steal private keys or trick users into signing fraudulent transactions.
  3. Deepfakes and AI-Driven Scams
    Fraudsters now use AI-generated voices and videos to impersonate executives, financial advisors, or even family members.
  4. Recovery Scams
    Victims of crypto fraud are often targeted again by “recovery services” that promise to retrieve lost funds, for a fee, only to scam them a second time.

 

Striking the Right Balance

Cryptocurrency isn’t inherently good or bad.  Like any financial tool, its impact depends on how it’s used. As a bank, our role is to embrace innovation responsibly while protecting our customers and communities from harm.

By staying informed, asking questions, and working together, we can reduce the risks while supporting the benefits of this rapidly evolving technology.

 

Stay informed. Stay cautious. Stay protected.

 


 

03/16/2026

Banks Never Ask That!

Scammers are increasingly posing as representatives from banks’ fraud departments to trick people into giving away money or personal information. These calls can sound legitimate and often create a sense of urgency.

It’s important to remember one simple rule:

Never provide personal or account information to anyone who contacts you claiming to be from your bank.


What a bank will NEVER ask you to do:

A legitimate bank employee will never:

  • Ask you to withdraw money and send it somewhere
  • Ask you to mail cash
  • Ask for your debit card number and PIN
  • Ask for your online banking username or password
  • Ask you to perform a transaction to “secure” your account

If someone asks you to do any of these things, it is a scam.


What a real Fraud Department actually does:

If your bank contacts you about suspicious activity, the conversation is simple.

They may ask you to verify recent transactions by asking questions like:

  • “Did you make this purchase?”
  • “Did you authorize this transaction?”

You should only need to answer yes or no.


A real example of how these scams work:

In a recent case, a scammer called an individual pretending to be from the bank’s fraud department. The caller convinced the customer to withdraw a bank check and a large amount of cash. They were then told to purchase a sweater and a pair of jeans, place the cash inside the jeans pocket, and ship the items through UPS.

The goal of this tactic was to make the package look like a normal shipment of clothing rather than cash.


Warning signs of a scam call:

Be cautious if someone claiming to be from your bank:

  • Creates urgent pressure to act immediately
  • Asks you to move money to another account
  • Instructs you to mail cash or packages
  • Requests passwords, PINs, or full card numbers
  • Asks you to keep the request secret

 

What you should do instead:

If you receive a call like this:

  • Hang up immediately.
  • Call your bank directly using a known phone number

Report the suspicious call. Taking a moment to verify could prevent significant financial loss.


Final Reminder:

Scammers rely on confusion, urgency, and trust. When in doubt, stop the conversation and contact your bank directly.

Your bank is always happy to help verify concerns and ensure your accounts remain secure.


 

02/05/2026

THE GRANDPARENT SCAM

In the first 3 months of 2025, Americans aged 60 and older lost more than $745 million to scams and that number is likely to increase over the first 3 months of 2026. One of the popular tactics scammers use to take advantage of older Americans is the Grandparent scam.

The Grandparent scam is a fraudulent scheme where a scammer poses as a grandchild in distress, tricking victims into sending money urgently. As a Grandparent myself, I would do anything to help my grandchild in their time of need, and most grandparents will likely do the same. Scammers know this too, and that’s why this scam works so well.

How does the Grandparent Scam Work?

  • A phone call is made from someone claiming to be a grandchild (or another family member). The caller sounds distressed or in a panic.
  • The caller fabricates a story, claiming to be in serious trouble and in need of help. This story could be about legal trouble, a car accident, or needing money for medical expenses.
  • The caller sounds urgent – money needs to be sent right away. Money is requested to be sent through the purchase of gift cards, wire transfer, or a payment platform, such as Cash App, Venmo, Zelle, etc.
  • The caller may ask that the situation remain a secret, so other family members don’t find out.

What should you do if you receive a call that you believe is a Grandparent Scam?

  • First, and foremost, DO NOT send any money to the caller until you can verify the person you are speaking with is your family member. You can do this by asking questions that only your grandchild will know the answer to, ie details about a recent family event or a personal nickname.
  • Verify the situation by calling your grandchild at a phone number you know belongs to them. Or, contact another family member that your grandchild is close to.
  • Remember scammers can spoof phone numbers and use AI resources to mimic someone’s voice to make the call sound legitimate.
  • If someone claims there’s an emergency, like an accident, arrest, or medical crisis, STOP and ask yourself whether the payment method makes sense. Real emergencies are never handled with gift cards, cryptocurrency deposits, or other unusual forms of payment.

If you reacted too quickly and sent the scammer money, what can you do?

  • It is uncommon to recover funds sent to a scammer, but that doesn’t mean you shouldn’t try. Contact whoever you used to send money. This could be your credit card company, the money transfer company (Western Union, MoneyGram), the gift card company, the cryptocurrency company, or the post office (if you mailed cash).
  • If you gave any of your personal information to the scammer, such as your Social Security Number, call each of the 3 credit bureaus and have a freeze placed on your credit report.
  • If you gave the scammer your username and password to any online banking systems, change your password right away and notify your financial institution.

Scammers succeed because they prey on love, trust, and fear. The best defense is awareness. Sharing this information with friends, neighbors, and fellow grandparents can help protect them from falling victim to a scam.

If you have any doubts about a phone call, pause, verify the information, and talk to someone you trust. Your loved ones would rather you double-check than fall victim to a scam.


 

09/22/2026

Commercial Banking Fraud

Fraud targeting business accounts and payment activity is a significant concern for businesses of all sizes.

While every payment method has some level of risk, criminals tend to focus on certain types of transactions and account activity. At the same time, fraud schemes are becoming more convincing and increasingly incorporate tools such as AI. This makes it especially important for businesses to remain alert, monitor financial activity closely, and establish strong safeguards around their accounts and payment processes.

The Evolving Threat:

Business payment fraud is a significant concern. According to the Association for Financial Professionals’ 2026 Payments Fraud and Control Survey, 76% of businesses experienced attempted or actual payments fraud in 2025. Checks were the most frequently targeted payment method, with 58% of organizations reporting check fraud. Business email compromise was also widespread, affecting 74% of organizations during the year, while ACH and wire fraud affected 30% and 25%, respectively.

The Federal Reserve is also focused on the growing risk to businesses. Federal Reserve Financial Services reported that business email compromise was a leading cause of fraudulent ACH and wire transfers from business deposit accounts. In addition, a 2026 Federal Reserve risk officer survey found that financial institutions continue to see significant fraud involving checks, ACH transactions, wire transfers, account takeovers, and social engineering.

These trends demonstrate why businesses should not rely on a single fraud prevention measure. Strong payment controls, employee awareness, independent verification procedures, transaction monitoring, and timely review of account activity can all play an important role in reducing fraud risk.

Common Fraud Schemes and Ways Businesses Can Reduce Their Risk:

Check Fraud:

Paper checks can be particularly vulnerable to fraud on business accounts because a check contains several pieces of information that a criminal can potentially use or alter, including the business name, bank routing number, account number, check number, and signature.

Some of the main reasons include:

  • Checks can be stolen. Checks mailed to vendors or deposited through a mailbox can be intercepted before they reach the intended recipient.
  • Information can be altered. Fraudsters may use techniques such as check washing to change the payee or dollar amount on a legitimate check.
  • Checks can be copied. Criminals can create counterfeit checks using information from a legitimate business check.
  • Account information is exposed. Routing and account numbers printed on checks can potentially be used to create unauthorized transactions.
  • Signatures can be forged. A stolen check provides an opportunity for someone to attempt to reproduce an authorized signature.
  • Businesses often issue many checks. With a higher volume of transactions, an unauthorized check may be harder to notice without regular reconciliation or a fraud-monitoring service.
  • Checks can be intercepted after they are issued. Even when a business follows its normal payment procedures, the check can be altered or redirected after leaving the business’s control.

How to alleviate check fraud: Businesses can take several practical steps to reduce their exposure to check fraud. Keep blank check stock in a secure location and limit access to authorized employees. When mailing checks, use secure mailing practices and avoid leaving outgoing checks in an unsecured mailbox. Whenever possible, consider replacing paper checks with digital payment solutions, which can reduce the risks associated with stolen, altered, or counterfeit checks. Businesses can also use check-monitoring services, such as Positive Pay, to compare checks presented for payment against those the business has authorized, helping identify discrepancies before fraudulent items are paid.

ACH Fraud:

ACH transactions provide an efficient and convenient way to move funds electronically, but they can still be targeted by fraudsters. Unauthorized ACH debits may occur when criminals obtain account information or otherwise gain access to payment details. Fraudulent ACH activity can be difficult to identify before processing and, depending on the circumstances, recovering funds after an unauthorized transaction may be challenging.

Common indicators of potential ACH fraud include unfamiliar or unexpected ACH transactions, requests to change established payment information, communications urging immediate action, suspicious or slightly altered email addresses or domains, and attempts to circumvent established authorization or approval procedures. Customers should carefully verify payment instructions and promptly report any ACH activity they do not recognize.

How to alleviate ACH fraud: Businesses can reduce their exposure to ACH fraud by implementing strong controls over the authorization, initiation, and monitoring of electronic payments. Payment instructions and changes to account information should be independently verified through a trusted method rather than relying solely on email. Businesses should restrict ACH access to employees with a legitimate business need and regularly review account activity. Transaction monitoring services, such as Positive Pay, can provide an additional layer of protection by allowing businesses to review, approve, or reject ACH transactions that do not meet established criteria before funds are withdrawn.

Account takeover fraud:

Business account takeover fraud occurs when an unauthorized individual gains access to a business’s online banking, payment systems, email, or other financial accounts, often through compromised login credentials, phishing schemes, malware, or social engineering. Once access is obtained, the fraudster may alter passwords, security settings, user access, or contact information to prevent legitimate users from accessing the account. The criminal may then use the compromised account to initiate unauthorized payments, transfer funds, add or modify users, or make other changes designed to facilitate fraudulent activity.

Account takeover can be particularly difficult to identify when the unauthorized activity appears to originate from a legitimate user or trusted device. Businesses should be alert to unexpected changes to account settings or user permissions, unfamiliar login activity, new devices or locations, and password or contact information changes that were not requested

            How to alleviate account takeover fraud: Businesses can reduce their chances of account takeover fraud by using layered security controls and limiting access to financial systems based on each employee’s role and responsibilities. Strong, unique passwords should be required, and shared login credentials should be avoided. Employees should be trained to recognize phishing emails, suspicious links, social engineering attempts, and other methods used to obtain login credentials. Separating payment preparation from payment approval and requiring dual authorization for certain transactions can provide an additional safeguard.

Business email compromise:

Business Email Compromise (BEC) is a form of fraud in which criminals use compromised email accounts, spoofed addresses, or social engineering to impersonate a business owner, executive, employee, or trusted business partner. The fraudster may use the compromised or fraudulent email account to request payments, provide false payment instructions, obtain sensitive information, or persuade employees to bypass established procedures. BEC schemes can be difficult to recognize because the messages may appear legitimate and often reference actual business relationships or transactions. Warning signs include unexpected requests involving money or account information, changes to previously established payment instructions, unusual urgency or secrecy, requests to bypass normal approval procedures, and subtle changes in email addresses or domains.

            How to alleviate BEC: Businesses can reduce the risk of Business Email Compromise (BEC) by establishing clear procedures for verifying payment requests and changes to payment instructions. Employees should independently confirm unusual or high-dollar requests using a known telephone number or other trusted communication method rather than relying on the email itself. Strong email security, multifactor authentication, unique passwords, and regular monitoring for suspicious login activity can help protect business email accounts from compromise.

Vendor fraud:

Vendor fraud involves the use of deceptive practices to obtain unauthorized payments from a business by exploiting its relationships with suppliers, contractors, or service providers. Fraudsters may impersonate legitimate vendors, submit false or inflated invoices, create fictitious vendor accounts, or attempt to redirect legitimate payments to an account they control. In other cases, an individual with access to the business’s purchasing or payment processes may manipulate transactions for personal gain.

How to alleviate vendor fraud: Businesses can reduce the risk of vendor fraud by establishing strong controls over vendor onboarding, invoice processing, and payment changes. Vendor information should be independently verified before a new vendor is added or existing payment instructions are modified, with account changes confirmed using trusted contact information already on file. Regularly reviewing vendor accounts and comparing invoices against purchase orders, contracts, and prior billing can help identify unusual or duplicate charges.


Business Fraud Mitigation Best Practices:

Fraud prevention is most effective when businesses use multiple layers of controls rather than relying on a single safeguard. Here are some additional tips:

  • Establish strong internal controls. Develop clear policies for handling money, payments, sensitive information, purchasing, and financial records. Controls should include defined responsibilities and appropriate approval requirements.
  • Use segregation of duties. Whenever practical, separate the responsibilities for initiating, approving, recording, and reconciling financial transactions. No single employee should have complete control over a financial process.
  • Limit employee access. Provide employees with access only to the systems, information, and financial functions necessary for their job responsibilities. Review access periodically and immediately when an employee changes roles or leaves the organization.
  • Implement strong authentication. Require multifactor authentication where available, particularly for email, financial systems, payroll, and other sensitive applications. Employees should use unique passwords and avoid sharing credentials.
  • Train employees regularly. Provide ongoing education regarding phishing, social engineering, impersonation, fraudulent requests, cybersecurity threats, and other common fraud techniques. Employees should know how and where to report suspicious activity.
  • Maintain strong physical and cybersecurity controls. Protect computers, mobile devices, financial records, customer information, and other sensitive data. Keep software and security systems updated and restrict access to sensitive areas.
  • Control sensitive information. Limit access to customer, employee, financial, and business information. Establish procedures for securely storing, transmitting, and disposing of confidential records.

Yakima Federal is here to help!

At Yakima Federal, we’re proud to support the local businesses that help our community thrive. When you open an Advantage Business Checking account, you’ll have access to a suite of business banking services designed to make managing your finances easier while providing additional tools to help protect your business from fraud. Services such as:

Positive Pay: Positive Pay provides businesses with an added layer of protection by helping identify potentially fraudulent checks and ACH transactions before they result in a loss. For check transactions, the business provides information about checks it has issued, allowing exceptions to be identified when a check presented for payment does not match the business’s records. ACH Positive Pay similarly allows businesses to establish criteria for authorized ACH activity and review transactions that fall outside those parameters. When an exception is identified, the business can review the transaction and determine whether it should be paid or returned. By combining transaction monitoring with business-controlled review and decision-making, Positive Pay can help businesses detect unauthorized activity and reduce their exposure to payment fraud.

Account Alerts: Businesses enrolled in online banking can set up account alerts to stay informed about activity affecting their accounts. Alerts can be delivered by text or email and can notify you when your account balance rises above or falls below a specified threshold, a check clears the account, someone logs in to online banking, or other selected account activity occurs. These real-time notifications provide businesses with greater visibility into their account activity and can help identify unusual or unauthorized activity more quickly.

Cash Flow Central: Cash Flow Central provides businesses with a centralized, digital solution for managing payables and receivables while helping streamline everyday financial processes. Businesses can use the service to manage and pay bills electronically, reducing the need to write and mail paper checks and limiting the amount of check stock kept on hand. Moving more payments to a digital process can help reduce opportunities for checks to be lost, stolen, altered, or counterfeited, while also making it easier for businesses to manage and monitor their payment activity. For businesses that continue to issue paper checks, pairing Cash Flow Central with Positive Pay can provide an additional layer of protection against check fraud.

 

Key takeaways:

  • Fraud can take many forms. Businesses should understand the risks associated with ACH fraud, account takeover, business email compromise, vendor fraud, and other types of financial fraud.
  • Strong internal controls are the first line of defense. Segregation of duties, dual authorization, appropriate access controls, and independent reviews can help reduce opportunities for fraudulent activity.
  • Protect access to financial information. Strong passwords, multifactor authentication, limited user access, and regular access reviews can help protect business accounts and sensitive.
  • Monitor account activity. Account alerts, transaction monitoring, and services such as Positive Pay can help businesses identify unusual or potentially fraudulent activity sooner.

 

Fraud prevention starts with awareness and is strengthened through layers of protection. By combining sound business practices, employee education, account monitoring, and available fraud-prevention services, businesses can better protect their finances and reduce their exposure to fraud.