Funds transfer fraud is becoming an increasingly common problem for most modern organisations. Fraudsters dupe innocent businesses and individuals into transferring what they believe are legitimate payments to fraudulent bank accounts.
However, it’s not always a business that can suffer a loss in this way, but it’s customers too. Customer payment fraud occurs when a fraudster poses as a business and deceives customers into transferring money to a fraudulent account. This type of fraud involves tricking customers by pretending to be a legitimate business. The fraudster convinces customers to send money to a fake account that they control.
One business affected by such a loss was a private, tuition-paying school responsible for educating 11-to-18-year-olds. The school in question has boarding facilities in place and attracts students from many different countries around the world.
Lack of multi-factor authentication lets fraudster in
The scam began when the school’s bursar fell for a credential phishing email. Credential phishing emails are used by scammers to trick people into handing over their login details, typically by directing them to a link that takes them to a fake login page.
In this case, the bursar received an email from what appeared to be Microsoft, asking him to validate his account details online. The bursar clicked on the link provided, which took him to an authentic-looking landing page where he inputted his email login details.
Despite appearances, however, the landing page was actually fake, and the bursar had unwittingly volunteered his email login details to a fraudster. What’s more, his email account didn’t have multi- factor authentication in place, so the fraudster was then able to access the account remotely and gather valuable information including the personal data of students and their parents.
Multi-factor authentication (MFA) is an authentication process that is used to ensure that a person is who they say they are by requiring a minimum of two pieces of unique data that corroborates their identity. Most cases of business email compromise could be prevented by implementing it.
Implementing MFA can be a simple process, depending on the system or account you are trying to secure. Many popular online services, such as Google and Facebook, offer MFA as an option for users to enable. For businesses, there are various MFA solutions available that can be integrated into existing systems and the best place to start is by talking to your IT department or service provider.
Scam initiated with offer of discount
Having spotted an opportunity, the fraudster moved on to the next stage of their scam. Their first step was to set up an email address that looked substantially similar to the bursar’s, but with the addition of an extra letter to the address line. So instead of saying @abcschool.com, it became @abcscchool.com.
The next step was to carefully select which parents to target. Rather than adopting a scatter gun approach and emailing every parent on the list, the fraudster specifically selected parents based overseas.
With the targets selected, the fraudster sent out an email about school fees. The email offered a discount of up to 25 percent if parents paid for the spring and summer terms in one lump sum.To add a sense of urgency, the email stated there was a deadline for the offer.
Social engineering attacks rely on manipulating and exploiting typical human behaviours, and in this case the fraudster knew the scam would have a better chance of success if the parents were provided with an incentive to make the payment within a set time frame.
In addition, the email was well thought through and included a number of features to make it appear more authentic. For example, not only did the fraudster use proper spelling and grammar and include the bursar’s genuine email signature, he also went on to state that if the student was unable to complete the academic year for whatever reason, then the fees would be reimbursed on a pro-rata basis.
School’s security breach puts parents out of pocket
Unfortunately, this offer proved to be too tempting for some and six parents fell for the scam, transferring the tuition and boarding fees over to the fraudulent account details provided on the email. With tuition and boarding fees at the school costing some £10,050 per term, the amount paid out by each parent at a 25% discount amounted to some £15,075.
It was only after a few days, when one of the parents that had received the email forwarded it to one of the school’s administrators to check the validity of the discount offer that the school became aware of the scam. The school immediately notified all parents about the scam and urged them to be aware of any suspicious emails that appeared to have come from the school.
Of the six parents affected, just two were able to get their money back
The parents that fell for the scam reported the incident to their respective banks to see if the transaction could be either frozen or reversed, with mixed results. Of the six parents affected, just two were able to get their money back, with the rest left out of pocket to the tune of £60,300 collectively.
As it was a compromise of one of the school’s email accounts that had allowed the fraudster to gain access to the parents’ email addresses, the school felt morally obliged to reimburse those parents affected by the fraud. Fortunately, the school was then able to recoup most of this loss under the cybercrime section of its business insurance policy.
A lesson learned
This case study highlights the need for customer payment fraud cover in cyber policies. Many cyber policies with crime sections will only provide cover for losses that directly affect a policyholder. But in this instance, it wasn’t the school that suffered a direct loss but its customers.
With more and more financial transactions being carried out electronically and with more and more cyber criminals looking to intercept them, the chances of a business’s customers falling for scams of this nature are only increasing and it’s usually the business that has been impersonated that will take the blame. That’s why it’s a good idea to check your cyber policy for customer payment fraud cover.
About cyber insurance
Cyber security insurance is a type of insurance coverage that helps protect individuals and businesses from financial losses resulting from cyber attacks and data breaches. It provides coverage for various aspects of cyber risks, including liability for data breaches, business interruption, and the costs associated with restoring systems and data. This insurance can help mitigate the financial impact of cyber incidents and provide resources to recover from them.
To discuss your cyber cover, call our friendly team at Rowett Insurance today on 01726 871144 option 3.



