email icon on computer screen

Cyber Insurance Focus: How Scammers Steal Your Funds

Funds transfer fraud is becoming an increasingly common problem for most modern organisations. Fraudsters dupe innocent businesses and individuals into transferring what they believe are legitimate payments to fraudulent bank accounts.

However, it’s not always a business that can suffer a loss in this way, but it’s customers too. Customer payment fraud occurs when a fraudster poses as a business and deceives customers into transferring money to a fraudulent account. This type of fraud involves tricking customers by pretending to be a legitimate business. The fraudster convinces customers to send money to a fake account that they control.

One business affected by such a loss was a private, tuition-paying school responsible for educating 11-to-18-year-olds. The school in question has boarding facilities in place and attracts students from many different countries around the world.

Lack of multi-factor authentication lets fraudster in

The scam began when the school’s bursar fell for a credential phishing email. Credential phishing emails are used by scammers to trick people into handing over their login details, typically by directing them to a link that takes them to a fake login page.

In this case, the bursar received an email from what appeared to be Microsoft, asking him to validate his account details online. The bursar clicked on the link provided, which took him to an authentic-looking landing page where he inputted his email login details.

Despite appearances, however, the landing page was actually fake, and the bursar had unwittingly volunteered his email login details to a fraudster. What’s more, his email account didn’t have multi- factor authentication in place, so the fraudster was then able to access the account remotely and gather valuable information including the personal data of students and their parents.

Multi-factor authentication (MFA) is an authentication process that is used to ensure that a person is who they say they are by requiring a minimum of two pieces of unique data that corroborates their identity. Most cases of business email compromise could be prevented by implementing it.

Implementing MFA can be a simple process, depending on the system or account you are trying to secure. Many popular online services, such as Google and Facebook, offer MFA as an option for users to enable. For businesses, there are various MFA solutions available that can be integrated into existing systems and the best place to start is by talking to your IT department or service provider.

Scam initiated with offer of discount

Having spotted an opportunity, the fraudster moved on to the next stage of their scam. Their first step was to set up an email address that looked substantially similar to the bursar’s, but with the addition of an extra letter to the address line. So instead of saying @abcschool.com, it became @abcscchool.com.

The next step was to carefully select which parents to target. Rather than adopting a scatter gun approach and emailing every parent on the list, the fraudster specifically selected parents based overseas.

With the targets selected, the fraudster sent out an email about school fees. The email offered a discount of up to 25 percent if parents paid for the spring and summer terms in one lump sum.To add a sense of urgency, the email stated there was a deadline for the offer.

Social engineering attacks rely on manipulating and exploiting typical human behaviours, and in this case the fraudster knew the scam would have a better chance of success if the parents were provided with an incentive to make the payment within a set time frame.

In addition, the email was well thought through and included a number of features to make it appear more authentic. For example, not only did the fraudster use proper spelling and grammar and include the bursar’s genuine email signature, he also went on to state that if the student was unable to complete the academic year for whatever reason, then the fees would be reimbursed on a pro-rata basis.

School’s security breach puts parents out of pocket

Unfortunately, this offer proved to be too tempting for some and six parents fell for the scam, transferring the tuition and boarding fees over to the fraudulent account details provided on the email. With tuition and boarding fees at the school costing some £10,050 per term, the amount paid out by each parent at a 25% discount amounted to some £15,075.

It was only after a few days, when one of the parents that had received the email forwarded it to one of the school’s administrators to check the validity of the discount offer that the school became aware of the scam. The school immediately notified all parents about the scam and urged them to be aware of any suspicious emails that appeared to have come from the school.

Of the six parents affected, just two were able to get their money back

The parents that fell for the scam reported the incident to their respective banks to see if the transaction could be either frozen or reversed, with mixed results. Of the six parents affected, just two were able to get their money back, with the rest left out of pocket to the tune of £60,300 collectively.

As it was a compromise of one of the school’s email accounts that had allowed the fraudster to gain access to the parents’ email addresses, the school felt morally obliged to reimburse those parents affected by the fraud. Fortunately, the school was then able to recoup most of this loss under the cybercrime section of its business insurance policy.

A lesson learned

This case study highlights the need for customer payment fraud cover in cyber policies. Many cyber policies with crime sections will only provide cover for losses that directly affect a policyholder. But in this instance, it wasn’t the school that suffered a direct loss but its customers.

With more and more financial transactions being carried out electronically and with more and more cyber criminals looking to intercept them, the chances of a business’s customers falling for scams of this nature are only increasing and it’s usually the business that has been impersonated that will take the blame. That’s why it’s a good idea to check your cyber policy for customer payment fraud cover.

About cyber insurance

Cyber security insurance is a type of insurance coverage that helps protect individuals and businesses from financial losses resulting from cyber attacks and data breaches. It provides coverage for various aspects of cyber risks, including liability for data breaches, business interruption, and the costs associated with restoring systems and data. This insurance can help mitigate the financial impact of cyber incidents and provide resources to recover from them.

To discuss your cyber cover, call our friendly team at Rowett Insurance today on 01726 871144 option 3.

a business woman with a mobile phone in an office

Learn more about business insurance add-ons

When it comes to protecting your business, having insurance is essential. However, many business owners are not aware of the full range of add-ons available to them when it comes to business insurance in the UK. In this blog, we will explore some of the lesser-known add-ons for business insurance in the UK.

Cyber Insurance

In today’s digital age, cyber-attacks have become increasingly common. Cyber insurance provides coverage for losses resulting from cyber-attacks, such as data breaches, cyber extortion, and business interruption due to cyber incidents. This type of insurance can also provide assistance with managing the fallout of a cyber-attack, including the cost of public relations and legal advice.

Directors and Officers Liability Insurance

Directors and officers liability insurance protects the personal assets of company directors and officers in the event of legal action being taken against them. This type of insurance provides coverage for legal expenses, settlements, and judgments resulting from alleged wrongful acts, such as breach of fiduciary duty, negligence, and financial mismanagement.

Professional Indemnity Insurance

Professional indemnity insurance is a type of insurance that protects businesses that provide professional services, such as architects, accountants, and consultants, against claims of negligence, errors, or omissions made in the course of their work. Professional indemnity insurance covers the cost of legal defence and any damages awarded to the claimant.

Business Interruption Insurance

Business interruption insurance provides coverage for losses resulting from events that cause a business to close temporarily, such as a fire, flood, or other natural disaster. Business Interruption insurance covers the costs of lost revenue, ongoing expenses, and the cost of getting the business back up and running.

Terrorism Insurance

Terrorism insurance provides coverage for losses resulting from acts of terrorism. This type of insurance is particularly relevant for businesses that operate in high-risk areas or industries, such as transportation or finance.

Having the right insurance in place can protect your business from a wide range of risks. It’s important to work with a reputable insurance broker to ensure you have the right level of coverage for your business’s needs. By exploring the lesser-known add-ons for business insurance in the UK, you can ensure that you have comprehensive coverage to protect your business in the event of unforeseen circumstances. Want to know more about how you can boost your business insurance? Get in touch with us on 01726 871144.

a padlock on a computer keyboard

The importance of cyber insurance for small businesses

In today’s digital age, small businesses face numerous risks related to cyber threats. With the world becoming increasingly dependent on technology, cybersecurity has become a necessity for small business owners. Cyber insurance is an essential tool that can help mitigate these risks and protect businesses from potential financial losses.

43 percent of all cyberattacks target SMEs

Small businesses are increasingly becoming targets of cyber attacks. A study by Verizon shows that 43 percent of all cyberattacks target small businesses. These attacks can have significant financial implications for small businesses, and in some cases, lead to bankruptcy. Cyber insurance provides financial protection to businesses against these types of attacks.

Protecting your data

One of the most significant risks that small businesses face is data breaches. A data breach can occur when a business’s sensitive information is accessed by unauthorized individuals. This can lead to identity theft, financial loss, and damage to the business’s reputation. Cyber insurance can help cover the costs associated with a data breach, including legal fees, notification costs, and the cost of providing credit monitoring for affected individuals.

Increasing risk of ransomware attacks

Ransomware attacks are also becoming increasingly common among small businesses. Ransomware is a type of malware that encrypts a business’s files and demands payment in exchange for the decryption key. Cyber insurance can help businesses recover from a ransomware attack by covering the cost of data recovery and ransom payments.

Disrupting your day-to-day

Small businesses are also at risk of business interruption due to cyber attacks. For example, if a business’s website is taken down by a DDoS attack, they may lose revenue from online sales. Cyber insurance can help cover the costs associated with business interruption, including lost income and extra expenses incurred to get the business back up and running.

Additional layer of protection for businesses 

It’s important to note that cyber insurance is not a substitute for cybersecurity measures. Small businesses should still take steps to protect themselves from cyber threats, such as implementing strong passwords, encrypting sensitive data, and training employees on cybersecurity best practices. However, cyber insurance can provide an additional layer of protection for businesses that may not have the resources to implement robust cybersecurity measures.

In conclusion, cyber insurance is essential for small businesses to protect themselves from the financial losses associated with cyber attacks. With the increasing frequency and severity of cyber threats, cyber insurance has become a necessary investment for small business owners. By investing in cyber insurance, small businesses can safeguard their finances and continue to operate even in the face of cyber attacks. Want to know more? Get in touch with us on 01726 871144 option 3. Or head to our dedicated page on cyber insurance for more information.

a person hacking a computer network

How To Spot A Cyber Attack

Think that you could spot a cyberattack a mile away? 

Find out more about social engineering in Cyber Attacks

Gone are the days when the term phishing was associated with a leisurely Sunday afternoon activity and trees were the only victims of hacking. As we continue to make dramatic advancements in the digital and tech space, the threat of cybercriminals has grown significantly, and the methods used aren’t just limited to viruses and ransomware.

What is social engineering and how it is used in cyber-attacks?

When cybercriminals use social engineering tactics, they aim to psychologically manipulate their victims for their own gain. This often includes handing over sensitive information or transferring large amounts of money to an unknown account. These attacks can occur at any time, through text, email, phone calls and social media chat facilities.

What does a social engineering attack look like?

Social engineering attacks often appear to come from a trusted source such as a friend, relative or colleague. Or you may find they approach you as your banking, utility or broadband provider. The purpose of this impersonation is to gain your trust. 

Phishing

Most phishing attacks aim to obtain personal information from the victim. These are often opportunistic and use fear tactics based on what’s happening in the world at the time, such as the COVID-19 pandemic.  No two types of phishing attacks look the same so it’s important to remain constantly aware of this threat when working online.

Baiting

Very similar to phishing attacks, baiting uses the promise of free goods or services to encourage victims to hand over information. This tactic also takes advantage of our natural curiosity, asking us to click a link to uncover a mystery prize or access a piece of information.

Tailgating

Not all cyber-related attacks happen online. Tailgating attacks occur when a criminal attempts to access your office premises by tailgating an employee, playing on our instinct to be polite and hold the door open for the person behind us. Some criminals have even gone as far as to wear fake baby bumps to garner sympathy – because who would shut the door on a pregnant person?

Pretexting

Unlike phishing attacks which are usually conducted in mass, pretexting attacks try to build a believable scenario to establish trust before they try to obtain information. For example, you could receive an email from your CEO who states they’re about to enter an important meeting and need your password urgently to access a system. Or you may receive a call from your payroll team saying your payment didn’t go through this month and they need to check your account details. These types of attacks are designed to put pressure on the individual, so they act fast without careful consideration. 

How to recognise a social engineering attack

Cybercriminals are changing their methods all the time, so there’s no exact formula that makes up a social engineering attack – but there are red flags to look out for.

These include:

  • Requesting information or money access.
  • Evoking a sense of urgency in the email.
  • Short and concise.
  • Asking you to donate to a charitable cause.
  • Asking you to verify information.
  • Responding to a question you did not ask.
  • Using fear tactics – threats or intimidation.
  • Offering you something too good to be true.
  • How to protect yourself against a social engineering cyber attack.

When it comes to protecting yourself and your business against cybercrime, you need to remain vigilant and think before you click.

Training

Ensure that your staff are up to date with the latest cyber training, implementing measures to ensure it remains at the forefront of their minds. If you have a near miss, let people know about it.

Anti-virus software

While it doesn’t make you immune to a cyber-attack, it helps to create an extra barrier of defence with well-reputed anti-virus software. Look at setting your spam filters to high – although keep an eye on your junk mailbox to ensure nothing legitimate slips through the net!

Check the sender

Encourage your staff to always check the source if an email seems suspicious. As well as checking the email address itself, recipients can hover over links (don’t click them!) to see where they lead.

Simulate social engineering events  

It’s hard to know how you’re going to react to a social engineering attack until it happens. That’s why it’s a great idea to send test emails to your staff to see what they would do. Use this as a learning tool to educate them on what they should do if a real risk presents itself.

Monitor your digital footprint

Some of us tend to overshare on social media, giving hackers ammo to hack into our devices. But have you considered what you’re sharing outside of these platforms? For example, if your CV is online – are your address and phone number on this? Not to mention your old schools, interests… the list goes on. Think twice about what you share online. 

Get Cyber Insurance

Despite nearly 40% of all UK businesses reporting at least one cyber attack in the last 12 months, businesses are still not taking the threat of cyber attacks seriously enough. Now, the Government are urging businesses to take steps to improve their digital resilience. Cyber Insurance is designed to protect your business in the aftermath of an attack, including investigation, data recovery, loss of income, reputation management and more. To discuss how you can better protect your business with dedicated Cyber Insurance, give Rowett Insurance a call on 01726 871144 option 3.

More information: https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2022/cyber-security-breaches-survey-2022

a padlock on a computer keyboard

Multi-Factor Authentication – What is it and what it means for your business  

Have you heard of Multi-Factor Authentication or MFA? 

While it might not mean much to some of you, it’s about to become one of the buzzwords in the Cyber Insurance industry. Here’s why.

What is Multi-Factor Authentication?

Multi-Factor Authentication requires system users to go through two layers of identification to access control of a system. Think about the systems you access regularly. Your ATM for example, the first layer of identification is your debit card, the second is your PIN. Or when you enter your credit card details online, each piece of information you provide is a separate layer of authentication, including your card number, expiry date and security code. Many providers also ask you to verify the purchase using an app – another layer of authentication.

Something you know, something you have, something you are

Multi-Factor Authentication is sometimes referred to as:

Something you know: A username or password

Something you have: Verification text on a mobile, key fob

Something you are: Biometric authentication, including fingerprint or retina scans

Multi-factor authentication is successfully enabled when at least two of these categories are required to successfully verify someone’s identity before gaining access to a system.

Why is it important?

Multi-Factor Authentication is important as it helps to make sure that a business’s IT systems remain secure, along with their customer and staff data. It effectively makes accessing it more difficult for cybercriminals to target your business. The harder your systems are to access, the less of a target you will be. It also helps to target natural human error – are your employees using the same passwords for everything? The more stringent password policies you set, the more time your IT team will spend resetting them – Multi-Factor Authentication helps to remove this pressure.

What it means for your Cyber Insurance

Multi-Factor Authentication isn’t currently a requirement for all insurers who provide Cyber Insurance policies, but it is heading in that direction. Cyber Insurance claims are being made thick and fast and many of these start with compromised passwords or IDs. It’s your responsibility as a business to ensure that you have sufficient levels of cyber security in place to prevent such an attack from happening and Multi-Factor Authentication is simple and low cost way to improve your cyber security.

If you are interested in a quote for cyber insurance please visit our website or phone 01726 871144 option 3 for the commercial department.