Fraudulent funds transfer quietly becoming leading driver of cyber loss

By Anita Byer, Setnor Byer Insurance & Risk

Did you know that fraudulent funds transfer (FFTs) is quietly becoming a leading driver of cyber loss? A recent survey of cyber insurance claims by Corvus Insurance revealed that the frequency of FFT claims has surpassed all others, making it the largest category of cyber incident. According to Corvus’ Risk Insights Index (Q4 2022), FFT claims represent 28 percent of all Corvus cyber claims and have become a leading driver of cyber loss. This is incredibly valuable information for businesses trying to keep cyber criminals at bay, particularly small- and medium-sized enterprises with limited resources because it’s usually easier (and cheaper) to defend against a known threat.

So, how does the FFT scam work? Though methods are constantly evolving, cybercriminals typically use business email compromise (BEC) attacks to initiate FFTs. BEC attacks are sophisticated scams that rely on deception and social engineering to convince victims to transfer money to an account controlled by criminal actors. Schemes often involve the spoofing of legitimate, known email addresses or the use of a nearly identical address to appear as someone known to or trusted by the victim. The FBI describes BEC attacks as one of the fastest growing, most financially damaging internet-enabled crimes.

This means that criminals are constantly refining their tactics to maximize their FFT payout. Over the last few years, scams have progressed from spoofed emails purportedly from chief executive officers to criminals impersonating legitimate vendors to redirect invoice payments to the criminal’s account. These scams can be very sophisticated and difficult to spot, so the FBI offers the following suggestions to help protect against FFTs.

  • Use secondary channels or multi-factor authentication (MFA) to verify requests for changes in account information.
  • Ensure the URL in emails is actually associated with the business, department or individual it claims to be from.
  • Be alert to hyperlinks that may contain misspellings of the actual domain name.
  • Refrain from supplying login credentials or PII of any sort via email. Be aware that many emails requesting your personal information may appear to be legitimate.
  • Verify the email address used to send emails, especially when using a mobile or handheld device, by ensuring the sender’s address appears to match who it is coming from.
  • Ensure the settings in employees’ computers are enabled to allow full email extensions to be viewed.
  • Monitor financial accounts on a regular basis for irregularities, such as missing deposits.

Businesses must implement and maintain appropriate security protocols to avoid not just FFT scams, but other forms of cybercrime as well. Ransomware, for example, did not go away. Despite declining frequency, ransomware remains a top driver of cyber loss.

While preventative measures can effectively reduce the risk of FFTs and other cyber threats, they are not foolproof. Every business should have Cyber Perils Insurance Coverage to protect against various cyber threats and liability exposures, including coverage for losses caused by FFT and other BEC attacks. Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches.

How do you know if your identity has been stolen?

By Anita Byer, Setnor Byer Insurance & Risk

The likelihood of identity theft seems to increase daily. With so many identities being stolen, many believe it’s a matter of when, not if. Taking preventative measures is crucial to reducing the likelihood of being a victim, but nothing is foolproof. When identity theft does happen, early detection is the key to limiting the damage. The sooner you know, the better. But, how do you know when your identity has been stolen? It can be harder than you think.

Fortunately, the Federal Trade Commission offered some helpful advice during this year’s Identity Theft Awareness Week. According to the FTC, you need to understand how thieves might use your stolen identity and be on the lookout for signs.  

An identity thief could use your information to get credit or service in your name.

How to spot it: Get your free credit report at AnnualCreditReport.com. Review it for accounts you didn’t open or inquiries you don’t recognize. A new credit card, a personal loan or a car loan will appear as a new account. A new cell phone plan or utility service (water, gas, electric) will show up as an inquiry.

An identity thief could use your credit card or take money out of your bank account.

How to spot it: Check your credit card or bank statement when you get it. Look for purchases or withdrawals you didn’t make. Sign up to get text or email alerts from your credit card or bank whenever there’s a new transaction. This could help you spot unauthorized or fraudulent activity on your account.

An identity thief could steal your tax refund or use your Social Security number to work.

How to spot it: A notice from the IRS that there’s more than one tax return filed in your name could be a sign of tax identity theft. So could a notice that you have income from an employer you don’t work for.

An identity thief could use your health insurance to get medical care.

How to spot it: Review your medical bills and Explanation of Benefits statements for services you didn’t get. They could be a sign of medical identity theft.

An identity thief could use your information to file a claim for unemployment benefits.

How to spot it: A notice from your state unemployment office or employer about unemployment benefits that you didn’t apply for could be a sign of fraud.

When preventative measures fail, insurance is available to help victims through the expensive and time-consuming process of recovery. Please contact us if you would like more information about insurance specifically designed to protect against identity theft.

How Can You Limit the Damage Caused by Identity Theft?

What’s worse than filing your taxes? Finding out that your return was already filed and your refund check was already cashed. Yep, that’s definitely worse. Unfortunately, tax season has become the time of year when many first discover that their identities have been stolen.

According to Javelin Strategy & Research’s 2017 Identity Fraud Study, there were 15.4 million U.S. victims of identity theft in 2016, which is 16 percent higher than 2015. It was the highest rate since Javelin began tracking identity fraud in 2003.

So, what should you do if your identity has been stolen? According to the Federal Trade Commission (FTC), you must take immediate action to limit the damage.

What to do right away.

Contact the fraud department of each company (retailer, bank, etc.) where you know fraud occurred. Explain that someone stole your identity and ask them to close or freeze the accounts so no one can add new charges unless you agree. Change logins, passwords and PINS for your accounts.

Contact one of the three credit bureaus to place a free 90-day fraud alert. That company must tell the other two. A fraud alert makes it harder for someone to open new accounts in your name. When you have an alert on your report, a business must verify your identity before it issues new credit in your name.

Get your credit reports from Equifax, Experian and TransUnion. Review your reports and note any accounts or transactions you don’t recognize.

Report identity theft to the FTC. The FTC will create an Identity Theft Report and recovery plan. An identity theft report proves to businesses that someone stole your identity. It also guarantees you certain rights.

File a report with your local police department. Tell the police someone stole your identity and that you need to file a report. Ask for a copy of the police report.

What to do next.

Close new accounts. Ask the fraud department of each business where an account was opened to close the account. Request a confirmation letter and keep a record of who you contacted and when.

Remove fraudulent charges from your accounts. Let the fraud department know which charges are fraudulent and ask that they be removed from your account. Request a confirmation letter and keep a record of who you contacted and when.

Correct your credit report. Write each of the three credit bureaus. Identify what information on your report came from identity theft and ask them to block that information. You have the right to block fraudulent information so that it won’t show up on your credit report and companies can’t try to collect the debt from you. If you have an Identity Theft Report, credit bureaus must honor your request to block this information.

Consider an extended fraud alert or credit freeze. Both can help prevent further misuse of your personal information, but there are important differences between the two. For example, an extended fraud alert allows access to your credit reports as long as steps are taken to verify your identity. A credit freeze stops all access until it’s removed. Though fraud alerts are free to place and remove, there may be small fees associated with credit freezes.

Protective measures to protect against identity theft are important, but they’re not always enough. However, there is insurance that is specifically designed to protect both individuals and businesses against identity thieves and hackers. For example, identity theft coverage can help individuals cover the cost of clearing their name. Cyber Liability and Security Breach (Cyber Perils) coverage can protect businesses against various cyber threats, including the cost of complying with data breach notice laws.

Please contact us if you would like more information about insurance specifically designed to protect against identity theft.

Additional information is also available in our weekly Risk Management Newsletters.

Can Your Car Be Hacked?

Cyber threats and data security remain a big concern for individuals and businesses alike. But sometimes, the most effective cybersecurity comes down to the little things, like using strong passwords, installing security updates and keeping your car’s key fob in the freezer. Wait, what?

It’s true. Storing key fobs in a refrigerator or freezer can prevent someone from hacking into your car.

There is a developing concern that increasingly connected motor vehicles are vulnerable to cyber attacks. This concern prompted the Federal Bureau of Investigation to release a public service announcement to alert consumers about the potential cyber threats that come with increased vehicle connectivity.

Vehicle hacking occurs when someone uses a computer to gain unauthorized access to vehicle systems to retrieve driver data or manipulate vehicle functionality. Though not all hacking incidents jeopardize safety, like a hacker taking control of a vehicle, the FBI stresses the importance of taking appropriate steps to minimize risk. This means consumers must understand the ways in which their vehicles may be hacked.

Here are some vulnerabilities that can be exploited to hack a vehicle.

  • Wireless Tire Pressure Monitors. These systems are directly connected to the vehicle’s main computer and transmit wireless signals that can be intercepted by hackers.
  • Multi-Media Systems. Files downloaded and used in vehicles (music, movies, etc.) may contain viruses or malicious software (malware) that can be used by hackers to gain access.
  • In-Car Wi-Fi. Vehicles that are directly connected to the Internet can be hacked like any other device that is connected to the Internet.
  • Bluetooth. Viruses and malware can be introduced when smartphones are synced to Bluetooth capable vehicles. In addition to vehicle-specific hacks, like remotely unlocking or starting a vehicle, a hacked Bluetooth system could jeopardize the security of sensitive data stored on synced smartphones.
  • Navigation Systems. Internet connections and outside networks used by in-car navigation systems can give hackers access to a vehicle’s controller network or stored data.
  • Key Fobs. Keyless entry and start systems continuously transmit random codes between a fob and the vehicle. These transmissions can be intercepted and hacked. The random codes that are constantly being transmitted by fobs can be blocked by storing the fob in a metal drawer, refrigerator or freezer.

Here are some tips that can help minimize the risk of vehicle hacking.

  • Keep the vehicle’s software current. Routinely check for (and install) new security updates. The FBI cautions that hackers may send socially engineered e-mail messages to vehicle owners who are looking for legitimate software updates. These messages may include links to malicious web sites or attachments containing malware.
  • Be careful when modifying a vehicle’s software. According to the FBI, improper software modifications or adjustments can introduce new vulnerabilities that may be exploited by hackers. They can also affect the installation of authorized software updates.
  • Exercise discretion when connecting third-party devices to a vehicle. Modern vehicles have standardized diagnostics ports (OBD-II) that directly connect to a vehicle’s computer systems. These ports have traditionally been used by maintenance and service technicians. However, third-party devices, such as insurance dongles and telematic monitoring tools, are increasingly being connected to these ports. The FBI cautions that the security of these devices is important because they can provide a new means of access for hackers.
  • Exercise discretion when giving others physical access to a vehicle. The FBI advises that vehicles, like personal computers or smartphones, should not be left in unsecure locations or with people who are not trusted.

When protective measures are not enough, it helps to have insurance coverage that is specifically designed to protect both individuals and businesses that have been victimized by hackers. For example, identity theft coverage can help individuals cover the cost of clearing their name. Businesses can rely on Cyber Liability and Security Breach (Cyber Perils) coverage to protect against various cyber threats, including the cost of complying with data breach notice laws.

Please contact us if you would like more information about insurance specifically designed to protect against cyber threats.

Additional information is also available in our weekly Risk Management Newsletters.