The Financial and Cyber Crime Group, Queensland Police Service has observed a trend in invoice scams targeting members of the building industry in Queensland. A number of businesses have already lost income as a consequence.
The scam involves offenders engaging with businesses pretending to be a supplier or creditor and convince businesses operators to change the suppliers banking account details held on record.
The engagement has been very professional including the use of letterheads, telephone calls or emails from ‘suppliers representatives’ to convince business operators the account change of detail is legitimate.
Tips to avoid becoming a victim of invoice scam through change of banking account details:
- Double check all requests to change suppliers or other businesses/persons bank account details.
- Independently verify all notices of changes in bank account details. Ensure telephone verification contact is done with the telephone number obtained from the particular businesses official website or Yellow Pages entry.
- Do not use telephone numbers located within the email to verify the change, always use details you already have or that you have sourced independently
- Use your database contact details to confirm notifications for any changes of banking details via official correspondence with your suppliers (such as a letter), preferably before processing the next payment.
- Always have up-to-date virus protection and remind staff not to open unknown emails or open links within emails they are unfamiliar with.
- Beware of false confirmation e-mails from almost identical e-mail addresses, such as .com instead of co.za, or slight variations from genuine addresses that can be easily missed.
- Consider a multi-person approval process for transactions over a certain dollar threshold.
- Always confirm the identity of the person your business is dealing.
- Ensure you always shred and never throw away your business (and suppliers) invoices or any communication material that contains letterheads.
- Do not publish your bank account details on the internet. This private information can be used fraudulently to trick genuine customers into making payments to alternative accounts.
- Ensure that your company’s private information is not disclosed to third parties who are not entitled to receive it, or third parties whose identities cannot be suitably verified.
If you suspect you have been a victim of an Invoice scam please report on Australian Cyber Online Reporting Network (ACORN).