Tom Muleya-Fraud Insight
Every business is vulnerable to cyber threats and cyber attacks. In the same way as businesses faced challenges of traditional frauds and thefts in the past, businesses are now faced with cyber crime threats.
As we come to the final week of the Cyber Security Awareness Month, let us take a look at cybercrime in the workplace, particularly Business Email Compromise (BEC).
Some common workplace cybercrimes are; Hacking, Identity Theft and fraud, Phishing, Online fraud, Credit card fraud (Card Cloning), Intellectual Property Theft, Impersonation, amongst others.
Cybercrimes are taking businesses, particularly in Zimbabwe by surprise as business entities are being subjected to manipulation in several ways.
Cybercrimes in workplaces impacts negatively on businesses as the cost of cyber fraud and attacks is currently one of the world’s biggest challenges.
Where huge losses are experienced, business may close down or be forced to cut down on the workforce. Also cyber crimes at workplaces undermine business integrity and scares-off potential foreign investors.
It is therefore apparent that businesses invest heavily on cyber security to safeguard businesses and minimize cyber risks.
Now let us take a look at ‘Business Email Compromise’. This is one crime with many names such as Employee Account Compromise, CEO Fraud/CEO Impersonation, and or Bogus Invoice Scheme.
Criminals normally gain entry to victim’s devices or systems through hacking, phishing websites, and malware.
Once criminals are in possession of victim’s information or details, they deceive the victim into transferring the money into their bank account.
Criminals at times commit Business Email Compromise through ‘Social Engineering’. This is whereby criminals target their victim based on information they share on social media platforms.
The other way is through Urgent Request. In this attack, the criminal impersonates a Superior (CEO), by requesting an urgent payment or change of bank details, or through a senior employee in the company with the authority to authorise payments.
In order to prevent or minimize incidences of Business Email Compromise at a workplace, business management may consider some of the following measures;
Regularly conduct risk assessment on key corporate areas, devices and software to identify vulnerabilities or weaknesses within the ICT security System.
Invest heavily on corporate security system by putting in place latest technologies and software to keep pace with advancing technology.
Avoid giving any single person within the business power to authorise payment or payment transactions.
Regularly change or rotate employees on key areas so that they do not overstay in the same position. Many cases are unearthed or detected soon after someone is suddenly changed from office.
Corporate emails should be careful checked to identify fraudulent emails that almost look like genuine Company Emails.
Urgent Email Requests for money and or change of account details by CEOs and senior employees with power to authorise payments must be treated with caution since they might have been impersonated. Voice calls may be made to verify the authenticity of the request. Where verification fails, withholding the payment may be the best weapon to silence the criminal.
Make use of strong passwords, and latest Antivirus is good defence against Business Email Compromise.
Proper selection of employees to handle corporate emails and communication.
Immediately report to the Police and Bank any suspicious transactions.
Participate in the fight against cybercrimes involving Business Email Compromise. Think Cyber Security. Watch out for the next issue.
For your feedback, WhatsApp line: 0772 764 043, or e-mail:[email protected]. Tom Muleya is a Detective Assistant Inspector working under the Criminal Investigations Department. Harare. He is also a member of the National Cyber Security Taskforce, Zimbabwe.



