What is Payment Diversion?

A completely normal process: your accounting department receives a notification from a supplier that their bank details have changed. What happens next? The new bank details are entered and all future payments are made to the new bank account.

Caution is advised here, because the alleged notification from the supplier could be a forgery by an attacker. This person is trying to redirect payments to their own account. Letters, faxes and also email senders can be easily forged technically, as can phone numbers.

In recent years, companies have suffered high losses through payment diversion – the redirection of payment flows. A Lithuanian fraudster was able to redirect over 100 million dollars of Facebook and Google payments to his accounts over a period of two years. Small and medium-sized enterprises are just as vulnerable to this scenario as large ones.

The procedure is similar in spectacular and less spectacular cases: the fraudsters prepare thoroughly and inform themselves about the internal circumstances of the company and the supplier. The attackers use all available technical possibilities for this. Social engineering is also used, in which attackers exploit human characteristics such as helpfulness or trust. In this way, they eventually gain information or can induce people to take certain actions. la

  • The attackers collect and analyze information from freely accessible sources:
    the company homepage, from the social media profiles of employees, etc.
  • Through calls and questions about trivialities, the attackers obtain seemingly unimportant information that they can later use to appear as insiders.
  • With trivial email requests, working hours, absences and substitution arrangements can be checked.
  • Security vulnerabilities in the IT are exploited, for example, email traffic is read or emails are sent with a forged email sender.

The fraudsters are well-equipped for their actual attack. The forged email, fax or letter is sent at the right time (for example, during the holiday season) to the right person. If the forgery is not recognized, the damage is sometimes only noticed when payment reminders for invoices already paid arrive.

Payment Diversion – what can be done against it?

If you are informed by a business partner about a change in their bank details, it is best to proceed as follows:

  • If you receive the notification by email, check the sender address. Sometimes only a dot or a letter is changed. Depending on the email program, hover the mouse over the email sender so that the actual sender is displayed.
  • Verify the account change by calling the business partner or sending them a confirmation letter. If you want to reply by email, do not use the reply button, but the address from your address book.
  • If necessary, ask the management.

The following measures also serve as prevention:

  • Be mindful of which details about the company are publicly visible – also on private social media accounts. The publication of information via such channels is possible; however, it must be noted that this information is publicly accessible from that point on and can be misused.
  • Be sparing with information in out-of-office notes.
  • Introduce clear absence regulations.
  • Define clear processes for master data management and payment instructions.
  • Sensitize your employees regarding social engineering methods.

Arm yourself against payment diversion and make it particularly difficult for attackers to manipulate payment flows in your company.