BEC Attacks: Who is legally responsible?

Posted On Monday, 28 June 2021 13:32 Published by
Rate this item
(0 votes)

Business Email Compromise (BEC) and cyber attacks are on the increase worldwide. Conveyancing firms, their clients, and other organisations effecting many large non-recurring type transactions are particularly vulnerable to BEC fraud.

Ryan_Mer_eftsure

Ryan Mer, Managing Director, eftsure Africa, a Know Your Payee™ (KYP) platform provider says gaps in organisations’ payment systems not only pose massive financial and reputational risks, but can have serious legal implications as well.

According to a global survey conducted by Mimecast Cyber Security Services in 2020, six out of ten companies globally were infected with ransomware and there was a 64% increase in email threats. An Accenture report from May 2020 confirms South Africa had the third most cybercrime victims globally, resulting in losses topping R2.2 billion.

All too aware of large deposits made to and from conveyancing firms, criminals target and intercept email accounts and scam victims into making payments into the incorrect account. While legislation like the Financial Intelligence Centre Act (FICA) and Protection of Personal Information Act legally requires attorneys and estate agents to responsibly gather and scrutinise an individual’s information, Business Email Compromise remains a threat to any organisation and its clients. In South Africa there is case precedence for firms being held liable for payments that did not reach the intended recipient; a situation that demands email correspondence containing bank details and personal information be handled with caution.

In circumstances where organisations are unable to meet their financial obligations as a result of a BEC attack, third parties may seek compensation for disrupted business operations and other losses, particularly where a firm is found to be in breach of its duty to take adequate measures to mitigate the risks of BEC attacks. It’s critical that attorneys and clients should take additional care in verifying account details before making payments and should be made immediately aware of sudden changes in email addresses and bank details. 

Most threats can be avoided with the correct financial controls as well as server, IT and email monitoring processes together with the following measures:

  • Be Informed, keep up to date with the latest scams and ensure your employees, colleagues and trading partners are aware of how they work in practice.
  • Review your company practices in relation to password and security controls.  Never share passwords across multiple sites or permit weak password. 
  • Acknowledge the fact that employee email accounts are gateways to sensitive information and attacks and enforce policies restricting what information can be kept in email inboxes prior to secure archiving. eftsure’s secure, digitised payee onboarding platform can assist with the collection and management of payee information.
  • Re-evaluate your financial procedures for approving payment release. A platform like eftsure can help limit the risks of BEC attacks by cross-referencing the payments an organisation is about to release with a database of verified bank account details. eftsure’s fully integrated platform will clearly alert to any suspect payments, at point of payment, allowing an organisation to deal with it before making payment i.e.: before the flow of funds have occurred.
Last modified on Friday, 06 August 2021 13:38

Most Popular

Accelerate Property Fund sells Cherry Lane Shopping Centre for R60m

Mar 30, 2024
Cherry Lane Shopping Centre
Accelerate Property Fund sells Cherry Lane Shopping Centre for R60 million with Cadastral…

FNB Broker Business Confidence declines in 1st quarter of 2024

Mar 31, 2024
John Loos FNB Property Strategist
1st Quarter 2024 Property Sales Activity Survey –Brokers point to the commercial property…

Repo rate holds steady for 5th consecutive MPC meeting

Mar 27, 2024
FNB Estate Agent Survey Q1 2024
Today’s announcement by the Monetary Policy Committee (MPC) that the repo rate would…

Urbanisation drives demand for affordable housing in the Eastern Cape, TUHF

Mar 31, 2024
Letlatsa Lekhelebana_TUHF
Eastern Cape’s major metros are seeing an influx of people from surrounding rural areas,…

Please publish modules in offcanvas position.