Stop the same trick from working again on you or your team.
What to do
- Adopt a written 'verify any change of bank details by phone' rule using a number from prior records, never the email
- Enable authenticator-app 2FA and disable legacy auth / app passwords on the mailbox
- Turn on DMARC / SPF / DKIM enforcement on your domain and ask suppliers to do the same
- Use accounts-payable approval workflows that flag any change of supplier bank details
- Run a phishing-awareness refresher with anyone who can authorise payments
Was this guide helpful?
Know someone who needs this? Send them the guide.
JD
Written by
Jordan DicksonFounder, CyberSecurityGuides
Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.
Reviewed by CSG Security Engineers