Hidden malware in fake invoices prompts warning

Friday 17th April, 2015

Anti fraud group, Financial Fraud Action UK, has warned that computer malware, hidden within fake invoices is being used to steal business' banking details.

 

According to a report on the BBC, faudsters email the invoices on text or spreadsheet documents to firms, claiming to be from a regular supplier or a trusted organisation.

Opening them triggers instructions which log the firm's financial data.

Anti-fraud group Financial Fraud Action UK said there had been a surge in this type of trick in recent weeks.

The fraud operates because victims unwittingly enable a macro - a big block of code - on their computer system when they think they are opening the invoice.

It contains malicious software which logs online banking details and other financial information and sends them back to the fraudster.

This information is then used to raid the firm's bank account.

Experts have warned that con-artists are increasingly targeting businesses, rather than individuals. This is because they generally have larger amounts in their bank accounts and because individuals are becoming wiser to scams and phishing emails.

Firms are being urged to keep an eye out for unexpected invoices and not to open macros on documents that staff do not trust. Accounts departments might also consider keeping a separate computer specifically for making online payments.

Fraud prevention service Cifas recently reported that fraud hotspots were found in London, Leicester, Birmingham, Manchester, Leeds and Glasgow.