Sadly, online fraud and cyber crime are becoming ever-more prevalent around the world, helped in large part by the ease that the Internet brings to those attempting to access funds from other people’s bank accounts.
The typical recruitment agency is regularly engaged in online banking transactions, especially if it has active contractors. That’s why your own firm needs to be aware of common frauds like the below.
- Bogus boss fraud, which involves a fraudster sending an email to a member of the accounts team asking for an urgent payment, while acting as if they were the company director.
- Telephone fraud or vishing, whereby the fraudster impersonates the bank over the telephone to try to get a payment made or obtain username, password and PIN information
- Invoice redirection, which is the phenomenon of an emailed invoice being intercepted during transmission and the bank details altered on the invoice, before the email is routed Alternatively, the client may receive a request to change the company bank details, which may lead to the client paying into the fraudster’s bank account, leaving the victim’s invoice unpaid
- Financial malware is a form of software downloaded from an attachment or link in a phishing Such phishing emails are frequently designed to resemble genuine emails from reputable organisations like HMRC, Companies House and even the bank itself. The malware is then installed on the victim’s computer when they click on the link or attachment, and will often remain undetected until the victim goes into their banking system. At this point, the software will obtain the victim’s login details by recording their keystrokes, or show a different screen to what the victim is seeing, entering payments in the background that the victim authorises without their knowledge – until it is too late.
What measures can be taken to guard against such frauds?
There are various steps that you can take to lessen the chances of your recruitment agency becoming a victim. These include alerting all of your employees to the various types of fraud that can occur, in addition to ensuring they are aware the bank will never request PINs, passwords or authorisation codes over the phone.
Your staff should also know that the bank or the police will never ask them to make a payment to a ‘test’ or ‘safe’ accountant. Furthermore, if they have any doubt about who they are speaking to on the phone, they should hang up the phone and get in touch with the bank directly from an independently found number, as well as – ideally – from a different phone line.
The employees of your agency can also reduce the likelihood of fraud by never opening any email attachments or links from unknown sources or email addresses. Any unusual requests or change of bank details should also be verified with the person making the request.
How TBOS can help in the fight against fraud
We manage online banking for clients on a daily basis as part of our broader recruitment back office services. One of the security measures that we implement to protect is agencies is dual authorisation, whereby one person enters payments, but another person authorises them.
Our internal quarterly security audits are also instrumental in reviewing current processes, pinpointing potential risks to the system and devising methods to reduce fraud within TBOS and the agencies that we serve. Regular fraud awareness training seminars are also provided to all of our employees, working alongside our banking partners.
All online fraud victims are urged to speak to their bank and get in touch with ActionFraud on 0300 123 2040, or by visiting www.actionfraud.police.uk.
Meanwhile, by contacting our office, you can learn more about what other recruitment back office services we are proud to provide.




