Employment Scam Victims Triple at Financial Institutions in 21 Countries
What Happened — BioCatch’s fraud‑detection platform aggregated reports from more than 370 banks and other financial firms in 21 countries and found that employment‑scam victims rose 258% over the past 12 months, outpacing every other scam type. Nine‑in‑ten of the fraudulent sessions began on a mobile device, and the average loss per investment‑scam case was $6,600.
Why It Matters for Trust & Control Assurance
- The spike reveals a gap in continuous fraud‑control monitoring: real‑time behavioral analytics must flag suspicious voice‑call patterns before a transfer is authorized.
- It underscores the need for documented security‑awareness training that can be audited as evidence of due diligence against social‑engineering risk.
- Regulators increasingly expect proof that organizations can detect and intervene in high‑risk transactions, a core control‑objective across NIST CSF 2.0 and related frameworks.
Who Is Affected — Banks, credit unions, fintech platforms, and other financial‑service providers that process consumer payments.
Recommended Actions
- Deploy or tune behavioral analytics that surface anomalous mobile sessions (e.g., rapid payee entry, concurrent voice calls).
- Strengthen security‑awareness programs with specific modules on employment and voice‑phishing scams; track completion as audit evidence.
- Capture and retain session logs, risk‑score calculations, and warning‑message timestamps to build a defensible incident‑response trail.
Source: Help Net Security
Technical Notes — The attacks rely on social‑engineering voice calls (vishing) initiated on mobile devices, leveraging real‑time remote‑access tools and rapid payee‑addition flows. No software vulnerability was disclosed. Source: same as above