Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Employment Scam Victims Triple at Financial Institutions in 21 Countries

A BioCatch study of 370 banks across 21 countries found a 258% increase in employment‑scam victims over the past year, outpacing all other fraud types. The surge highlights gaps in security awareness and real‑time fraud controls that auditors and regulators scrutinize.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
helpnetsecurity.com

Employment Scam Victims Triple at Financial Institutions in 21 Countries

What Happened — BioCatch’s fraud‑detection platform aggregated reports from more than 370 banks and other financial firms in 21 countries and found that employment‑scam victims rose 258% over the past 12 months, outpacing every other scam type. Nine‑in‑ten of the fraudulent sessions began on a mobile device, and the average loss per investment‑scam case was $6,600.

Why It Matters for Trust & Control Assurance

  • The spike reveals a gap in continuous fraud‑control monitoring: real‑time behavioral analytics must flag suspicious voice‑call patterns before a transfer is authorized.
  • It underscores the need for documented security‑awareness training that can be audited as evidence of due diligence against social‑engineering risk.
  • Regulators increasingly expect proof that organizations can detect and intervene in high‑risk transactions, a core control‑objective across NIST CSF 2.0 and related frameworks.

Who Is Affected — Banks, credit unions, fintech platforms, and other financial‑service providers that process consumer payments.

Recommended Actions

  • Deploy or tune behavioral analytics that surface anomalous mobile sessions (e.g., rapid payee entry, concurrent voice calls).
  • Strengthen security‑awareness programs with specific modules on employment and voice‑phishing scams; track completion as audit evidence.
  • Capture and retain session logs, risk‑score calculations, and warning‑message timestamps to build a defensible incident‑response trail.

Source: Help Net Security

Technical Notes — The attacks rely on social‑engineering voice calls (vishing) initiated on mobile devices, leveraging real‑time remote‑access tools and rapid payee‑addition flows. No software vulnerability was disclosed. Source: same as above

📰 Original Source
https://www.helpnetsecurity.com/2026/10/01/employment-scam-victims-research/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →