A cybersecurity alert has been issued to charities in the U.K. to warn them of mandate fraud, which recently observed a jump in the number of cases being reported.
What happened?
The Charity Commission for England and Wales admitted to receiving several complaints about fraudsters targeting charities in the country.
A spokesperson for the Charity Commission said, "We have received several reports from charities who have been targeted by fraudsters impersonating members of staff, specifically attempting to change employees bank details."
Modus operandi
The scammers reportedly sent fake emails from spoofed email addresses mimicking closely the real email address of the member of staff being impersonated.
"With a strong social engineering element, the fraudster often states that they have changed their bank details or opened a new bank account," said a Charity Commission spokesperson.
Actions taken by the commission
As per the Charity Commission’s notice, charities were advised to refrain from opening any attachments or clicking on any links contained in unexpected or unusual emails.
"Check email addresses and telephone numbers when changes are requested. If in doubt, request clarification from an alternatively sourced email address or phone number," said the Charity Commission spokesperson. "Sensitive information you post publicly or dispose of incorrectly can be used by fraudsters to perpetrate fraud against you. The more information they have about your charity and employees, the more convincingly they can appear to be one of your legitimate employees."
Cyber Security Breaches Survey 2019 earlier this year had revealed that over two-thirds of high-income charities recorded a cyber breach or attack in 2018. Of those charities affected, the vast majority (over 80 percent) had experienced a phishing attack.
Publisher