Small business beware: Emerging types of scams and how to avoid being stung
Tuesday, September 17, 2013/
It could come in the form of a random email, a suspicious text or even a dated fax, but one thing’s for sure, scammers are on the hunt and they’re looking for small businesses.
In 2012, more than 84,000 scams were reported to the Australian Competition and Consumer Commission and, according to ACCC figures, Australians lost $93 million as a result.
Research from the Australian Institute of Criminology suggests less than 10% of scams are reported, making it potentially a $1 billion problem.
Scams have been presented in a variety of forms. It could be an email message from a ‘friend’ saying they have been kidnapped in a foreign country, or your phone number might have been the ‘lucky winner’ of a lottery. These scams are easy to identify, but as technology develops, so do the scams.
A number of more sophisticated scams are emerging, including social media scams, business identity theft and SEO scams, which have the potential to cost businesses a lot more money.
Dr Paul Weber from Curtin University’s Business School and ACCC deputy chair Michael Schaper spoke to SmartCompany about these new types of scams, with tips for how businesses can protect themselves.
Business identity theft
Weber and colleagues from Curtin University are conducting ongoing research into small business scams and he says small businesses are seen as an easy target.
“These victims do seem more attractive to the scammer since they provide access to larger account balances than a normal consumer, effectively without any greater level of security or procedures to foil the scam attempt,” he says.
“Small businesspeople see opportunities and go for it. They’ve learnt that’s how you get on in business, but it can make you gullible and more open to scams.”
As technology has developed, Weber says more and more small businesses are becoming the victims of identity theft.
“In a similar vein to personal identity theft, business identity theft is becoming more commonplace. There are many forms that such an impersonation of another organisation can take, but all have the potential for relatively large losses by the very nature of the business-to-business environment in which they occur,” he says.
The scam occurs by the attacker gaining access to the business, or its supplier’s email account, and then proceeding to skim the emails between the businesses until a large transaction occurs. When the supplier asks the business to transfer a large sum to a specified account number, the business alters the account details on the email before it reaches the business’s inbox.
The business then transfers the money into the scammer’s account, thinking it’s paying the supplier. By the time both parties discover the money went to the wrong account, it’s too late and the money can’t be retrieved.
Weber says these types of scams are practically impossible to detect as for all intents and purposes the scammer is the other business. It has the same email address, the same email signatures, the same business information, the only thing different is the account number.
At a recent event in Perth to launch a national prevalence study into small business scams, Weber says out of a group of five business owners, three of them had experienced this type of scam.
When conducting his research, Weber received a personal account from an Australian business owner:
“Using this technique, the attacker was able to intercept an email from my supplier sending me a deposit invoice, change the bank account details and forward it onto me; I then made the money transfer to this incorrect account… We suspected no problem until it was too late when the money did not come through. The invoice amount was for over $4500, which was a huge loss to my brand-new business,” the owner said.
Weber says this type of scam is changing the way people think about this type of illegal activity.
“While it is all well and good to encourage people to maintain the mantra, ‘if it is too good to be true…’, this was a totally normal business transaction between two reputable businesses, nothing looked out of place,” he says.
“The scammers are watching and learning how to mimic the businesses’ behaviours before they strike. They are not easy to pick as bogus organisations.”
Weber says businesses generally aren’t protected from these types of scams by the banks, which are “too busy” trying to thwart similar attacks on consumers, so it’s left up to the business owner to change their procedures.
“The only effective way to foil such a sophisticated scam is to make separate independent contact with all electronic transaction requests and any other important business instruction,” he says.
“The language is very clearly about thinking about different processes so you won’t have to figure out if it’s a scam. I’m reasonably savvy and I can’t even figure these out because there are just no clues.”
Unfortunately for consumers, it seems scammers like online shopping too – for victims.
In 2012 the number of online shopping scams increased by 65% to over 8000 and cost businesses and consumers upwards of $4 million.
The ACCC says this is likely to continue to increase as more and more people shop online.
Online shopping scams generally come in two forms, classified ad scams and overpayment scams.
In classified ad scams a scammer posts a fake ad on a legitimate classifieds website for cheaply priced popular items. When a consumer expresses interest in an item, the scammer will claim that the goods will be delivered following payment. Once the consumer pays, the goods never arrive.
Schaper says overpayment scams are becoming common, too.
“Basically what happens is someone comes in, buys your product off you and then when they transfer you the money, shortly afterwards they say they’ve ‘accidentally’ paid you too much,” he says.
“The scammer then asks you to refund the money. The original payment was usually made on a stolen credit card and that’s how they’re scamming the repayment off you. They will ask you to transfer the refund and hope you do so before realising the scammer’s cheque has bounced or the money was phony.”
Effectively, this results in the consumer losing the transferred money, as well as the money they ‘refunded’.
But there is some good news, people and businesses are becoming savvier to these types of scams.
The conversion rate between a person coming into contact with an online scam and money being lost fell in 2012 to almost 37%, a decrease of 43% from 2011 levels, according to the ACCC.
Story continues on page 2. Please click below.