Invoice fraud and the callback rule
The cheapest control in the building: call the number you already have, not the one on the invoice.
ITSIGN Administrator · May 7, 2025 · 2 min read
Write it down. Train AP. Put the threshold in the ERP if you can. The email is not the verification.
Attackers know Canadian firms pay on Net 30 and that December is noisy. They use both.
We include this scenario in security awareness for finance, not a generic module.
Related reading
Email retention, PIPEDA, and the mailbox you never deleted
Keeping everything forever is not a strategy. It is a larger breach waiting for a number.
2 min read
When the phish comes from a vendor you trust
Their tenant, your payment. Callback still wins. So does knowing who is allowed to change details.
2 min read
Turn off IMAP and POP before someone else uses them
Legacy protocols skip modern MFA. They are still on in tenants that were migrated in a hurry.
2 min read
Want this applied to your environment?
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
