Skip to content Logo Ifis Finance

Protect your finances. Part 4: from Quishing to Spear Phishing. Protect your finances. Part 5: Social engineering, or how cybercriminals manipulate people to seize corporate capitalHere are twelve common online threats targeting company cybersecurity

Even the most advanced IT security systems are useless if the weakest link turns out to be a human. In the fifth and final part of our cybersecurity series, we look at techniques where hackers do not hack into computers, but into human minds. Social engineering is a cyberattack technique based on studying human behavior, aimed at encouraging the victim to take risky actions. Directed against directors, accountants, or business owners, it can drain hard-earned capital from a business in the blink of an eye. See how to protect your company’s financial security from scammers who are only interested in money extortion.

Kluczowe wnioski:

  • Social engineering relies on human psychology, ruthlessly exploiting the emotions and impulsive actions of victims to intercept confidential financial data, steal identities, and extort money.
  • Scammers build trust for months (e.g., through investment fraud) to persuade the victim to voluntarily authorize a transfer at the decisive moment.
  • Financial security requires continuous verification of the identity of interlocutors and using only verified, licensed business entities.

Wangiri, or the trap for corporate phones

Wangiri is also known as the one-ring phone scam. The attack scheme on a corporate phone fleet is relatively simple: an employee receives a call from an unknown number that drops after just one or two rings. Upon calling back, an answering machine is activated, or there is dead silence on the line. Unfortunately, this call results in an immediate charge to the phone bill because the foreign number turns out to be a premium-rate number, costing up to several dozen euros per minute. Worse, there are advanced wangiri variants that activate hidden subscription services on the account without the scammed person’s knowledge. Such money extortion is often detected by the accounting department only after a few weeks during invoice analysis, and identifying the perpetrator is extremely difficult.

How to protect yourself:

  • Strictly avoid calling back unknown, especially foreign numbers from which you receive unexpected calls.
  • Block the ability to make calls to premium-rate numbers with your telecommunications operator for the entire corporate fleet.
  • Regularly monitor corporate phone bills to instantly catch suspicious, high call costs.

WhatsApp scam targeted at entrepreneurs

Entrepreneurs are also fathers, mothers, and grandparents. The scammer contacts the victim via the WhatsApp messenger, most often posing as a relative who allegedly lost their mobile phone and urgently needs money due to serious trouble. The person receiving the message, acting under stress and thinking they are talking to a loved one, obediently sends the money according to the instructions, which ends in its irretrievable loss. Such money extortion is often financed directly from corporate accounts, which directly hits the financial security of the business.

How to protect yourself:

  • Always verify the sender’s identity by attempting a traditional voice call or contacting them through another secure communication channel.
  • Do not engage in discussion – ignore the message, delete the entire conversation from the messenger, and block the number in your contacts.
  • If you read the message, categorically avoid clicking any links provided in it.

Payment extortion and fake bank employees

APP fraud (Authorized Push Payment) attacks are currently one of the most severe forms of social engineering for companies. The victim voluntarily authorizes a fund transfer or direct debit via internet banking, believing the request comes from a trusted person or institution. In reality, the capital goes directly into the hands of scammers. A classic example in the B2B sector is a call from a fake bank employee or factoring company representative who demands urgent payment or authorization codes, pretending it is absolutely necessary to resolve a technical issue on the corporate account.

How to protect yourself:

  • Always carefully verify received financial operation requests, meticulously record every payment made, and approach unexpected requests from strangers with the utmost caution.
  • Remember that a real bank employee will never ask you for your full system password, PIN code, or to authorize a “test” transfer.
  • Keep antivirus software on workstations in the finance department up to date, as modern and updated computer systems provide an additional layer of protection against data interception.

Romance scam and the threat to the business owner's assets

Although associated with the private sphere, the romance scam poses a real threat to business owners. The criminal pretends to be someone looking for friendship and contacts lonely entrepreneurs, mostly via social media. They initiate a “digital friendship”, gain trust, and over time arouse strong feelings, attaching the victim to themselves. Once the ground is prepared, the scammer asks for significant sums of money, explaining this with sudden, personal, and extremely dramatic circumstances (e.g., an accident, illness, legal problems).

How to protect yourself:

  • Maintain a healthy skepticism towards strangers from the internet – verify such a person in a search engine by checking their first name, last name, profile pictures, and post history to rule out previous scam reports and confirm their identity.
  • Categorically do not trust people who try to isolate you from your surroundings and urge you to cut ties with family or financial advisors.
  • Do not trust people who, despite a short acquaintance, persistently and regularly ask for financial support.
  • Never give money to strangers, and in case of suspected manipulation, immediately report the matter to the appropriate law enforcement agencies.

Investment fraud and fictitious multiplication of financial surpluses

Companies with free capital often look for ways to multiply it. Investment fraud usually begins with an attempt to establish contact via social media (e.g., LinkedIn) by someone claiming to be a financial broker. They offer access, for example, to an exclusive trading platform and promise huge returns on investment with zero risk. The cybercriminal first asks for a small deposit, which very quickly generates an apparent profit in the fabricated client panel. The appetite grows, and requests for subsequent, ever-larger deposits suggest the prospect of easy and fast money. Once the company pays the target amount, the fake advisor vanishes without a trace, and the company loses both the invested capital and the fictitious profits generated on the screen.

How to protect yourself:

  • Be extremely cautious about offers that guarantee “easy money” significantly exceeding standard market rates of return.
  • Categorically avoid cooperating with unverified financial, investment, or lending institutions that do not have an established history in the B2B market – they are most likely “shell companies” whose sole purpose is investment fraud.
  • Always check if a given broker has the appropriate licenses and permits by verifying them on the official website of the Financial Supervision Authority (KNF) or local industry organization websites.
  • Conduct thorough research in an internet search engine, looking for independent opinions and comments regarding the alleged trading platform.
  • Carefully analyze received messages – grammatical, spelling, or stylistic errors, or obvious signs of automatic translation, disqualify the sender’s credibility.

Awareness and factoring as pillars of security

Attacks based on social engineering prove that financial security does not depend solely on algorithms, but on the procedures and caution of employees. Team education is the absolute foundation. It is equally important to use the services of proven, certified institutions. Cooperating with a professional factoring partner allows you to free up cash from frozen invoices in a secure, fully regulated environment. Diversifying funding sources based on reliable entities is the best insurance policy against the risks posed by investment fraud and payment extortion.

Frequently Asked Questions (FAQ) about social engineering attacks

What exactly is social engineering in the context of attacks on companies?

Social engineering is a set of manipulation methods, based on psychology, that induce employees or business owners to take actions contrary to financial security procedures. Scammers rely on fear, haste, or the desire for profit to force the disclosure of passwords or the execution of a transfer without breaking the company’s IT security.

How to distinguish a real offer from a financial institution from investment fraud?

A legal institution always appears in the registers of national supervisors (e.g., KNF in Poland). Furthermore, authentic brokers never guarantee “certain and quick profits” without risk, and their correspondence is conducted through official corporate channels, in impeccable form. Offers flowing through private messengers from unknown “advisors” promising “easy money” are almost certainly a scam.

Why is payment extortion (APP fraud) so difficult to recover by the bank?

Unlike classic theft with an account break-in, in a payment extortion scenario, the victim (e.g., the chief accountant) independently authorizes the transaction using correct, own passwords and tools (tokens). For the bank’s security systems, the operation looks completely legal, which makes the chances of reversing such a transfer after the fact close to zero.

Share