• Skip to primary navigation
  • Skip to main content
Dean Dorton – CPAs and Advisors
  • Services
        • Audit & Assurance
          • Audits, Reviews & Compilations
          • ESG Programs & Reporting
          • Internal Audit
          • International Financial Reporting
          • Lease Accounting Managed Services
          • Peer Review Services
          • SOC Reporting
        • Family Office
        • Consulting & Advisory
          • Business Valuation Services
          • Forensic Accounting
          • Fractional CFO
          • Litigation Support
          • Matrimonial Dissolution
          • Merger & Acquisition
          • SEC Services
          • Succession Planning
          • Transaction Advisory Services
          • Whistleblower Hotline
        • Outsourced Accounting
        • Private Wealth
        • Healthcare Consulting
          • Finance
          • Health Systems Operational Transformation
          • Medical Billing and Credentialing
          • Risk Management & Compliance
          • Strategic Growth for Private Practices
          • Strategy and Strategy Implementation
          • Technology & Data Analytics
        • Tax
          • Business Tax
          • Cost Segregation Studies
          • Credits and Incentives
          • Estates and Trusts
          • Individual Tax
          • International Tax
          • SEC Provision and Compliance
          • State and Local Tax
        • Technology & Cybersecurity
          • Accounting Software
          • Cybersecurity
            • Cybersecurity Assessments
            • Cybersecurity Scorecard Assessment
            • Security Awareness Training
            • Virtual Information Security Office
          • Data Analytics & AI
          • IT Audit & Compliance
            • Cybersecurity Maturity Model Certification (CMMC)
            • Data Privacy Laws
            • SOC Reporting
          • IT Infrastructure & Cloud Solutions
            • Automation
            • Backup and Disaster Recovery
            • Cloud Strategy
            • Data Center
            • Enterprise Network
            • Network Security
            • Phone and Video Conferencing
            • User Identity Management Solutions
            • Webex
          • Managed IT Services
  • Industries
        • Construction
        • Distilleries and Craft Breweries
        • Energy and Natural Resources
        • Equine
        • Financial Institutions
        • Government
        • Healthcare
        • Higher Education
        • Life Sciences
        • Manufacturing and Distribution
        • Nonprofit
        • Real Estate
  • Insights
    • Articles
    • Guides
    • Case Studies
  • Events
  • Company
        • News
        • Our Team
        • Experiences
        • Careers
          • College Students
          • Experienced Professionals
        • Locations
        • Lexington, KY

          250 West Main Street
          Suite 1400
          Lexington, KY 40507
          859-255-2341

        • Louisville, KY

          435 North Whittington Parkway
          Suite 400
          Louisville, KY 40222
          502-589-6050

        • Louisville, KY

          700 North Hurstbourne Parkway
          Suite 115
          Louisville, KY 40222
          502-589-6050

        • Ft. Wright, KY

          810 Wright’s Summit Parkway
          Suite 300
          Fort Wright, KY 41011
          859-331-3300

        • Cincinnati, OH

          312 Walnut Street
          Suite 3330
          Cincinnati, OH 45202
          859-331-3300

        • Blue Ash, OH

          9987 Carver Rd
          Suite 120
          Blue Ash, OH 45242
          513-891-5911

        • West Chester, OH

          9025 Centre Pointe Drive
          Suite 310
          West Chester, OH 45069
          513-985-6240

        • Indianapolis, IN

          5975 Castle Crk Pkwy Dr N
          Suite 400
          Indianapolis, IN 46250
          317-469-0169

        • Raleigh, NC

          4130 Parklake Avenue
          Suite 400
          Raleigh, NC 27612
          919-782-9265

  • Contact Us

Banking fraud

Article 06.24.2020 Dean Dorton

I never cease to be amazed at the creativity and effort of cyber criminals. Any time I think I’ve seen it all, our team runs across a new tactic that has caused significant harm to a business. This week we assisted a client that fell victim to a complex, yet simple cyber-scheme, leading to the compromise of bank accounts and the possible loss of millions of dollars. Please share this article with anyone in your organization who is involved in the banking and finance area. You do not want this happening to your organization.

Just when we get comfortable with the assumption that our controls are protecting us, cyber criminals find a new way to bypass security measures. This industry is ever-changing. We spend a lot of time preaching about multi-factor authentication (MFA) and for years banks have provided customers with comfort in this control. This week we saw that control fail, further enforcing the importance of layered security measures and continual risk assessment and control improvement.

It all started with a user in our client’s accounting department who had elevated administrative access to the corporate online banking platform. This user searched for their banking login page through a normal Google search. She clicked the search result and navigated to the bank login website (or so she thought). She entered her user ID, her password, and her rotating MFA token code to login as normal. Little did she know, the top result was not the site that she expected. The website in which she entered her sensitive information, including MFA token, was a fake site, mocked up to look identical to her real banking login site. The cyber criminals instantaneously initiated a login to the real banking site using her credentials and MFA token to gain access to the bank account. Think about the sophistication here—on average, MFA codes change about every 30 seconds.

Upon gaining access to the real account, the cyber criminals quickly moved to create additional user accounts. These accounts were used to initiate multiple wire requests for hundreds of thousands of dollars each (totaling close to $2 million in total). They then used the compromised account to approve the wires they had initiated with the fake user accounts. During this same time, they initiated attacks on the compromised user’s email to flood the inbox and distract the user from seeing any banking communication. Later they initiated a distributed denial of service (DDoS) on the user’s internal internet connection. This rendered the user’s internet connection basically useless. The cyber criminals attempted to limit the user’s ability to access the real bank account or any other online resources, thus helping to cover their tracks.

At the time of this article, the user is still working with the bank to recover a large portion of the funds that were not stopped before they were fully processed.

What are the critical lessons learned and how do we improve our controls to protect your organization?

  • Be sure you have a robust and continual user awareness training program.
    • Users should be cautious of search results
    • Users should be cautious about clicking links in emails and never click on links regarding banking
  • Review your online banking platform security and controls.
    • Be sure all users’ logins have multi-factor authentication
    • Be sure you are using all of the latest security controls offered by your bank
    • Think through segregation of duties. First, an approver should not be able to create/initiate transactions. Second, a user who can approve/release funds should not have the ability to create users and manage user security.
    • Your bank should provide controls that prevent any one single person from making changes to user security. Any security changes should require secondary approval and the secondary approver should not have any transaction approval authority.
    • Many people ignore segregation of duties in smaller organizations, likely due to physical personnel limitations. This should not be an excuse. Leverage trusted advisors like your CPA or attorney to give you the secondary approval, if needed.
  • Continually evaluate your cyber risks and improve your controls. As we have seen here, very reliable controls like MFA can potentially now have vulnerabilities under certain targeted campaigns. Layer controls whenever possible.

Contact us to evaluate your cyber risks and improve controls before your organization becomes the next victim.

Cybersecurity Assessment Information

Filed Under: Cybersecurity, Services, Technology Tagged With: Banking fraud, case study, Controls, cyber criminals, Cybersecurity, fraud, protections

  • Services
    • Outsourced Accounting
    • Audit & Assurance
    • Tax
    • Consulting & Advisory
    • Technology & Cybersecurity
    • Family Office
    • Wealth Management
  • Industries
  • Company
  • Locations
  • Careers
  • Insights
  • Events
  • Contact Us
facebook Dean Dorton - CPAs And Advisors On Facebook twitter twitter linkedin Dean Dorton - CPAs And Advisors On LinkedIn youtube Dean Dorton - CPAs And Advisors On YouTube

The matters discussed on this website provide general information only. The information is neither tax nor legal advice. You should consult with a qualified professional advisor about your specific situation before undertaking any action.

© 2026 Dean Dorton Allen Ford, PLLC. All Rights Reserved