Fraud Glossary
Every term a finance team needs to talk about voice and payment fraud — defined in plain English, with the attack pattern and the fix.
Vishing & Voice Fraud
CEO Fraud
CEO fraud is a targeted attack in which criminals impersonate a senior executive — by email, phone, or increasingly by AI-cloned v…
Wire & Payment Fraud
Wire Transfer Fraud
Wire transfer fraud is any scheme that causes funds to be sent by bank wire to an account controlled by a criminal — usually by de…
Wire & Payment Fraud
Invoice Fraud
Invoice fraud is any scheme that uses a false, inflated, or manipulated invoice — or a fraudulent change to a real supplier's paym…
Compliance & Controls
Dual Authorization
Dual authorization (also called the four-eyes principle) is a payment control requiring two independent people to approve a transa…
Vishing & Voice Fraud
What Is a Spoofed Number?
A spoofed number is a falsified caller ID: the caller deliberately transmits someone else's number — a bank, a government agency,…
Vishing & Voice Fraud
Smishing vs Vishing
Smishing is phishing conducted over SMS/text messages; vishing is phishing conducted over voice calls. Both move the classic email…
Compliance & Controls
Positive Pay
A fraud-prevention service in which the bank pays only the items that match the issued-payment list a company sends it.
Compliance & Controls
ACH Positive Pay
A bank service that defines which originators may debit an account — by originator ID, amount limit, and frequency — and blocks the rest.
Compliance & Controls
Reverse Positive Pay
The bank sends each day's presented checks to the company, which does the matching and decides what to pay.
Compliance & Controls
Positive Pay File
The structured list of issued payments a company transmits to its bank so presented items can be matched.
Vishing & Voice Fraud
Vishing Examples
Nine recurring shapes of vishing attacks, and the red flags that identify each one.
Wire & Payment Fraud
Wire Transfer Fraud Recovery
Attempting to freeze or claw back funds after a fraudulent wire — a process measured in hours, not weeks.
Compliance & Controls
Account Takeover (ATO)
Account takeover (ATO) is a form of fraud in which an attacker gains control of a legitimate user's account — email, banking, corporate identity — and operates it as that user.
Compliance & Controls
Corporate Account Takeover
Corporate account takeover (CATO) is account takeover aimed at a business — most damagingly its online banking, treasury, or identity-provider accounts.
Identity Verification
Candidate Fraud
Candidate fraud is any hiring scheme in which the person a company assesses is not the person it ends up employing.