A new breed of cyber criminal stole £7m from an IFA’s client by gaining access to the adviser’s email account using subtle phishing techniques.
According to EJ Hilbert, managing director of investigations agency Kroll, the new scam involves tricking advisers into giving up their private email addresses and passwords, then discreetly setting up a filter so client correspondence skips the adviser’s inbox.
The scam artist then corresponds with the client and/or a clearing bank and tricks them into transferring their money away.
Evidence gathered by Kroll, first revealed in FTAdviser sister title FTfm, reveals that at least six wealth managers have fallen prey to this scam in the past four months, costing clients a total of £45m.
Mr Hilbert told FTAdviser that one IFA was the first to be targeted with the scam. One client of the firm ended up losing £7m after the adviser’s email was hacked.
He said initial steps of the scam can include setting up legitimate-looking wifi hotspots in airports requiring advisers – or anybody – to provide a password and email address to log in. Because so many people use the same password across many sites, cyber criminals could then easily break into the adviser’s email account.
After gaining access to the adviser’s account the thieves can set up email filters which will make client correspondence skip the inbox and go straight to a special folder, allowing the thieves to communicate with clients and clearing banks under the guise of their adviser.
Mr Hilbert said: “The bad guys will attack them without them knowing. There is no intention to attack and harm the wealth manager at all.”
Only when investigators find the email folder ‘smoking gun’ will the adviser realise the scam which was afoot.
He said the best ways to avoid falling victim to these scams are for advisers to have personal relationships with banks or other parties who can contact them in case of unusual transfer requests.
Keeping an eye on email filters set up in your account is another way of remaining alert to the wiles of potential cyber thieves.
Mr Hilbert added that some of the £45m has since been recovered, as the transfers can eventually be traced.
