The Securities and Exchange Commission (SEC) is urging companies to consider cyber threats more closely when implementing internal accounting controls, following a report on nine organisations that fell victim to cyber frauds with combined losses of some $100m (£76m)
The US regulator focused on ‘business email compromises’ (BECs) in which perpetrators posed as company executives or vendors and used emails to dupe company personnel into sending large sums to bank accounts controlled by the perpetrators.
The frauds in some instances lasted months and often were detected only after intervention by law enforcement or other third parties. Each of the companies lost at least $1m, two lost more than $30m, and one lost more than $45m. In total, the nine companies wired nearly $100m a result of the frauds, most of which was unrecoverable. No charges were brought against the companies or their personnel.
The companies, which each had securities listed on a national stock exchange, covered a range of sectors including technology, machinery, real estate, energy, financial, and consumer goods. The FBI estimates fraud involving BECs has cost companies more than $5bn since 2013.
SEC chairman Jay Clayton said: ‘Cyber frauds are a pervasive, significant, and growing threat to all companies, including our public companies. Investors rely on our public issuers to put in place, monitor, and update internal accounting controls that appropriately address these threats.’
Report by Pat Sweet