The National Fraud Intelligence Bureau (NFIB) has seen an increase in recent weeks in the volume of CEO Fraud reports whereby schools are the targeted victim. This has resulted in substantial financial losses for several schools that have fallen victim to this type of fraud.
A school is targeted by a fraudster who purports to be the Head Teacher / Principal. The fraudster contacts a member of staff with responsibility for authorising financial transfers and requests for a one-off, often urgent, bank transfer to be made. The amounts requested have been between £8,000 and £10,000.
Contact is made by email and from a spoofed / similar email address to the one the Head Teacher / Principal would use.
PROTECTION / PREVENTION ADVICE
- Ensure that you have robust processes in place to verify and corroborate all requests to change any supplier or payment details. Get in touch with the supplier (or internal colleague) directly, using contact details you know to be correct, to confirm that a request you have received is legitimate.
- All employees should be aware of these procedures and encouraged to challenge requests they think may be suspicious, particularly urgent sounding requests from senior employees.
- Sensitive information you post publicly or dispose of incorrectly, can be used by fraudsters to perpetrate fraud against you. The more information they have about you, the more convincingly they can purport to be one of your legitimate suppliers or employees. Always shred confidential documents before throwing them away.
- Email addresses can be spoofed to appear as though an email is from someone you know. If an email is unexpected or unusual, then don’t click on the links or open the attachments. Staff should not be allowed to check emails or use the internet with administrator accounts.
- If you have been affected by this, or any other type of fraud, report it to Action Fraud by calling 0300 123 2040 or visiting www.actionfraud.police.uk.