The WPI Hub | Spread | Secure It June 2024 (2024)

A monthly Information Security publication for the WPI community.

June's focus is on FISCAL YEAR END SECURITY. The end of the fiscal year is a busy time for an organization. Criminals exploit that by impersonating legitimate businesses and taking advantage of the likelihood that people may not have time to scrutinize requests.

In this issue:

  • Invoice Fraud: Recognizing and Preventing
  • WPI's Fraud Prevention Strategies
  • Red Flags
  • Example of a Fraudulent Invoice
  • Learning with Laughter
  • Featured Videos
  • In the News & by the Numbers
  • WPI Resources
  • Diversity in Cybersecurity
  • Coming Next Month...

Invoice Fraud: Recognizing and Preventing

According to CFO Share, these are the 3 most common types of accounts payable fraud:

  • Fake vendors and invoices fraud - when someone either internal or external to the company creates a fake invoice. No goods or services are given to the company and the creator and/or their associates profits from it.
  • Check fraud - this usually happens when there are lost checks or duplicate payments and someone pockets the money.
  • Expense reimbursem*nt fraud - this is when an employee submits a false or exaggerated expense report for personal profit.

And these methods help to prevent it:

  • Segregation of duties:for example entering data, approving transactions, and paying bills are tasks that should be done by 3 different people.
  • Staff education:people are more likely to detect fraud when they have been taught exactly what to look for.
  • Routine audits of fraud prevention processes:a best practice is having an external organization perform this audit to ensure the processes are being followed correctly. Failure to follow established procedures is a common weak link in the accounts payable process.

3 Types of Invoice Fraud and How to Prevent it (CFO Share)

WPI's Fraud Prevention Strategies

Workday's detailed audit trails, requirement of receipts, and engagement of multiple approvers helps to prevent fraud.

WPI Workday processes support fiscal security by:

  • Detailed audit trail in Workday for invoices and purchase orders.
  • Electronic payments with detailed audit trails in Workday to prevent check fraud.
  • Requiring receipts for expenses that are $75 or more.
  • Clearly defined approval procedures for how many people need to approve large transactions.
  • Highly defined roles in Workday so users have access to exactly what they need to do their jobs and no more. In cybersecurity this is known as the principle of least privilege.

Vendor relationships:

  • WPI's Procurement team manages supplier policies and master agreements. Their policies afford consistency and thorough oversight, making vendor fraud more difficult for scammers to accomplish.
  • Individual employees can support fiscal security by developing strong relationships with vendors. An example exists between ITS and DelSignore Electric, a partner for many years. There are two specific individuals there that ITS works with for billing. If a questionable invoice or suspicious email ever arises, these direct contacts could confirm or deny the legitimacy and fraud would be stopped in its tracks!

Education:

  • The SECURE IT newsletter and related materials educate the WPI community on cybersecurity.
  • WPI's Finance & Operations staff regularly offer assistance and training on best practices.

Red Flags

The more familiar we are with differences between legitimate and false invoices and requests, the more confident our decisions on whether to respond or report! According to EFT Sure's blog, here are 10 red flags for fraud:

  1. Spoofed invoices or incorrect information about vendors
  2. Unknown senders or unverified vendors
  3. Unusual requests for sensitive information
  4. Suspicious links or attachments
  5. Unsolicited emails, phone calls or text messages
  6. Enticing offers that sound too good to be true
  7. Incorrect email addresses
  8. Grammar and spelling mistakes
  9. Blurry company or entity logos
  10. Urgent or threatening language

End of financial year scams 2023: how to spot them (EFT Sure)

Example of a Fraudulent Invoice

This screenshot of an invoice scam looks like an official business email and entices the user to provide a phone number and email.

Notice how it does not include the sender's company, the receiver's company, or make any references to the specific goods or services provided.

The WPI Hub | Spread | Secure It June 2024 (1)

Grammatical errors are common in fraudulent email messages. Of note in this email:

  • "The below reject reason" is not how a fluent English speaker would word that phrase.
  • "Can not be process" is an incorrect verb conjugation. It should be "cannot be processed."
  • "Can not" is typically written as 1 word.
  • "Finial" instead of final.
  • Reading the comment section out loud sounds a bit choppy, as if a few words were omitted.

Learning with Laughter

The WPI Hub | Spread | Secure It June 2024 (2)

Featured Videos

These news segments discuss how to spot and avoid scams.

Scams to Look Out for in 2024 (NBC Detroit)Scams to Look Out for in 2023 (CBS Houston)

In the News

Virginia Commonwealth University was conned out of $470,000 when a British citizen impersonated an employee at a construction firm VCU uses. Then the money was laundered in Los Angeles.

LA businessman accused of laundering money stolen from VCU (ABC Richmond)

Evaldas Rimasauskas was one of the orchestrators of a Lithuania-based business email compromise (BEC) scheme that started in 2013 and stole over $120 million from Facebook and Google.

Leader of Fraud Ring Sentenced (FBI)

By the Numbers

- $752 million lost to business imposters in 2023.

- In358,000 reports to the FTC, scammers contacted the victims by email.

- 2.6 million fraud reports were sent to the FTC in 2023.

Facts about fraud from the FTC – and what it means for your business (FTC)

WPI Resources

If you receive a questionable email pertaining to WPI financials, take 5 minutes to think before you respond!

Take 5! (WPI Hub)

WPI policies help to safeguard our financial data. If end-of-year tasks raise any questions about these, Information Security would be happy to assist.

Graham-Leach-Bliley PolicyData Classification and Usage PolicyRestricted Use Data Clean Desk and Clear Screen Policy

Diversity in Cybersecurity

Tia Hopkins,Chief Cyber Resilience Officer

The WPI Hub | Spread | Secure It June 2024 (3)

Tia Hopkins

Coming Next Month...

Phishing!

Is there a cybersecurity topic that you would like to know more about? Please contact WPI Information Security using Get Support below.

The WPI Hub | Spread | Secure It June 2024 (2024)

FAQs

What is the acceptance rate for WPI? ›

About Worcester Polytechnic Institute

Worcester Polytechnic Institute is a medium-sized private institution located on an urban campus in Worcester, Massachusetts. It has a total undergraduate enrollment of 5,224, and admissions are selective, with an acceptance rate of 60%.

Where is the WPI registrar? ›

Unity Hall

What is WPI ranked in 2024? ›

Worcester Polytechnic Institute's ranking in the 2024 edition of Best Colleges is National Universities, #82.

How prestigious is WPI? ›

Worcester Polytechnic Institute is one of the top universities in Worcester, United States. It is ranked #901-950 in QS World University Rankings 2025.

How many credits is full time at WPI? ›

All full time students are expected to register and enroll in twelve 36 credits per academic year *.

Who is the head of the school at WPI? ›

Grace Wang, PhD, began as WPI's 17th president on April 3, 2023.

Does WPI accept dual enrollment credits? ›

Early college, early entrance programs, “College in the High School”, or any dual enrollment coursework provided in partnership with a college/university but offered in the high school classroom and taught by certified high school teachers are not eligible for credit at WPI.

What GPA do you need to get into WPI? ›

With a GPA of 3.9, Worcester Polytechnic Institute requires you to be at the top of your class.

Is WPI difficult to get into? ›

Worcester Polytechnic Institute admissions has an acceptance rate of 57% and an early acceptance rate of 64.5%. The application deadline at Worcester Polytechnic Institute is Feb. 1. Admissions officials at Worcester Polytechnic Institute consider a student's GPA a very important academic factor.

Is WPI a top tier school? ›

Worcester Polytechnic Institute is ranked #82 out of 439 National Universities. Schools are ranked according to their performance across a set of widely accepted indicators of excellence.

What is WPI famous for? ›

WPI is often remarked on for its many inventions that have changed the world. Explore notable WPI alumni that have graduated from WPI. Students, faculty, and alumni of WPI have changed the world with inventions ranging from liquid-fueled rockets to concrete that heals its own cracks.

References

Top Articles
Latest Posts
Article information

Author: Stevie Stamm

Last Updated:

Views: 5669

Rating: 5 / 5 (60 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Stevie Stamm

Birthday: 1996-06-22

Address: Apt. 419 4200 Sipes Estate, East Delmerview, WY 05617

Phone: +342332224300

Job: Future Advertising Analyst

Hobby: Leather crafting, Puzzles, Leather crafting, scrapbook, Urban exploration, Cabaret, Skateboarding

Introduction: My name is Stevie Stamm, I am a colorful, sparkling, splendid, vast, open, hilarious, tender person who loves writing and wants to share my knowledge and understanding with you.