Wire Fraud
Wire fraud is consistently cited by security professionals as one of the most serious operational threats facing family offices. The most common form is business email compromise: an attacker gains access to or spoofs a legitimate email address — often impersonating a family principal, attorney, or financial institution — and sends convincing instructions to initiate a wire transfer. Because family offices move large sums as part of normal operations, and because staff are often conditioned to respond quickly to principal requests, these attacks can succeed even against careful, well-run organizations. Once funds leave via wire, recovery is difficult and often impossible.
The attack works because it exploits trust and urgency rather than technical vulnerabilities. A message that appears to come from a family member saying "I need a transfer done today for a closing" is designed to short-circuit normal controls. This is why procedural defenses matter more than technological ones: offices that require verbal confirmation via a known phone number for any wire instruction — regardless of how legitimate the email appears — are far harder to deceive. Dual control requirements add a second line of defense, because a fraudulent instruction must now fool two people rather than one.
Families also commonly address wire fraud risk through staff training, strict bill pay procedures, and clear policies about how payment instructions may be changed or updated. A policy stating that bank account changes for any vendor or counterparty require verbal verification through a pre-established number — never a number provided in the change request itself — eliminates one of the most common attack vectors. Wire fraud risk is a meaningful reason why governance documents like the approval matrix should address not just who may approve payments, but exactly how approvals must be communicated and verified.
Verwante begrippen
Dual control is an operational requirement that two authorized individuals must independently…
BegripSocial EngineeringA manipulation technique where attackers exploit human trust or authority rather than technical…