On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

June 14th, 2006

Internal fraud coupled with IT savvy is a killer combination

Posted by Richard Stiennon @ 12:56 pm

Categories: Spyware, State Sponsored Hacking

Tags:

As any auditor knows internal fraud is as old as business. The classic case involves the secretary who is responsible for accounts payable as well as procurement. He generates bogus invoices and pays them to bogus companies. I have a friend in Chicago whose business was ruined this way.  A law firm here in Michigan lost millions to the Nigerian 419 scam because their secretary had access to the firm’s funds. ( By the way check out this article. A couple of con artists in Toronto have received jail terms.  Nigerians are not responsible for all advance-fee scams! )

Modern accounting controls are supposed to prevent this kind of fraud. The real danger is that controls are not keeping pace with technology. Since the introduction of the first commercial computer (UNIVAC,  on this date in 1951) computers have been used to make the fraudster’s job easier.   This article mentions three cases of admittedly low tech fraud but involving IT staff. In one case a mid level IT manager at the Canadian Defense Department created bogus orders for Tempest Terminals that were funneled through a supplier, HP, to front companies from which he would get kick backs.  The point is that IT staff are not above sneaking a buck out of the till now and then.  Imagine the consequences if a developer or internal admin monkeys with the workings of your automated billing and receivables software?

What could an insider accomplish with a few simple credentials? Access to the treasury system for instance. Most large organizations swap millions into overnight instruments to take advantage of the best interest rates only to swap them back into their working accounts during the day. Skimming a piece of that transaction could be simple. 

It is probably a good time to review internal controls at your organization. Rolling out a new layer of authentication could cut short any existing fraudulent operations. Strong authentication for any treasury function should be mandated. Monitoring of transactions and data transmissions is another step. And an audit of existing controls, including a test would be good.

Richard Stiennon is an industry consultant. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 15 Talkback(s)
You need proof and a white knight in a bullet proof vest
to begin with. Organizations have worked together for years, long before computers, to take advantage of situations and continue to be successful as long as they don't get too greedy. Greed is the do... (Read the rest)
Posted by: Dumber_z Posted on: 06/26/06 You are currently: a Guest | | Terms of Use
Rounding error  Anton Philidor | 06/14/06
Hah!  RStiennon | 06/14/06
This is one thing where IT doesn't matter at all  vdenisov@... | 06/15/06
Disagree  RStiennon | 06/15/06
So?  vdenisov@... | 06/15/06
Checks and balances  RStiennon | 06/15/06
Bank tellers.  Anton Philidor | 06/15/06
Of course not perfect  RStiennon | 06/15/06
real world example  kckn4fun | 06/15/06
Absolutely agree  vdenisov@... | 06/15/06
Yikes  RStiennon | 06/15/06
Non-negotiable audit trails....  RU_Trustified | 06/17/06
Also....  RU_Trustified | 06/17/06
Not just fraud, retribution  sixt7gt350@... | 06/15/06
You need proof and a white knight in a bullet proof vest  Dumber_z | 06/26/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    Favorite Links

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    SmartPlanet

    Click Here