How to Make Email Fraud Prevention a Priority

Blaine Sanderson   July 31st, 2025

Best Practices to Protect Your Inbox From Fraud_web banner

The role email plays in business has changed significantly in the past decade. New channels of communication such as SMS messaging and social media mean that businesses aren’t as dependent on email as they once were. When it comes to fraud, however, email unfortunately still reigns supreme.   

According to a 2025 report by the Federal Trade Commission (FTC), email is still the most commonly used channel for scammers. As cybercrime on the whole has skyrocketed over the past several years, businesses are taking a more proactive angle and investing in fraud prevention tools. Understanding how to detect fraud emails and how to avoid email fraud on the whole will remain a key concern for businesses for the foreseeable future.  

“In 2025, technology is advancing faster than we’ve ever seen. That makes it hard for businesses to keep up with the different kinds of threats out there, and what they can do to prevent them. MHC NorthStar is designed to give our customers peace of mind that lets them go about their day-to-day operations without worrying about fraud prevention.”

Gina Armada, former CEO of MHC 

WEBINAR

Your IT team’s email filters don’t block all fraudulent emails. Join MHC’s webinar featuring Debra R Richardson and learn how to keep your company’s inbox protected from fraud!

IT and Your Inbox: Email Fraud

Did you know that some cybersecurity experts estimate that around 85% of the emails sent every day are spam? Did you also know that the typical IT security system is only able to filter out around 85% of that spam? That may not look like a bad percentage, but as Debra R. Richardson notes, “The problem is that you still have to deal with that 15%.” Email-based cyberattacks have skyrocketed in recent years, putting virtually every business and organization at greater risk of falling victim to fraud. Let’s take a closer look at some of the most important elements of email fraud, in Richardson’s words.

Types of Email Fraud

Phishing emails are the most familiar form of email fraud. Phishing is defined as posing as a legitimate source in order to send fraudulent communications. Along with email, these can include variations such as vishing (voice-based fraud, usually over the phone), smishing (SMS or text-based fraud), and quishing (QR code-based fraud). Richardson breaks phishing down into three main categories:

Debra R Richardson LLCThe first one is the beginner’s level, just a mass email. The fraudsters are sending out millions of emails just to see who’s going to click. Then you get to spearfishing, where they’re targeting a specific person or group. They’re watching you on social media, they’re checking you out on Facebook and LinkedIn to see who your connections are, what content you’re responding to. When they send an email to your inbox, it seems more legitimate because they’re using content and words from what they saw you connecting with on social media.

Then there is whaling. That’s where they’re really targeting the inboxes of your senior executives. If you get an email from the C-suite, just because of basic human behavior, the first thought process is to make sure you hurry up and do what the boss says.

Debra R. Richardson, Accounts Payable Speaker

A business email compromise (BEC) is a specific form of phishing in which a fraudster poses as someone with authority in order to get employees to send them money or data, or to provide access to higher levels of their system. Richardson highlights two key areas of focus for BEC accounts payable scams:

Debra R Richardson LLCThose emails are getting into your inbox for the vendor maintenance teams that have the ability to add or change banking or remittance details on the vendor master file. You are being targeted so that you can either change that information to divert vendors’ payments for legitimate invoices, or to divulge sensitive information so that the frauds can create their own fictitious invoices.

Check fraud is exploding. They’re also including the change of remittance address for vendors that have check payments. They’re getting those checks, they’re whitewashing them, and they’re very successful at getting those checks cashed.

Debra R. Richardson, Accounts Payable Speaker

Tricks Fraudsters Use to Seem More Real

Spam filters manage to catch 85% of fraud emails, but how do scammers manage to land that last 15% in your inbox? The creativity of cybercriminals is endless, unfortunately, but according to Richardson, some of the most frequently seen tricks of the trade include:

Email addresses including subtle misspellings or similar-looking characters, such as “O” and “0” or “.com” and “.co”

Emails originating from real addresses using stolen login credentials

Using CSS code to evade external email indicator filters

Evading ChatGPT fraud filters by instead generating AI content on FraudGPT, WormGPT, and other unethical sites

Monitoring social media feeds to access employees’ contacts and personal information for use in phishing schemes

Job seeker schemes that rely on employee behavior, such as staging fake interviews in order to obtain personal data and access employee emails

Richardson also notes that too many businesses are overconfident in making confirmation calls to vendors as a method of avoiding fraud. “The confirmation call is not that silver bullet, because if it was there would be no fraud. Say the vendors don’t pick up. They may send us a legitimate change, but they’ll send it to us and then they’ll go off and do vendor things. Or it could be that you just don’t have the right contact. Lots of companies are removing telephone numbers and email addresses because of fraud, so it’s getting harder to reach out to those vendors, especially vendors that are not in the U.S.”

Even when you do reach a vendor, if the team members are using information that came from a fraud email or fictitious invoice, the fraudsters are going to say, ‘Sure, I approve!’ or ‘Right, I submitted that request for a bank account change or remittance address change!’

6 Ways to Combat Email Fraud

Want to beat fraudsters to the punch with a plan for spotting fraud before it happens? Debra Richardson outlines five best practices and useful tools that can help your organization stay several steps ahead of fraudulent behavior.

1. Keep Up to Date with Frauds and Scams

There are resources where you can either sign up to get alerts or search for the latest news. There’s the FBI. For those that are doing 10-99s in-house, you’ll want to sign up for the IRS tax scam/consumer alerts. They have a whole e-news subscription.

The Better Business Bureau has one, they’re really good for regional scams. And you can sign up for my new scam alerts. I review all the different resources and post them. I’ve been posting about two to three per week.

2. Share the Knowledge

Once you get those scam alerts or new fraud trends, share them with your team. If you have a vendor team or accounts payable team meeting on a recurring basis, have fraud as a static agenda item.

Talk about the latest frauds that are out there. If you’ve gotten tools to help avoid fraud, share that with your team members so they have it as well.

3. Password Manager 

Employees can have up to a hundred passwords to remember. Best practices says just don’t reuse them, so that if a fraud does get a hold of your info, they won’t be able to get into your email or other accounts. But that’s easier said than done with so many passwords to remember. Another best practice is to make sure that they’re around 20 digits long so it takes much longer to crack. 

With a password manager you don’t have to remember those long passwords. It’ll generate them for you. If you happen to click on a phishing link, if that is not a legitimate site the password manager will not prefill your username and password. That can be another red flag for you.”  

4. Whois.com  

Another zero-cost tool is whois.com/whois, the domain lookup. If you are suspicious about an email domain or an email address, you can copy and paste it into this search. You’re going to get a lot of information, but what I look at is the date of registration.

You’re not going to know the dates of all of your different vendors, of course, but what you will know is if it was a recent date. Lots of times fraudsters will create specific spoof sites just for a campaign that they’re going to be running. It could be a red flag if it has a date that is within weeks or months.” 

5. Secured Email For Sensitive Data  

Say you’re sending sensitive information like banking documents or W-9s, anything with a social security number on it. You can put the vendor’s actual email address into a secured email. The vendor will get a request to sign in again using that actual email address.

What I like about it is when you’re exchanging that sensitive information, it doesn’t even have to be on a form. The fields to input that data can be embedded in that actual form. Best practice is to update it every year, because if you get an old form, that’s an indication that it could be fraud.” 

6. Authentication Reference Template 

When you contact your bank, they will ask you two to three identifying questions before they even start talking to you, just to make sure you are who you say you are. You can do this too, via phone or email. Studies have shown that if you push back on frauds, they’ll hang up or abandon the email string and go on to the next victim.

If they’re asking, ‘Hey, how do I change my banking?’ you say, ‘No problem, can you give me an invoice number and the last five digits of your existing bank account?’ If they don’t have the existing bank account, that is a huge red flag.

7 Ways to Know If Your Email Has Been Hacked

If you suspect your email has been compromised but aren’t 100 percent certain, there are a few telltale signs to look into before you take further action. If any of these items check out, you may be the victim of an email hack. Don’t panic — security breaches happen all the time, and your business likely has a plan in place for this exact situation — but do be sure to alert the appropriate channels within your organization.

1. You aren’t able to log in to your email

2. You get notified that an unauthorized device tried to access your account 

3. You’re receiving unexpected password reset emails  

4. Your Sent folder contains messages you don’t remember sending 

5. Co-workers and contacts report receiving strange emails from your account

6. Your account seems to have accessed sites or tools that you wouldn’t usually use

7. Your account data has been altered or edited

Debra R. Richardson’s 6-Step Process to Avoid a Fraudulent Payment if a Fraudulent Email Gets Through

So what happens in the event that one of these fraudulent messages makes it into your inbox? Debra Richardson lays out a six-point plan for avoiding fraudulent payments and not playing into the fraudsters’ hands.

1. Authenticate the Requester:
Make sure the requester can correctly answer a series of identifying questions before complying with their request. 

2. Authenticate the Data:
Always ask the requester to provide authenticating data about existing accounts before approving any banking changes. 

3. Vendor Communication Before and After Change:
Verifying a change with a vendor both before and after you make it gives you an added chance to catch fraudulent requests. 

4. Check Payments Before Sending:
Double-check that the payment amount you’re about to send matches the original request and that no unauthorized changes have been made.   

5. Confirm That the Vendor Received Payment:
A quick check-in with each vendor to ensure that payments have been received can help avoid confusion later on. 

6. Document and Audit Your Process and Vendor Data:
Keeping careful records and running regular audits makes it easier to spot patterns of fraud, as well as potential security gaps.

How Can MHC NorthStar Help with Email Fraud Prevention?   

Is it time for your organization to bolster fraud prevention by making the leap to an automated AP software system? If you’re ready to see some of these anti-fraud tools in action, contact us today to schedule a free demonstration of our MHC NorthStar software solutions. We’re eager to show you the difference a reliable AP automation system can make in guarding your organization against fraud at every level.

Email Fraud FAQ

“Email fraud” is a broad term for a number of scams, including business email compromises, phishing, fake invoices, and distributing malware. The goal in every case is to steal personal information or financial data, or to trick a recipient into a fraudulent transfer of funds.  

How to report fraud emails varies between different organizations, but most business email systems provide built-in options for reporting emails that you suspect to be fraudulent.  

Again, where to report email fraud depends on your business’s practices and preferences. Generally speaking, a single phishing attempt or other fraud does not require IT intervention, but repeated or high-volume fraud attempts might. 

As cybercrime tools become more sophisticated, identifying fraudulent emails becomes even trickier. Be on the lookout for emails that don’t pass your organization’s authentication tests, text that is filled with spelling and grammar errors, language that sounds artificial or unnatural, and tone that creates a stronger than usual sense of urgency. 

While email filters and security systems can reduce the number that make it to your inbox, fraud emails are here to stay. Rather than focusing on how to stop the scammers, invest in email fraud prevention solutions that make their efforts easy to identify and remove, and training that teaches employees how to detect fraud emails. 

Avoiding email fraud requires a combination of trained employees and reliable tools. Investing in email security and automated customer communications management (CCM) is the surest way to keep your organization from becoming the latest victim of email scammers. 

FREE DEMO

Get a Live Demo Today

Agile and reliable delivery of high-impact communications when it matters most. Experience it today! Easily integrated with your business systems, utilizing our cloud-based platform will guide you to communication success.

DEBRA R RICHARDSON – Accounts Payable Speaker | Consultant | Trainer

Debra is an accounts payable speaker, consultant, and trainer with over 20 years of experience in AP, AR, general ledger, and financial reporting for Fortune 500 companies including Verizon, General Motors, and Aramark.

For ten years, Debra has focused on Global Vendor Setup and Maintenance. As AP Sr Manager she led a team that processed over 2,000 vendor add/change requests per month and was responsible for 140k+ active global vendors across seven ERPs. In her consultancy, she provides accounts payable teams consulting services and training to add authentication techniques, internal controls, and best practices to prevent fraud, fines, and bad vendor data.

She has a YouTube channel where she posts vendor master file tips every Tuesday, and hosts a weekly podcast: “Putting the AP in hAPpy”.

Blaine K. Sanderson

Blaine K. Sanderson is Senior Product Manager for Procure-to-Pay solutions at MHC, where he leads product strategy and innovation for accounts payable automation. With more than two decades of experience in enterprise content management, workflow automation, and ERP integration, Blaine has deep expertise in helping organizations modernize financial operations across SaaS and on-premises environments. Before joining MHC, he held product management and architecture roles at Bottomline Technologies and 5280 Solutions, shaping AP automation offerings used by leading enterprises.

Share this post

Facebook
LinkedIn
X

Explore Our Topics

Explore Our Verticals

Read the 2026 QKS Group SPARK Matrix™ CCM Report

Every CCM vendor claims AI. This independent analyst report cuts through the noise — ranking platforms on actual delivery. MHC is named a Market Leader.

Industry Trends

BLOG & INFOGRAPHIC

Stay ahead of the curve with the top 26 communication trends shaping 2026! Read on for expert insights from our award-winning SMEs and see our infographic.

BLOG

Discover the key 15 trends in accounts payable for 2026! Featuring insights from AP experts Mary Schaeffer & Mark Brousseau, MHC’s Blaine Sanderson and more.

var _hsq = window._hsq = window._hsq || []; _hsq.push(['setContentType', 'blog-post']);
Scroll to Top