Where one unauthorised request becomes an expensive event
01
One root, many frauds
Every fraud below works the same way: someone impersonates a trusted party to trigger an action — a payment, a change of details, the acceptance of a document. They are one problem wearing different clothes.
$55bn+
Nine situations, one shape: the channel is authentic and the instruction inside is not the organisation’s. Each card says what can be established TODAY — and each of those answers is bounded by the same fact: the questions are built, and no organisation is enrolled.
02
Nine names, one question
Open the situation you are in.
The same question settles all of them — and it is a cryptographic question, not a judgement call.
03
The telephone check that complements the proof
For bank-detail changes above all: call the supplier on a number you already had — never the number in the request — and confirm one field with the dictated code. The code reveals nothing by itself; it confirms, it does not disclose.
CEO fraud, supplier impersonation, a redirected payroll, a closing account changed at the last minute — the attacker’s work is the same each time: make an unauthorised request look ordinary. The question that separates them from a real one does not change either: what evidence exists for THIS request?