<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Fraud &#8211; Crawford Ellenbogen</title>
	<atom:link href="https://www.ce-cpa.com/category/fraud/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.ce-cpa.com</link>
	<description></description>
	<lastBuildDate>Tue, 22 Aug 2023 13:59:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.3</generator>
	<item>
		<title>How secure is your accounts receivable department?</title>
		<link>https://www.ce-cpa.com/how-secure-is-your-accounts-receivable-department/</link>
		
		<dc:creator><![CDATA[Victor Dozzi]]></dc:creator>
		<pubDate>Tue, 22 Aug 2023 13:59:45 +0000</pubDate>
				<category><![CDATA[Fraud]]></category>
		<category><![CDATA[accounts receivable]]></category>
		<category><![CDATA[discounts]]></category>
		<category><![CDATA[fraud prevention]]></category>
		<category><![CDATA[lapping]]></category>
		<category><![CDATA[misappropriation]]></category>
		<category><![CDATA[write offs]]></category>
		<guid isPermaLink="false">https://www.ce-cpa.com/?p=6653</guid>

					<description><![CDATA[Asset misappropriation schemes make up more than half of all occupational fraud schemes, according to the Association of Certified Fraud Examiners. It’s a broad category that includes everything from skimming cash to stealing inventory to paying “ghost” employees. One hotspot for asset misappropriation is the accounts receivables department, where dishonest staffers could potentially divert customer]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Asset misappropriation schemes make up more than half of all occupational fraud schemes, according to the Association of Certified Fraud Examiners. It’s a broad category that includes everything from skimming cash to stealing inventory to paying “ghost” employees. One hotspot for asset misappropriation is the accounts receivables department, where dishonest staffers could potentially divert customer payments for their own use. If you don’t have strong internal controls for receivables, what are you waiting&nbsp;for?</p>



<p class="wp-block-paragraph"><strong>Lapping leads</strong></p>



<p class="wp-block-paragraph">The most common form of receivables fraud is lapping, where perpetrators apply receipts from one account to cover misappropriations from another. For example, rather than credit Customer A’s account for its payment, a thief may pocket the funds and later post a payment from Customer B to A’s account, Customer C’s payment to B’s account, and&nbsp;so&nbsp;on.</p>



<p class="wp-block-paragraph">Unethical write-offs and discounts are also popular. Instead of crediting a payment to a customer’s account, fraudsters might pocket the funds and then record a bad debt write-off or discount to the customer. Even though incoming payments are diverted, the customer’s account would reflect the expected current balance.</p>



<p class="wp-block-paragraph"><strong>Investigation and prevention&nbsp;</strong></p>



<p class="wp-block-paragraph">If receivables fraud is suspected, a forensic expert usually can trace a sample of cash receipts to the sales ledger and deposit slips to find discrepancies in dates, payee names and amounts. An expert also may compare deposit slips against the books and send requests for confirmations to a sample of customers to verify current balances and payment histories. Bad debt write-offs, accounts with unexplained credits, increased customer credit limits and random adjustments to the accounts receivable ledger could also come under scrutiny during a fraud investigation.</p>



<p class="wp-block-paragraph">But to help prevent receivables fraud from occurring in the first place, businesses should segregate duties. This means that an employee who handles incoming payments from customers should be different from the person who handles invoicing. Also consider assigning a different employee to manage customer complaints because complaints tend to&nbsp;increase if someone is misappropriating receivables. Other helpful controls include mandating vacation time and job rotation for all accounting staffers.</p>



<p class="wp-block-paragraph"><strong>Consider audits&nbsp;</strong></p>



<p class="wp-block-paragraph">You may also want to consider conducting regular (and surprise) audits of receivables. Not only might audits help catch schemes in progress, but they enable you to test your controls and ensure employees are following them to the letter. Contact us&nbsp;for&nbsp;help.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Good acquisition? Not if your seller’s hiding something</title>
		<link>https://www.ce-cpa.com/good-acquisition-not-if-your-sellers-hiding-something/</link>
		
		<dc:creator><![CDATA[Victor Dozzi]]></dc:creator>
		<pubDate>Thu, 06 Jul 2023 13:50:33 +0000</pubDate>
				<category><![CDATA[Fraud]]></category>
		<category><![CDATA[buying a business]]></category>
		<category><![CDATA[red flags]]></category>
		<guid isPermaLink="false">https://www.ce-cpa.com/?p=6616</guid>

					<description><![CDATA[If you’re considering buying a company, fraud may be the last thing on your mind. Unfortunately, you can’t afford to ignore the possibility that your acquisition target is hiding something — possibly something that will have negative financial and legal implications after the deal is complete. To ensure the transaction is what it appears to]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">If you’re considering buying a company, fraud may be the last thing on your mind. Unfortunately, you can’t afford to ignore the possibility that your acquisition target is hiding something — possibly something that will have negative financial and legal implications after the deal is complete. To ensure the transaction is what it appears to be, acquaint yourself with the issues and include a forensic accounting expert on your deal team.</p>



<p class="wp-block-paragraph"><strong>Look at the numbers</strong></p>



<p class="wp-block-paragraph">During the due diligence process of a merger or acquisition, forensic experts review financial statements for subtle warning signs of fraud. These include excess inventory, a large number of write-offs, an unusually high number of voided discounts for returns, insufficient documentation of sales and increased purchases from new vendors. Another suspicious sign is increased accounts payable and receivable combined with dropping or stagnant revenues and income.</p>



<p class="wp-block-paragraph">Fishy revenue, cash flow and expense numbers as well as unreasonable-seeming growth projections warrant further investigation to determine whether financial statements represent fraud or they’re evidence of unintentional errors or mismanagement. The latter is common in smaller companies that don’t have their statements audited by outside experts or that may not have adequate internal financial expertise.</p>



<p class="wp-block-paragraph"><strong>Watch for red flags</strong></p>



<p class="wp-block-paragraph">To determine whether unusual income figures indicate systematic manipulation, experts often consider whether insiders had the opportunity to commit fraud. A lack of solid internal controls usually raises red flags. Regulatory disapproval, customer complaints and suspicious supplier relationships can also indicate fraud. If warranted, an expert may perform background checks on your target company’s principals.</p>



<p class="wp-block-paragraph">It’s important to note that some accounting practices adopted to present a selling business in the best light may be perfectly legal. However, if your expert finds evidence of intentional fraud —particularly at the executive level — you’ll probably want to rescind your acquisition offer. In less serious cases, you may simply need to make purchase price adjustments or even change the deal’s structure.</p>



<p class="wp-block-paragraph"><strong>Manage risk</strong></p>



<p class="wp-block-paragraph">There’s a way to help protect your transaction even if a seller successfully hides financial manipulation and other illegal activities: Include an indemnification clause in the purchase agreement. Your advisors may have to wrangle with the seller over such details as the definition of “fraud” and liability limits, but such clauses can help you manage the significant risk most acquisitions involve. Contact us for more information.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Before you scan a QR code, make sure it’s legitimate</title>
		<link>https://www.ce-cpa.com/before-you-scan-a-qr-code-make-sure-its-legitimate/</link>
		
		<dc:creator><![CDATA[Victor Dozzi]]></dc:creator>
		<pubDate>Thu, 29 Jun 2023 14:13:15 +0000</pubDate>
				<category><![CDATA[Fraud]]></category>
		<category><![CDATA[QR code scams]]></category>
		<guid isPermaLink="false">https://www.ce-cpa.com/?p=6609</guid>

					<description><![CDATA[Technology has made seemingly everything fast, convenient and easily accessible. This is certainly true of quick response (QR) codes, those ubiquitous symbols you can find on everything from restaurant menus to product packages to advertisements. When you scan QR codes with a smartphone, you can access prices, instructions, product information and even payment apps. But]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Technology has made seemingly everything fast, convenient and easily accessible. This is certainly true of quick response (QR) codes, those ubiquitous symbols you can find on everything from restaurant menus to product packages to advertisements. When you scan QR codes with a smartphone, you can access prices, instructions, product information and even payment apps.</p>



<p class="wp-block-paragraph">But as with most technologies, fraud perpetrators have found ways to exploit QR codes — and steal from consumers and businesses. Here’s what you need to know.</p>



<p class="wp-block-paragraph"><strong>How thieves use them</strong></p>



<p class="wp-block-paragraph">Last year, the FBI issued an alert about QR code tampering. Fraudsters replace or alter QR codes so that users are directed to malicious websites or inadvertently download malware onto their devices. Such schemes enable fraudsters to access victims’ account usernames and passwords and personal and financial information.</p>



<p class="wp-block-paragraph">Unfortunately, it’s very easy for criminals to create QR codes using online tools. They replace the codes of legitimate businesses with their own by, for example, placing stickers over existing codes. Such stickers have been found on menus, parking meters, signs in front of businesses and packaging of all kinds. Fraudsters might also include them in phishing emails or printed advertisements, coupons or surveys sent through the U.S. Post Office.</p>



<p class="wp-block-paragraph"><strong>Foiling schemes</strong></p>



<p class="wp-block-paragraph">Preventing QR fraud is similar in many ways to foiling phishing schemes. When you’re directed to a website, scrutinize it for authenticity. Fraudulent sites often look amateurish and feature misspellings and typos. The site’s name may be similar — but not quite the same — as the site you intended to visit. If you’re suspicious, don’t type in a username, password or payment information. Leave the site immediately.</p>



<p class="wp-block-paragraph">Other ways to avoid QR code traps are to:</p>



<ul class="wp-block-list"><li>Inspect physical objects for stickers or other signs the original QR codes have been replaced.</li><li>Be careful about scanning any QR code included in an email. Try to verify the authenticity of the email first.</li><li>Use only your phone’s camera to scan codes. You shouldn’t download a QR code app.</li><li>Don’t make payments via QR codes. Go directly to the website by typing in the URL and only use payment processing systems that encrypt your information with SSL or TLS protocols.</li></ul>



<p class="wp-block-paragraph">Businesses can help protect themselves by routinely checking online and physical sites where they’ve placed QR codes for signs of tampering. Include a message with your QR code telling customers that they should notify you if scanning your code takes them to a suspicious site.</p>



<p class="wp-block-paragraph"><strong>Be on guard</strong></p>



<p class="wp-block-paragraph">Not even QR codes are safe from fraud perpetrators. As with all types of fraud, your best defense is a good offense. Look closely at QR codes before you scan them and scrutinize the sites they lead to.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Financial statement fraud: Don’t believe everything you read</title>
		<link>https://www.ce-cpa.com/financial-statement-fraud-dont-believe-everything-you-read/</link>
		
		<dc:creator><![CDATA[Joan Ellenbogen]]></dc:creator>
		<pubDate>Tue, 20 Jun 2023 13:38:16 +0000</pubDate>
				<category><![CDATA[Fraud]]></category>
		<category><![CDATA[financial statement fraud]]></category>
		<category><![CDATA[red flags]]></category>
		<guid isPermaLink="false">https://www.ce-cpa.com/?p=6593</guid>

					<description><![CDATA[Financial statements are central to understanding any business. A public company’s balance sheet, income statement and cash flow statement enable investors, lenders, the media and other stakeholders to value the company, forecast short- and long-term performance, and determine potential credit risk, among other purposes. To ensure analysis of a company is accurate and insightful, financial]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Financial statements are central to understanding any business. A public company’s balance sheet, income statement and cash flow statement enable investors, lenders, the media and other stakeholders to value the company, forecast short- and long-term performance, and determine potential credit risk, among other purposes. To ensure analysis of a company is accurate and insightful, financial statements must be reliable.</p>



<p class="wp-block-paragraph">For this reason, financial statement fraud — the exaggeration or outright fabrication of numbers by insiders, such as owners and executives — is extremely dangerous. It can lead to criminal charges, lawsuits, large financial losses and even the company’s demise. It’s critical that your business do everything possible to prevent this type of fraud.</p>



<p class="wp-block-paragraph"><strong>More common than you might think</strong></p>



<p class="wp-block-paragraph">Financial statement fraud involving large public companies has received considerable press coverage in the past couple of decades. But small and mid-sized businesses aren’t immune to this type of fraud. In fact, such schemes generally are easier to perpetrate in small companies where there’s less oversight.</p>



<p class="wp-block-paragraph">Regardless of size and sector, financial statement fraud is probably more prevalent than you think. A well-received 2023 study by a University of Toronto finance professor finds that 10% of publicly traded companies are committing securities fraud.</p>



<p class="wp-block-paragraph">These schemes can involve everything from overstating revenue and inflating assests, to understating expenses, hiding liabilities and omitting disclosures. According to the Anti-Fraud Collaboration of the Securities and Exchange Commission, the most common enforcement actions involving financial statements feature:</p>



<ul class="wp-block-list"><li>Improper revenue recognition (43%),</li><li>Operational reserves manipulation (24%),</li><li>Inventory misstatement (11%), and</li><li>Loan impairment issues (11%).</li></ul>



<p class="wp-block-paragraph"><strong>6 red flags</strong></p>



<p class="wp-block-paragraph">Although each fraud scheme is as unique as the company it victimizes, financial statement scams share certain characteristics that can tip off fraud experts and eagle-eyed stakeholders. These include:</p>



<p class="wp-block-paragraph"><strong>1. Implausible revenue growth.</strong> A sudden or sustained increase in revenue, especially when the company faces harsh economic conditions, can be a cause for concern and deserves further investigation.</p>



<p class="wp-block-paragraph"><strong>2. Relationship between expenses and revenues.</strong> Expenses typically increase as revenue grows. If a company reports significant revenue growth, its costs should also generally rise, unless there are extenuating circumstances.</p>



<p class="wp-block-paragraph"><strong>3. Inconsistencies and anomalies.</strong> Closer scrutiny may be warranted if financial statements include numbers that are out of line with industry benchmarks, report a trend reversal with no plausible explanation or merely appear inconsistent with historical performance.</p>



<p class="wp-block-paragraph"><strong>4. Related-party transactions.</strong> Transactions with related parties aren’t inherently problematic. There can be good reasons to engage in such transactions. But exercise skepticism if they’re hard to understand or seem to serve no purpose.</p>



<p class="wp-block-paragraph"><strong>5. Changes in accounting methods.</strong> A company may have a legitimate reason for switching accounting methods. But such changes can mask weaknesses because they make it more difficult to compare performance between accounting periods and spot suspicious numbers.</p>



<p class="wp-block-paragraph"><strong>6. Frequent changes in auditors.</strong> If a company changes auditors frequently, it could be a sign of conflict or represent an effort to conceal material financial misstatements.</p>



<p class="wp-block-paragraph"><strong>Reducing risk</strong></p>



<p class="wp-block-paragraph">To minimize the threat of financial statement fraud, always encourage — and model — ethical business practices. This includes communicating clear expectations to executives regarding acceptable behavior. Be sure to empower rank-and-file employees (and other stakeholders) who may witness illicit activities by providing an anonymous reporting hotline.</p>



<p class="wp-block-paragraph">Include a separation of duties and multiple layers of approval and oversight in your internal control policies. And make it nearly impossible for managers to override controls. Education also plays a critical role in preventing financial statement fraud. Put the basics of financial statement fraud and potential warning signs in your company’s training materials.</p>



<p class="wp-block-paragraph"><strong>Personal stake</strong></p>



<p class="wp-block-paragraph">One of the most common reasons executives commit financial statement fraud is because their compensation depends on company performance. For this reason, look for ways to evaluate and compensate managers on several fronts — including on leadership and coaching — not simply on financial performance. Also rely on outside advisors who have no personal stake in your business’s financial results. Contact us for help.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Don’t let tax ID thieves steal your refund — or your peace of mind</title>
		<link>https://www.ce-cpa.com/dont-let-tax-id-thieves-steal-your-refund-or-your-peace-of-mind/</link>
		
		<dc:creator><![CDATA[Joan Ellenbogen]]></dc:creator>
		<pubDate>Tue, 11 Oct 2022 13:23:13 +0000</pubDate>
				<category><![CDATA[Fraud]]></category>
		<category><![CDATA[ID thieves]]></category>
		<category><![CDATA[prevent fraud]]></category>
		<category><![CDATA[report fraud]]></category>
		<category><![CDATA[tax refund]]></category>
		<guid isPermaLink="false">https://www.ce-cpa.com/?p=6453</guid>

					<description><![CDATA[Any form of identity theft can be costly, unsettling, and take months — sometimes years — to fully recover from and repair. But tax-related identity theft can be particularly disturbing because it involves the IRS, about which many people already harbor suspicion and anxiety. Although the IRS has taken significant steps in recent years to]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Any form of identity theft can be costly, unsettling, and take months — sometimes years — to fully recover from and repair. But tax-related identity theft can be particularly disturbing because it involves the IRS, about which many people already harbor suspicion and anxiety. Although the IRS has taken significant steps in recent years to help minimize the occurrence of tax-related identity theft, this type of fraud continues to occur. Here’s how to avoid becoming a victim.</p>



<p class="wp-block-paragraph"><strong>Individuals and businesses are vulnerable</strong></p>



<p class="wp-block-paragraph">If criminals use your information to file an income tax return to claim your refund, the first notification of fraud you receive may be a denial of your return. Tax returns are identified via Social Security numbers (SSNs) and the IRS won’t accept two returns with the same taxpayer identity. Thieves make a point of filing as early as possible to get a jump on the legitimate taxpayer.</p>



<p class="wp-block-paragraph">Tax-related identity theft isn’t limited to personal returns. Business identity theft can occur when a fraud perpetrator uses an Employer Identification Number (EIN) associated with your business to file a return. In either case, if the IRS receives a fraudulent request for a refund, it could issue it to the criminal via direct deposit or check.</p>



<p class="wp-block-paragraph"><strong>4 red flags</strong></p>



<p class="wp-block-paragraph">Often, the IRS is responsible for uncovering tax-related identity fraud when confronted with the problem of two separate returns. But you also should be on the lookout for red flags, for example:</p>



<ol class="wp-block-list" type="1"><li><strong>Your return is rejected.</strong> The most unambiguous indication of tax-related identity theft is when the IRS rejects your return based on a duplicate SSN or EIN. You may learn this immediately if you e-file your return.</li><li><strong>The IRS notifies you.</strong> When the IRS discovers a suspicious tax return, it will contact the affected taxpayer through the mail. If you receive a letter indicating a problem, the IRS may ask you to complete a form to prove your identity. The IRS might also notify you that there’s a new online account in your name or that someone has taken over your existing account.</li><li><strong>You’re asked to pay additional taxes.</strong> To trigger a refund payment, criminals often submit fictitious information to the IRS. If the agency conducts a review and learns that the return associated with your SSN or EIN contains incorrect amounts (usually <em>after</em> a return is processed), it may ask you for more money. The IRS could notify you that you owe additional tax, that it’s withholding a future refund or that it plans to take collection actions.</li><li><strong>IRS records are incorrect.</strong> Criminals often invent sources of income to appear legitimate to the IRS and facilitate a refund. If, for example, the IRS issues an EIN you didn’t request, a criminal may be using your business’s identity to submit fraudulent returns.</li></ol>



<p class="wp-block-paragraph"><strong>How to report fraud</strong></p>



<p class="wp-block-paragraph">If it appears your tax-related identity has been stolen, your need to complete IRS Form 14039, <em>Identity Theft Affidavit</em> as soon as possible. The IRS then will assign your case to one of its employees who’s trained to help identity-theft victims. The employee will determine the scope of the fraud, make any necessary corrections to IRS records and assign to you a personal identification number to prevent criminals from using your SSN or EIN to file returns in the future.</p>



<p class="wp-block-paragraph">You may also need to notify your state’s tax authority. Although less prevalent (because refunds generally are smaller), it’s possible someone could use your SSN or EIN to file a fake state tax return.</p>



<p class="wp-block-paragraph"><strong>Prevent it from happening in the first place</strong></p>



<p class="wp-block-paragraph">Of course, the best defense against tax-related identity theft is offense. File early before a potential scammer can file a fraudulent return in your name. Ensure that your computer is well-protected from viruses, malware and other hacker weapons and watch out for phishing emails. Also take advantage of the ID.me program. After you verify your identity, you can use your ID.me account to securely communicate with the IRS and various other government agencies.</p>



<p class="wp-block-paragraph">If you suspect you’ve become a victim of fraud or have questions about protecting your own or your business’s identity, contact us.</p>



<p class="wp-block-paragraph"><em>© 2022</em></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>5 ways to stop employees from colluding in fraud</title>
		<link>https://www.ce-cpa.com/5-ways-to-stop-employees-from-colluding-in-fraud/</link>
		
		<dc:creator><![CDATA[Victor Dozzi]]></dc:creator>
		<pubDate>Tue, 26 Jul 2022 13:32:00 +0000</pubDate>
				<category><![CDATA[Fraud]]></category>
		<category><![CDATA[Internal controls]]></category>
		<category><![CDATA[preventing fraud]]></category>
		<category><![CDATA[surprise audits]]></category>
		<guid isPermaLink="false">https://www.ce-cpa.com/?p=6397</guid>

					<description><![CDATA[What happens if two or more individuals in your organization collude to commit fraud? According to the Association of Certified Fraud Examiners’ (ACFE’s) 2022 Report to the Nations, fraud losses rise precipitously. The median loss for a scheme involving just one perpetrator is $57,000, but when two or more perpetrators are involved, the median loss]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">What happens if two or more individuals in your organization collude to commit fraud? According to the Association of Certified Fraud Examiners’ (ACFE’s) 2022 Report to the Nations, fraud losses rise precipitously. The median loss for a scheme involving just one perpetrator is $57,000, but when two or more perpetrators are involved, the median loss skyrockets to $145,000. When three or more thieves work together, it soars to $219,000.</p>



<p class="wp-block-paragraph">Unfortunately, collusion schemes are common — they make up approximately 58% of all fraud incidents. So these five steps are recommended:</p>



<ol class="wp-block-list" type="1"><li><strong>Enforce internal controls.</strong> Colluding thieves usually either ignore internal controls or take steps to hide noncompliance. For example, a colluding manager might override controls to allow another employee to commit expense reimbursement or payroll fraud. To prevent such scenarios, ensure controls function as they were designed. If an employee fails to comply with a control, does it raise a red flag? Are controls regularly reviewed for compliance and efficacy?</li><li><strong>Conduct surprise audits.</strong> When employees know unexpected audits are a possibility, they’re generally less likely to attempt fraud. Surprise audits focusing on your company’s vulnerabilities (such as inventory or cash-on-hand) should be conducted by outside fraud experts. Keep the time and place confidential to only those who need to be in the loop. That way, a colluding manager is less likely to be able to warn fellow thieves or falsify an audit’s results.</li><li><strong>Pay attention to relationships.</strong> Obviously, you want employees to get along and even be friends. But do any workplace relationships seem suspicious — for example, does a nonaccounting worker spend an unusual amount of time in an accounting staffer’s office with the door closed? Also scrutinize any employee relationship with a vendor that seems too chummy. When vetting vendors, ensure their personal information, such as addresses, don’t match those of any employees.</li><li><strong>Monitor electronic communications.</strong> In partnership with your legal counsel, ensure you have the right to monitor employee communications, such as email or instant messages shared on your network. Investigate employees if their communications lapse into unintelligible code, appear unrelated to their primary roles or appear to violate your company’s policies and procedures.</li><li><strong>Implement a job rotation program.</strong> When employees rotate positions, it’s harder for fraud perpetrators to hide criminal activity. If someone is resistant to participating in a job rotation plan, you might want to look closer at that employee’s work for red flags. Along the same lines, require everyone to take vacations. Employees who continually avoid time off or only want certain individuals to cover their work while they’re out generally deserve attention.</li></ol>



<p class="wp-block-paragraph">You can further impede criminally minded employees from working together by making all workers sign a code of conduct and by modeling ethical conduct. If you need help strengthening controls or suspect employees are colluding in fraud, contact us.</p>



<p class="wp-block-paragraph"><em>© 2022</em></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Partially empty offices can be fertile ground for theft</title>
		<link>https://www.ce-cpa.com/partially-empty-offices-can-be-fertile-ground-for-theft/</link>
		
		<dc:creator><![CDATA[Joan Ellenbogen]]></dc:creator>
		<pubDate>Thu, 07 Jul 2022 15:17:34 +0000</pubDate>
				<category><![CDATA[Fraud]]></category>
		<category><![CDATA[creeper scheme]]></category>
		<category><![CDATA[protecting your business & property]]></category>
		<guid isPermaLink="false">https://www.ce-cpa.com/?p=6387</guid>

					<description><![CDATA[Half-empty offices due to the pandemic may provide an advantage to “creepers.” These thieves typically gain access to a company’s physical facilities via unlocked doors and social engineering tactics. Once in, they steal proprietary information, inventory, computers and personal property. You can prevent theft by installing security cameras, keeping doors locked at all times, issuing]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Half-empty offices due to the pandemic may provide an advantage to “creepers.” These thieves typically gain access to a company’s physical facilities via unlocked doors and social engineering tactics. Once in, they steal proprietary information, inventory, computers and personal property. You can prevent theft by installing security cameras, keeping doors locked at all times, issuing photo badges to employees and educating workers about the risks. In particular, warn employees not to leave purses, wallets, phones and other valuables unsecured on or in their desks. Contact us for help preventing fraud and other theft.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Don’t lose your business’s IT assets</title>
		<link>https://www.ce-cpa.com/dont-lose-your-businesss-it-assets/</link>
		
		<dc:creator><![CDATA[Victor Dozzi]]></dc:creator>
		<pubDate>Wed, 09 Mar 2022 14:59:20 +0000</pubDate>
				<category><![CDATA[Fraud]]></category>
		<category><![CDATA[policies & procedures]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[track IT assets]]></category>
		<guid isPermaLink="false">https://www.ce-cpa.com/?p=6340</guid>

					<description><![CDATA[Keeping track of every IT asset — particularly as remote work has become common — is essential if your company wants to limit financial losses and fraud risk. According to some estimates, most remote employees use at least two employer-assigned devices, and a smaller percentage use three or more. In general, the more devices in]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Keeping track of every IT asset — particularly as remote work has become common — is essential if your company wants to limit financial losses and fraud risk. According to some estimates, most remote employees use at least two employer-assigned devices, and a smaller percentage use three or more. In general, the more devices in use, the greater the potential for loss or theft.</p>



<p class="wp-block-paragraph">But you can keep tabs on hardware such as desktops, laptops, mobile phones, tablets and the software you’ve purchased or developed to operate them, with IT asset tracking. Following is a three-step guide.</p>



<p class="wp-block-paragraph"><strong>1. List your assets.</strong> The first step involves developing a list of the IT assets you need to track. Although third-party software can help simplify this task (especially if the software incorporates physical barcoding to identify and track physical assets), cost may outweigh the benefits for small businesses. In those cases, a simple spreadsheet can suffice. Regardless of the approach you follow, the goal is to identify every asset and ensure the tracking database or document is kept up to date.</p>



<p class="wp-block-paragraph"><strong>2. Develop policies and procedures.</strong> Your company must have tracking mechanisms at every stage of the process — from ordering, receiving and assigning to retiring IT assets. When writing your policies, ask such questions as:</p>



<ul class="wp-block-list"><li>Who’s authorized to purchase hardware or software?</li><li>Is there a process to assign a unique tracking number to each asset?</li><li>How should employees report possible theft or loss?</li><li>What’s the procedure for reclaiming IT assets from employees leaving the company?</li><li>Who’s allowed to access and update tracking records?&nbsp;</li></ul>



<p class="wp-block-paragraph"><strong>3. Ensure compliance.</strong> To help ensure your IT asset tracking process works as designed, audit it periodically. The audit should focus on the accuracy of the tracking database. It should also document and verify that devices assigned to employees remain in their possession. Depending on the volume of hardware and software your company tracks, it may make sense to randomly select assets for scrutiny. If you find that assets are missing, investigate the incidents thoroughly.</p>



<p class="wp-block-paragraph">These steps are important because lost or stolen IT assets are expensive to replace. Also, they can expose your company’s data, including customer information, to unauthorized third parties. In extreme circumstances, a missing device may enable a thief to gain access to your company’s IT network. Contact us for more information about preventing fraud and theft.<em>© 2022</em></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>To prove fraud, you need to preserve evidence</title>
		<link>https://www.ce-cpa.com/to-prove-fraud-you-need-to-preserve-evidence/</link>
		
		<dc:creator><![CDATA[Victor Dozzi]]></dc:creator>
		<pubDate>Thu, 10 Feb 2022 14:15:13 +0000</pubDate>
				<category><![CDATA[Fraud]]></category>
		<category><![CDATA[fraud mitigation]]></category>
		<category><![CDATA[fraud prevention]]></category>
		<guid isPermaLink="false">https://www.ce-cpa.com/?p=6313</guid>

					<description><![CDATA[Prevention is the heart of any fraud mitigation program. But sometimes internal controls fail and unethical employees steal. If you suspect fraud, act quickly to preserve evidence. It’s usually best to hand an investigation over to experts such as your attorney and a forensic accountant. But before they arrive on the scene, secure paper documents]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Prevention is the heart of any fraud mitigation program. But sometimes internal controls fail and unethical employees steal. If you suspect fraud, act quickly to preserve evidence. It’s usually best to hand an investigation over to experts such as your attorney and a forensic accountant. But before they arrive on the scene, secure paper documents related to the possible fraud. Digital evidence requires more expertise. So provide training to IT staffers before the need for a fraud investigation occurs. At the very least, they should know to stop routine data destruction immediately. Contact us for help investigating fraud.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Typosquatters are leading innocent victims astray</title>
		<link>https://www.ce-cpa.com/typosquatters-are-leading-innocent-victims-astray/</link>
		
		<dc:creator><![CDATA[Joan Ellenbogen]]></dc:creator>
		<pubDate>Wed, 01 Dec 2021 15:05:20 +0000</pubDate>
				<category><![CDATA[Fraud]]></category>
		<category><![CDATA[cybersquatting]]></category>
		<category><![CDATA[typosquatters]]></category>
		<category><![CDATA[Uniform Domain-Name Dispute-Resolution Policy]]></category>
		<guid isPermaLink="false">https://www.ce-cpa.com/?p=6237</guid>

					<description><![CDATA[Typosquatting takes advantage of an inclination among internet users known as “fat fingers” — a tendency to hit the wrong keys and enter misspelled trademarks or brands. Like phishing, typosquatting is a type of social engineering that tricks people into visiting websites they didn’t intend to visit. These schemes can harm both consumers and the]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Typosquatting takes advantage of an inclination among internet users known as “fat fingers” — a tendency to hit the wrong keys and enter misspelled trademarks or brands. Like phishing, typosquatting is a type of social engineering that tricks people into visiting websites they didn’t intend to visit. These schemes can harm both consumers and the businesses whose names are abused.</p>



<p class="wp-block-paragraph"><strong>Connection to cybersquatting</strong></p>



<p class="wp-block-paragraph">Typosquatting is connected to cybersquatting, where someone registers a site’s domain name that includes a trademark and then tries to profit by selling that name to the trademark owner. With typosquatting, fraudsters register URLs that are common misspellings of company and brand names. For example, a bad actor might register landswnd.com and lnadsend.com. Then, when users try to visit the site of retailer Lands’ End but mistype the name, they may end up on a fake site that looks like the real one. Other human errors, such as typing the wrong URL extension (.com instead of .org) or omitting punctuation marks such as hyphens, can also work to typosquatters’ advantage.</p>



<p class="wp-block-paragraph">According to Palo Alto Networks’ Unit 42 research, the most commonly targeted sites include Netflix, Microsoft, Facebook and PayPal. But any business can be vulnerable to this type of fraud.</p>



<p class="wp-block-paragraph"><strong>Valuable information&nbsp;</strong></p>



<p class="wp-block-paragraph">The goal often is to divert users away from competitors or draw traffic to their own sites (often pornography or dating sites). The greatest risk for users is that they’ll be diverted to a site where they’re induced to enter login information or download malware. Resulting identity theft can make big money for fraud perpetrators.</p>



<p class="wp-block-paragraph">Typosquatting can also be used for corporate espionage. In one case, a law firm sued a programmer who had obtained a domain name similar to its own, except for a minor typo. The law firm alleged that the defendant had used his doppelgänger domain name to create fake email accounts and intercept email sent to the firm.</p>



<p class="wp-block-paragraph"><strong>Protect online assets</strong></p>



<p class="wp-block-paragraph">To protect your business from typosquatting schemes, routinely check mistyped versions of your URL. If you find a questionable site, try to contact the domain name owner. The owner may have an innocent explanation. But if you believe the owner has malicious intent, you may want to file a complaint using the Uniform Domain-Name Dispute-Resolution Policy (UDRP) or pursue litigation.</p>



<p class="wp-block-paragraph"><em>© 2021</em></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
