Skip to content
Amrani Academy
Fraud AwarenessLesson 7 of 13

2. Common frauds against organisations

Refund fraud and impersonation

Refund fraud

Refund fraud abuses the process that gives money back. It comes from both directions.

From outside, customers or fraudsters posing as customers claim refunds they are not entitled to: goods falsely reported as never delivered, items used and then returned as faulty, or refund requests for purchases that never happened. Organised versions of this are run at scale against retailers.

From inside, staff with access to refund functions can process refunds to their own cards or accounts, or collude with outsiders to refund genuine-looking transactions. Because a refund looks like an ordinary reversal, this can hide in plain sight in busy transaction data. Sensible controls include limiting who can process refunds, requiring approval above a threshold, and regularly reviewing refunds by employee, by card, and by destination account, looking for patterns.

Supplier impersonation

You have already seen supplier impersonation in the context of mandate fraud. It goes wider than bank details. Fraudsters impersonate suppliers to obtain payments, but also to harvest information: a plausible email asking accounts payable to confirm outstanding invoices, contact names, or payment schedules is often reconnaissance for a later attack. Be as careful with information about payments as with payments themselves.

Customer impersonation

Impersonation also runs the other way. Fraudsters pose as customers, sometimes using stolen identities of real businesses, to obtain goods on credit accounts with no intention of paying, or to place large orders for delivery to addresses that turn out to be short-term rentals. A new customer who wants a large order, quickly, on credit, with delivery to an address that doesn't match their stated premises, deserves checks before goods leave the building.

The common thread

Almost everything in this section is social engineering: exploiting trust, routine, and time pressure rather than breaking technical defences. The attacker's real target is not your IT system. It is a busy person making a reasonable-looking decision without verification. That is worth remembering, because it means every member of staff is part of the defence.

Check your understanding

A short, optional 5-question quiz on this section. It doesn't block your progress, it's just a quick self-check.

Try the section quiz →
Course contents