5 fraud schemes targeting businesses right now — and how to guard against them

April 2026

<p>5 fraud schemes targeting businesses right now — and how to guard against them</p>

Business fraud is on the rise, and five types of schemes are trending. As fraud continues to evolve and become increasingly sophisticated, it’s important to recognize the most pervasive types. To help protect your business and to help you and your employees identify these schemes, read about these five common scenarios, as well as fraud prevention tips.

5 scenarios to beware of

Scenario #1, Quishing or QR Code Fraud

A fraudster sends phishing emails to employees of a mid-sized company. Masquerading as originating from the IT department, the emails instruct employees to scan a QR code to update their security settings. Several employees comply and are lead to a phishing site, where they enter their login credentials and other sensitive information. The fraudster uses this data to gain unauthorized access to the company’s internal systems and customer databases, resulting in a significant data breach and potential financial losses.

Scenario #2, Double-Sided Spoofing

A fraudster poses as a financial institution and contacts a business user to extract login credentials using social engineering. Using this information, the fraudster then contacts the business’s financial institution, impersonates the business user, and attempts to reset the business user’s online banking login credentials. The fraudster gains access and submits ACH or wire transfers out of the accounts they now control.

Scenario #3, SIM Swapping

A fraudster gathers personal information to convincingly impersonate a business user’s cellular account. Then, they contact the cellular provider’s customer service, claiming the SIM card is lost or damaged. The provider transfers the phone number to the fraudster’s SIM card. The fraudster may also exploit weaknesses in the provider's security procedures or use insider assistance to facilitate the transfer. Once the transfer is complete, the fraudster intercepts text messages and calls containing sensitive information, which they can use to compromise the business's online accounts.

Scenario #4, Business Email Compromise (BEC)

A fraudster sends an email to a business and poses as a merchant the business works with. The email contains new banking info or payment change instructions, such as a new bank or bank account number to remit a payment request. The business then sends the funds, thinking it was their legitimate merchant.

Scenario #5, Bank Impersonation

A fraudster contacts a business by phone call, email, or text message pretending to be a bank employee. They may claim there’s been fraudulent activity on the business’s account or that the account needs to be secured and that they need to verify the account information or other personal information. Once fraudsters have that information, they are positioned to swiftly drain the business bank account and engage in other malicious activities.

Protect your business from fraud: Essential practices

1. Train and monitor

Train employees on fraud tactics and how to report suspicious activity, and monitor accounts daily for unauthorized transactions. Conduct audits periodically to verify compliance with security policies.

2. Secure access and authentication

Verify employees use secure connections, and never public Wi-Fi, for sensitive transactions. Require strong passwords with 15+ characters with mixed case, numbers, and symbols. For any monetary transactions, require multifactor authentication (MFA).

3. Protect devices and data

Implement strict security policies for accessing and storing sensitive data. Install and regularly update antivirus and antimalware software on all devices. Shred all sensitive documents before disposal.

4. Verify before you trust

Be skeptical of communications that create false urgency. Never share sensitive information by email, text, or phone unless you initiated the contact. Don’t click links or download software from unknown sources. And, to verify information, call your bank using known contact information, not a number provided by an unverified source.

What to do if your business becomes a victim of fraud

If you suspect your business has been exposed to fraud, immediately contact any financial institution where you maintain an account. If you are a KeyBank client, contact KeyBank’s Fraud Client Service Center immediately at 1-800-433-0124 or dial 711 for TTY/TRS.

We’re committed to arming you with the latest information on cybercrime and payments fraud. For information about KeyBank’s Core Fraud Solutions, connect with your Payments Advisor or Relationship Manager. To learn more, visit key.com/cybersecurity.

This material is for general educational purposes only. KeyBank makes no representation or warranty, express or implied, as to the accuracy, reliability, or completeness of such information and disclaims any and all liability for any direct, indirect, incidental, consequential, or other losses arising from or related to its use. Nothing herein constitutes an offer, solicitation, recommendation, or advice (including financial, accounting, legal, or tax advice). Consult appropriate professionals for your specific circumstances.

Connect With Us

Find an Expert