Fraud19 Keynote: Context and a Current Fraud-Prevention Guide

A familiar sender can still carry fraudulent payment instructions. Explore Fraud19 keynote context and practical steps to verify transactions, prevent impersonation, and protect funds.

A familiar vendor sends new banking instructions. An executive calls with an urgent payment request. An email arrives inside an existing conversation, complete with the right names and a plausible explanation. The challenge is not simply spotting something suspicious. It is ensuring that a convincing request cannot bypass a reliable verification process.

Looking for Bart McDonough’s Fraud19 keynote? His speaking page lists “Fraud19 Keynote” under “In Action.” That listing establishes the context for this address, but the original page is unavailable. The available information does not establish the presentation’s exact event, date, recording availability, or contents.

This is a newly written replacement article—not a transcript, recap, or reconstruction. It provides current, independently sourced guidance on preventing payment fraud, strengthening authentication, managing AI-enabled impersonation, and responding when money has already moved.

Start With the Transaction, Not Just the Message

Business email compromise, or BEC, uses apparently legitimate communications to deceive people into transferring money or sharing sensitive information. The FBI’s BEC guidance describes schemes involving fraudulent vendor-payment requests and altered real-estate wire instructions. Attackers may impersonate someone trusted or operate through a compromised account.

That distinction matters. Checking the sender’s address is useful, but a message from a genuine account can still carry fraudulent instructions. Professional language and familiar branding do not authenticate a transaction.

Recognizing the sender and verifying the transaction are different tasks. A familiar message should never replace an independent check of changed payment instructions.

Consider an illustrative example: a supplier emails that its bank account has changed just before a scheduled payment. The invoice amount is correct, and the signature looks familiar. The safe response is not to decide whether the email “feels real.” It is to confirm the change through an established contact channel before releasing funds.

Build Verification Into the Payment Workflow

Independently confirm changed instructions

The FBI recommends verifying payment requests and changes to account numbers or payment procedures independently. For organizations, that advice should become a required process rather than a reminder to “be careful.”

  • Pause the transaction when banking details, payment destinations, or established procedures change.
  • Use trusted contact information already on file or obtained independently—not a phone number supplied in the questionable message.
  • Confirm the specific change, including the intended recipient and destination account.
  • Record the verification, including who performed it, which channel was used, and what was confirmed.

Maintain trusted contact details separately from incoming payment instructions, and establish a controlled process for updating them. Otherwise, an attacker could replace both the banking information and the number employees use to verify it.

The tradeoff is friction: legitimate payments may take longer. Reduce that burden with clear ownership, current contact records, and an escalation route. Urgency should trigger escalation—not permission to skip verification.

Separate verification from authorization

Verification asks whether a request is authentic. Approval asks whether the organization should authorize it. Those are separate decisions.

The Office of the Comptroller of the Currency’s fraud-risk guidance identifies dual controls and segregation of duties as preventive measures for banks. Other organizations can adapt these principles without treating bank-specific supervisory guidance as a universal legal requirement.

A practical workflow assigns one person to record a requested change, another to verify it, and an authorized approver to review the evidence before payment. Avoid letting one person change vendor details, validate the change, and release the funds without additional review.

Small organizations may not have enough staff for complete separation. Document that limitation and consider an owner or manager review for higher-risk transactions. A deliberate compensating control is better than an unacknowledged gap.

Strengthen Accounts Without Overtrusting Authentication

Payment controls and account security address different parts of the problem. Better authentication can reduce account compromise, but it cannot establish that every request from an authenticated user is legitimate.

CISA recommends aiming for phishing-resistant multifactor authentication. FIDO/WebAuthn-based approaches are designed to resist phishing in ways that manually entered codes do not.

A practical rollout should prioritize email, administrator accounts, and systems involved in financial workflows. Identify supported methods, test enrollment, and plan backup access and account recovery before enforcing a new requirement. Follow each provider’s current configuration guidance.

The tradeoffs include compatibility, deployment effort, and support needs. Recovery deserves particular attention: users need a workable way to regain access, but recovery must not become an easy bypass around stronger authentication.

Keep payment verification in place after upgrading MFA. A fraudster may manipulate a legitimate employee, impersonate someone outside the organization, or exploit a process weakness without compromising the payer’s account.

Keep AI-Enabled Impersonation Inside the Same Controls

The FTC warns that scammers can use AI to imitate a loved one’s voice and pressure people into emergency payments. Its advice is to contact the supposed caller using a number already known to be correct, or check with another trusted person.

The same verification principle is useful in business. An unexpected voice request—even one that sounds like a senior executive—should not override the payment workflow.

For example, suppose an employee receives a call that appears to come from the CEO demanding an immediate transfer. The employee should end the incoming conversation and initiate verification through an established channel. The task is to authenticate the request, not diagnose whether the audio is synthetic.

This approach has a practical advantage: employees do not need to become deepfake specialists. They need a repeatable process and explicit permission to challenge urgent requests, regardless of the apparent caller’s seniority.

Assess Fraud Risk Before Buying Another Tool

Technology can support prevention, but buying a product before understanding the exposed workflow can leave the central weakness untouched. AGA’s fraud-mitigation resources recommend assessing relevant risks, ownership, likelihood, financial impact, and controls.

Start with specific scenarios: diverted supplier payments, unauthorized payroll changes, fraudulent refunds, or altered wire instructions. For each, record:

  • Exposure: Where could the fraud occur, and what would be affected?
  • Ownership: Which role is accountable for the risk?
  • Prevention: What stops an unauthorized action?
  • Detection: What review, reconciliation, alert, or reporting channel would reveal it?
  • Improvement: What needs to change, who will act, and by when?

Evaluate tools against those needs. The OCC advises banks to consider fraud-prevention tools in relation to cost, value, complexity, and risk profile—a useful purchasing principle beyond banking, though not a universal regulatory mandate.

Test whether the controls actually work

A written policy is not evidence of consistent execution. Review a sample of payment changes: was independent verification documented, did approval happen before release, and were exceptions handled properly?

GAO’s guidance on evaluating antifraud activities emphasizes evaluating effectiveness and adapting activities, considering more than financial returns and tailoring evaluation to available capacity.

Useful measures include verification completion, procedural overrides, reporting speed, corrective-action closure, and staff time. Use the results to improve the workflow—not merely repeat the training.

Organizations seeking a broader framework can consult GAO’s Green Book. The 2025 edition became effective for federal agencies beginning with fiscal year 2026; it is not automatically binding on every private business.

If Money Has Already Been Sent, Act Immediately

Contact your financial institution immediately. The FBI advises asking it to contact the institution that received the transfer. Report suspected BEC to the FBI’s Internet Crime Complaint Center using the reporting route linked from its BEC guidance. Do not wait for a completed internal investigation before contacting the bank.

Activate your incident-response process and preserve payment details, relevant communications, and the known timeline. Coordinate account containment with the security team if compromise is suspected. These actions support response; they do not guarantee recovery.

For consumer scams, the FTC guidance linked above provides a separate fraud-reporting route.

A Practical Fraud-Prevention Checklist

  • Independently verify changed payment instructions.
  • Maintain trusted contact details outside incoming requests.
  • Record verification evidence before approval.
  • Separate payment changes, verification, and authorization where feasible.
  • Document compensating controls for small teams.
  • Assess phishing-resistant MFA and secure recovery options.
  • Keep urgent voice requests within normal verification procedures.
  • Assign owners to specific fraud risks.
  • Test controls and track corrective actions.
  • Keep bank and incident-response contacts readily available.

Make Verification a Business Habit

The verified Fraud19 keynote listing establishes this page’s context, not the contents of the unavailable presentation. The guidance here stands independently: reduce reliance on appearances and make sensitive actions depend on verifiable evidence.

Start with one workflow this week. Review how your organization changes supplier banking details, test whether verification survives an urgent request, and close the gaps you find. Effective fraud prevention comes from making the safe process clear, practical, and difficult to bypass.

Browse all insights · Contact Bart McDonough