This course is designed for organisations operating in finance, trading and banking where a single mistaken click can become a material financial event. You’ll learn how modern phishing works across email, SMS (smishing), WhatsApp, voice calls (vishing), and document workflows. We focus on the threats that reliably hit finance teams: invoice and beneficiary change requests, “safe account” pressure tactics, brand impersonation, look‑alike domains, and spoofed communication that appears legitimate.
You’ll leave with:
A quick orientation to the course, the reality of finance‑sector targeting, and the one habit that prevents most losses.
Understand the three outcomes criminals chase (money, access, and authority), the channels they use (email, SMS/WhatsApp, voice), and the finance processes they exploit.
Learn the typical phishing “sequence” (hook → action → outcome), the most common lures used against finance teams, and the simple checks that stop most attacks.
Learn how attackers fake trust using spoofed sender names, look‑alike domains, and deceptive links, and how to defeat them with three quick checks.
A real-world case study showing how a legitimate document-signing platform can be abused to deliver phishing, and exactly what to do when you receive an unexpected signing request.
Learn the red flags that matter most in finance: beneficiary changes, invoice redirection, thread hijacking, CEO/Director impersonation, and “process bypass” pressure — plus the controls that reliably stop losses.
Understand what smishing is, why it works so well on mobile, and learn a simple “Stop → Switch channel → Verify” habit you can apply before you click, reply, or call back.
Learn the most common smishing storylines used against banking and finance staff, and practise the correct response using short decision drills.
Learn how smishing can move from “just a message” to device compromise (malware/trojans), what that means for banking and corporate accounts, and the safest immediate actions if you clicked, replied, or installed anything.
Learn the most common “payment diversion” patterns that hit finance teams: supplier impersonation, beneficiary-change requests, and invoice redirection. You’ll practise a repeatable verification process that prevents losses before money leaves the account.
Learn how fraudsters combine phone calls (vishing), spoofed caller IDs, and urgency to trick finance staff into moving money to a “safe/secure account”. You’ll learn exactly what to do and what never to do.
Turn “be careful” into a repeatable process. This lesson teaches the core controls that stop BEC-style invoice fraud: maker/checker approvals, call-back validation using trusted numbers, and a simple verification record you can use for audit and accountability.
Learn how attackers hijack invoice conversations (thread hijacking), resend “updated” invoices, and use tiny changes (domains, PDFs, bank details) to divert payments. You’ll get a simple invoice‑review checklist and practise spotting the red flags.
Learn the “never rules” used by major banks and insurers to protect clients: what they will never ask for, why criminals ask for it, and the safest immediate response when you’re unsure.
When a suspicious message arrives, speed and clarity matter. Learn a simple reporting checklist: what evidence to capture, how to escalate safely, and which official reporting channels to use.
By the end, learners will be able to: