Building a Digital Defense Against Business Email Compromise Involving Gift Card Fraud

Scammers know businesses are more likely to reward employees or thank customers during this time of year. ‘Tis the season, after all, for presents, incentives, and end-of-year bonuses. That combined with an upward spike in business email compromise scams make companies particularly vulnerable to this kind of fraud.

Over the past year and a half—and especially in the last few months—the FBI’s Internet Crime Complaint Center,, has seen a huge increase in the number of businesses that are getting hit with this kind of fraud. From January 2017 to this fall, the adjusted loss topped $1 million.

The scam starts with a spoofed email or text from a person of authority, such as a CEO or HR director, telling an employee to purchase gift cards for the executive to give away or to use to purchase items, say, for a Christmas party. The employee is told to send the gift card information, including the number and PIN, back to the “boss”—really the fraudster—who then can cash out the value before you know there is a problem.

There are ways to prevent these types of scams:

  • Keep an eye out for email addresses that look similar to, but not exactly the same as the ones used by your work supervisors or peers.
  • Be wary of requests to buy multiple gift cards, even if the request seems ordinary.
  • Watch out for grammatical errors or odd phrasing.
  • Notice language that tries to pressure you to purchase the cards quickly.
  • Finally, be wary if the sender asks you to send the gift card number and PIN back to him.

In any case, requests for gift card purchases or wire transfers should be highly scrutinized. Make sure your business uses two-factor authentication protocols or at least follow up a phone call to confirm any transfer of funds.

IC3 says that while this kind of fraud can happen to any company, there are a variety of sectors most at risk. They include the real estate, legal, medical, and distribution and supply parts of our economy as well as religious organizations.

If you have been victimized by this or any cyber fraud, be sure to report it to the FBI’s Internet Crime Complaint Center at or call your local FBI office.

(Visited 8 times, 1 visits today)

The Government Technology & Services Coalition's Homeland Security Today (HSToday) is the premier news and information resource for the homeland security community, dedicated to elevating the discussions and insights that can support a safe and secure nation. A non-profit magazine and media platform, HSToday provides readers with the whole story, placing facts and comments in context to inform debate and drive realistic solutions to some of the nation’s most vexing security challenges.

Leave a Reply

Latest from Cybersecurity

Go to Top