Sunshine Coast and Brisbane Accountants - Clarke McEwan Accountants and Business Advisorrs
Sunshine Coast and Brisbane Accountants - Clarke McEwan Accountants and Business Advisorrs

Another year Another scam

Clarke McEwan Accountants



While data driven crime is more sophisticated and difficult to address than ever, human error and judgement remains one of the major problems.

The latest data breach report from the Office of the Australian Information Commissioner (OAIC) is surprising for the simplicity of the problems - 37% of data beaches resulted from human error not malicious attack. In over 20% of reported cases, personal information was simply sent to the wrong recipient. Another 6% of complaints were attributed to system faults.

Since 22 February 2018, businesses covered by the Privacy Act need to report unauthorised access to or disclosure of personal information or loss of personal information that your business holds under the Data Breach Scheme. The rules impact organisations with an annual turnover of $3 million or more, businesses 'related to' another business covered by the Privacy Act , or if your business, regardless of size, deals with health records (including gyms, child care centres, natural health providers, etc.,), is a credit provider, or holds Tax File Number information (see the list ).

Organisations are required to take all reasonable steps to prevent a breach occurring, put in place the systems and procedures to identify and assess a breach, and issue a notification if a breach is likely to cause 'serious harm'.

What the statistics from the OAIC demonstrate is that procedural integrity in your business is paramount – train your team to not only be wary of scams but ingrain best practice for the day to day management of personal data. Privacy protection is not just an 'IT' issue.

While not the only factor, protecting your systems remains a priority as Marriot Hotels discovered when the Starwood guest reservation database was breached.

According to the latest announcement, up to 383 million records were potentially impacted. Of those, there were approximately 5.25 million unique unencrypted passport numbers. On 30 November 2018, the company announced that unauthorised access to the database may have been occurring since 2014.

Similarly, Cathay Pacific released a statement notifying that up to 9.4 million members of their Marco Polo Club, Asia Miles or a Registered Account holder have potentially had their data breached including passenger name; nationality; date of birth; phone number; email; address; passport number; identity card number; frequent flyer programme membership number; customer service remarks and historical travel information.

Remember, hackers can gain access to your business's data simply by a staff member clicking on a link.

While not impacting personal data, according to the ScamWatch , a common scam is where hackers gain access to a business' email accounts, or 'spoof' a business' email so their emails appear to come from the company. The hacker then sends emails to customers claiming that the business's banking details have changed and that future invoices should be paid to a new account. These emails look legitimate as they come from one of the business's official email accounts. Payments then start to flow into the hacker's account. The average loss from these scams is around $30,000.

A variation is where the hacker sends an email internally to a business' accounts team, pretending to be the CEO, asking for funds to be urgently transferred to an off-shore account. Hackers can also request salary or rental payments be directed to a new account.

In 2018, these scams cost Australian business $30 million in 2018.

Simple measures you can take:

· Have strong and enforced processes in place for the management of personal client information.

· Strong authorising procedures for payments – two-step authority.

· Change passwords often and use two-step authentication where available.

· If a client's bank details have changed, phone them and check the details.

· If contacted by the ATO, contact us to verify the information if you are concerned.

· Train your team on cyber security:

o Check requests for payments that arrive electronically from other team members and management.

o Check email addresses are legitimate – look for slight variations.

o Be suspicious of poorly written emails.

o Don't click on links from email – always use your account with the supplier or Government department to check details.

Editor's note:
Clarke McEwan utilises strong security measures to protect data. We encourage our clients and associates to use the 2StepAuthentication system when accessing organisations records. This step is part of our commitment to support tighter security requirements and recommendations from the Australian Tax Office. 2SA has been adopted by many of the software providers that we and our clients utilise. For instance, it is now compulsory to use two-step authentication (2SA) when logging into a Xero account. Xero will be changing the passwords for all users from 12 February 2019, so in order not to be delayed the next time you want access software or banking details is it imperative that you set up 2SA when it is offered to you. If you need more information, contact us. #clarkemcewan #2SA #cybersecurity #authentication

2024–25 Federal Budget Highlights
By Clarke McEwan 15 May, 2024
The Federal Treasurer, Dr Jim Chalmers, handed down the 2024–25 Federal Budget at 7:30 pm (AEST) on 14 May 2024. Described as a “responsible Budget that helps people under pressure today”, the Treasurer has forecast a second consecutive surplus of $9.3 billion. The main priorities of the government, as reflected in the Budget, are helping with the cost of living, building more housing, investing in skills and education,strengthening Medicare and responsible economic management to help fight inflation.
Company money crackdown
By Clarke McEwan 15 May, 2024
The ATO is cracking down on business owners who take money or use company resources for themselves.
Accessing money in your SMSF
By Clarke McEwan 15 May, 2024
The ATO has made a call to professional accountants to help identify and manage illegal early access to superannuation by members of self-managed superannuation funds (SMSFs). In general, access to your super is only possible if: You retire and turn 60; or You turn 65 (regardless of whether you’re working).
Should you be the ‘bank of Mum & Dad’?
By Clarke McEwan 15 May, 2024
So, should you help your children buy a home? If they can, many parents would prefer to assist their children when they need it most, rather than benefiting from an inheritance later in life. However, it’s essential that any support does not risk your financial security, and that means looking at what support you can afford to provide.
Do your kids really want to take over your business?
By Clarke McEwan 15 May, 2024
Generational succession - handing your business across to your kids or family - sounds simple enough but, many families end up in a dispute right at the point when the parents, business, and children are most vulnerable. It’s important that generational succession is managed as closely and diligently as if you were selling your business to a stranger to avoid misunderstandings and disputes.
Your upcoming tax calendar for May and June
By Clarke McEwan 06 May, 2024
As we move into the business end of tax planning for 2024, here is a list of key tax dates for May and June 2024. Be aware of your upcoming tax obligations here.
More Posts
Share by: