Advisory

Risk Warning Regarding the Increased Use of Compromised E-mail Accounts to Commit Fraud (2015-03-11)

Guernsey Financial Services Commission (GFSC) · Guernsey

Issued 2015-03-11

Current version last checked: 2026-07-12

Summary

This is a risk warning from the Guernsey Financial Services Commission (GFSC) alerting financial institutions to a rise in fraud attempts carried out via compromised or spoofed customer e-mail accounts, where fraudsters send instructions purporting to be from genuine customers to divert funds to accounts in other jurisdictions.

  • Verify by phone: Businesses should verify e-mail instructions (whether changing customer details or transferring funds) via a telephone call to a person authorised to give instructions.
  • Check e-mail addresses: Any e-mail address used for instructions should be validated against existing records, with further enquiries if it is unfamiliar or previously unused.
  • Scrutinise unusual payment requests: Extra enquiry and verification should be applied to payment requests to jurisdictions not previously used by the customer, inconsistent with expected activity, or associated with heightened corruption, bribery or weak AML/CFT risk.
  • Escalate uncertainty and suspicion: Uncertain cases should be raised with senior management, and suspicious cases reported to the MLRO or Nominated Officer.
  • Report to authorities: Businesses are encouraged to notify the appropriate authorities, including the FIU, if they identify or suspect such fraud attempts.

The warning does not create new legal rules but sets out risk-management steps the Commission expects businesses to consider in light of the fraud pattern identified, drawing on liaison with the Financial Intelligence Unit (FIU).

Key obligations

  • Verify e-mail instructions to change customer details or transfer funds via a telephone call to an authorised party
  • Validate e-mail addresses used for instructions against existing records and make further enquiries if unfamiliar
  • Apply additional enquiry and verification to payment requests involving unfamiliar jurisdictions, inconsistent activity, or heightened corruption/bribery/AML-CFT risk
  • Escalate uncertain instructions to senior management and suspicious cases to the MLRO or Nominated Officer
  • Notify the FIU or other appropriate authorities of suspected e-mail fraud attempts

Applies to

financial institutions, businesses (banking, fiduciary and other licensed sectors)

Topics

Version history

2026-07-12

source file (current)