Course track
Email Compromise and Payment Fraud
For anyone who can move money: vendor master-file fraud, payroll diversion, escrow/wire fraud, hidden mailbox rules, and building a payment-verification culture.
Who takes this: Finance, accounts payable, HR/payroll, and legal/escrow-adjacent staff
PCIFTCISOSOC2NISTNDPA
| Module | Length | What staff learn | Maps to |
|---|---|---|---|
| Vendor Master File Fraud | 6 min | Verify any vendor bank-detail change by phone before updating payment records. | PCI, FTC, ISO |
| Payroll Diversion Fraud | 5 min | Verify any direct deposit change verbally before processing it. | PCI, FTC, ISO |
| Real Estate and Escrow Wire Fraud | 6 min | Verify new wiring instructions by phone using a number from an original signed document. | FTC, ISO |
| Mailbox Rules and Hidden Forwarding | 5 min | Recognize signs of a compromised mailbox hiding behind quiet mail rules. | ISO, SOC2 |
| How Business Email Compromise Actually Works | 5 min | Explain the typical stages of a business email compromise attack so you can spot warning signs before money moves. | ISO, NIST |
| CEO and Executive Impersonation Fraud | 5 min | Identify the signs of executive impersonation fraud and apply a safe verification habit before acting on any high-authority payment request. | ISO, NIST, FTC |
| Supplier and Invoice Fraud | 5 min | Recognize when a supplier's payment details have been fraudulently changed and apply the right steps to confirm legitimate updates. | ISO, PCI, NIST |
| Recognizing Phishing Emails That Enable BEC | 5 min | Identify the phishing techniques attackers use to gain the email access that makes BEC attacks possible. | ISO, NIST, SOC2 |
| Building a Payment Verification Culture | 5 min | Apply practical team habits and process controls that make it harder for BEC and payment fraud to succeed in your organization. | ISO, SOC2, NIST |
| Responding When You Think You Have Been Compromised | 5 min | Follow the correct immediate steps when you suspect your email has been compromised or a fraudulent payment has been made. | NDPA, ISO, NIST |
Compliance codes show which frameworks each module supports. Some clauses are marked "verify" in our source review, meaning we phrase the claim cautiously rather than cite an exact, unconfirmed section number. See the glossary for term definitions.