Cyber Brief for CFOs: August 2026

Cyber Brief for CFOs: August 2026

Each month, the team at Eftsure monitors the headlines for the latest accounts payable (AP) and security news. We bring you all the essential stories in our cyber brief so your team can stay secure.

FBI seizes $1M of $1.8M stolen from Guam agency in BEC scam

A fraudster impersonating a Judiciary of Guam official used a spoofed email to redirect $1.8 million meant for the court into an account they controlled - the FBI has since seized $1 million of it back, but $800,000 is still missing.

A scammer posing as a Judiciary of Guam official emailed the department's accounts payable team in January, convinced staff to redirect a routine interagency payment, and backed the request with fabricated verification documents. DOA wired nearly $1.8 million before catching the fraud in late February; the FBI traced and seized about $1 million from the fraudster's bank accounts in May, but the remaining $800,000 is still unaccounted for. Even routine, internally-expected payments need out-of-band verification before a bank detail change goes through.

Governments warn North Korean IT workers are infiltrating remote hiring

Eleven countries, including the US, issued a joint statement on 31 July warning that North Korean IT workers are using fake identities and AI tools to land remote jobs and funnel their earnings back to fund the regime's weapons programs.

The US Department of State signed alongside Australia, Canada, France, Germany, Italy, Japan, the Netherlands, New Zealand, South Korea and the UK, noting workers are using "increasingly sophisticated methods, including the integration of AI" to disguise their identities. For finance and HR teams running remote hiring or contractor onboarding, this is a direct instruction to tighten identity verification at the point of engagement, not just at the point of payment.

New research: 70% of finance teams hit by a payment fraud attempt

Yooz's 2026 Payment Fraud Readiness Report, surveying 750 US finance and AP professionals, finds 70% experienced a payment fraud attempt in the past two years or couldn't rule one out, and 39% of successful attempts cost more than $50,000.

Teams relying mainly on manual AP processes lost money in 42% of fraud attempts, against 22% for teams using a mix of automation - a gap large enough to change the ROI case for automation investment. Nearly half of respondents said they'd let, or almost let, a suspicious payment through because it appeared to come from a trusted source, which is the finding that should worry finance leaders most: verified identity no longer means legitimate intent.

DOJ's trade-fraud crackdown is pulling banks and payment data into enforcement

The Justice Department's Trade Fraud Task Force has surpassed $1 billion in civil and criminal recoveries, penalties, forfeitures and publicly charged losses in under a year, and the DOJ has now published a joint resource guide making clear that financial institutions sit inside its enforcement perimeter.

Customs fraud doesn't always involve dirty money: the funds can be legitimate while the declared product value, classification or country of origin is false. That means banks reviewing trade-finance transactions increasingly need to reconcile payment amounts against customs documentation, since a mismatch between what's declared at the border and what a bank actually processes can be the clearest signal something's wrong. For finance teams managing cross-border vendor payments, it's a reminder that trade compliance and payment verification are converging into the same control problem.

North American CFOs flag cybersecurity as a top AI governance concern

Deloitte's second-quarter 2026 CFO Signals survey of 200 CFOs at North American organizations with at least $1 billion in revenue found only 43% feel confident in their organization's current AI governance, while 53.5% feel only somewhat confident.

Fifty-nine percent cite balancing the pressure to deploy AI quickly against managing risk as their biggest governance challenge, and cybersecurity ranks as the second-most-cited external concern (41%) tied to AI use, just behind litigation risk. That lines up with Deloitte's separate Finance Trends 2026 survey, where 47% of finance leaders named data security their top barrier to AI adoption. Notably, 19% of CFOs say they personally hold the greatest responsibility for AI governance at their company, ahead of CEOs, AI governance committees, and boards combined.

Author

Catherine Chipeta

Published

19 Aug 2026

Reading Time

4 minutes

security-image

The New Security Standard for Business Payments

security-image
security-image