Cyber Brief for CFOs: July 2026

Cyber Brief for CFOs: July 2026

Each month, the team at Eftsure monitors the headlines for the latest accounts payable (AP) and security news. We bring you all the essential stories in our cyber brief so your team can stay secure.

SC town loses $545,000 to scam despite verification efforts

South Carolina town Surfside Beach lost $545,598 to a business email compromise scam after a fraudster slipped into an email thread between the town and its contractor. The malicious actor then switched a scheduled payment from a check to an electronic transfer, as reported by The Wall Street Journal and Insurance Business.

The scammer used a lookalike domain, a capital "I" standing in for a lowercase "l," and a forged ACH form to redirect the payment to an account in Utah, helping fraudsters go unnoticed for 45 days. The town and contractor are now disputing who is liable, and the town's insurer has questioned whether its policy even responds.

See our full breakdown of how the scam worked.

New research: 4 in 10 finance teams hit fraud or overpayment last year

New research from the Controllers Council and Ottimate finds that 41% of organizations experienced invoice fraud or overpayment in the past year, based on a survey of more than 200 finance leaders.

The State of AP Maturity 2026 report ties that exposure to partial automation: disconnected systems and manual reviews that leave errors and fraud invisible until after a payment goes out. Just 48% of teams have a step to verify a vendor's banking details before paying, and only about half require two or more approvers. As AI makes fraud harder to spot, the report argues that piecemeal automation widens the gap rather than closing it.

Hackers stole entire mailboxes through a Zimbra flaw

A joint advisory from CISA, the NSA, the FBI, and allied agencies warns that a Russia-linked group known as Laundry Bear stole entire mailboxes from organizations running Zimbra Collaboration Suite, using an exploit that needs no link click or attachment.

The group abused a zero-day flaw (CVE-2025-66376) that runs code the moment a rigged email is opened or previewed in the Zimbra web client, a method Proofpoint calls a "half-click" exploit with no social engineering required.

Once in, it took up to 90 days of email and the full address book, harvested credentials and two-factor codes, set an app-specific password for persistent access, and used the hijacked accounts to phish new targets. The campaign allegedly hit government and private-sector organizations across the US and NATO countries after first testing on Ukraine.

Nacha extends ACH fraud-monitoring rules to every business originator

New fraud-monitoring rules from Nacha now apply to every business that originates ACH credit payments, after the second phase of its 2026 Risk Management amendments took effect on June 22.

Phase 2 extends the requirement to all non-consumer originators, third-party senders, and service providers that fell below the volume threshold covered by Phase 1 in March, and it asks receiving institutions to run their own risk-based checks to catch fraudulent credits. The rules stay deliberately technology-neutral, so the obligation is to have effective monitoring in place, not to buy a specific tool.

Make sure to catch our discussion with a Nacha specialist exploring recent rule changes and what they look like within everyday operating rhythms.

Deloitte: most corporate boards still have no rules for AI use

A Deloitte survey of governance professionals finds that 51% of boards have no rules or guidance for how artificial intelligence is used, even as the technology spreads through the businesses they oversee.

Only 8% of boards use company-approved AI tools for committee work, and nearly half do not facilitate AI use at all. Where policies do exist, they tend to focus on security, confidentiality, and recordkeeping. The finding matters as AI moves into finance and payment workflows, where an unmanaged tool can expose confidential data or approve something it should not.

Survey: 92% of finance leaders feel pressure to prove AI's return

An Avalara survey of 1,505 finance leaders finds that 92% feel pressure to show a return on their AI investments, while only 7% say their organization prioritizes AI governance over speed of adoption.

The gap shows up in the controls. Thirty percent have not updated internal controls in the past year, 44% are only somewhat confident they could explain an AI agent's actions to an auditor, and nearly half say their AI incident response plans are untested or still in development. Half reported only limited measurable ROI so far.

In other words, agents are being deployed into finance processes faster than the oversight around them is being built.

Kyriba: security and privacy rank among CFOs' top concerns

Kyriba's CFO Risk Radar, based on a survey of 1,000 CFOs and senior finance leaders, ranks security and privacy as the second-highest concern at 76%, behind only inflation.

The reading places security ahead of geopolitical instability, interest rates, and regulatory risk, a sign that fraud and data protection now sit firmly in the CFO's core risk view rather than the IT department's alone. The shift reflects how payment fraud and social engineering have become financial performance issues, not just technical ones.

Author

Shanna Davis

Published

27 Jul 2026

Reading Time

5 minutes