When the FBI responded to claims that its jobs portal had been breached, it couldn't yet say where the weak point was. The point of breach, the bureau said, was "still undetermined", with investigators working out whether it sat with a third party or within the FBI's own systems. The hacking group ShinyHunters claims it exploited a previously unknown flaw in widely used HR software to take data on agents, employees and job applicants. The FBI says it is investigating and working with the third-party providers that support the site.
That uncertainty is what makes the story relevant to finance leaders this Cybersecurity Awareness Month. An agency that investigates cybercrime for a living is still establishing whether a provider's systems were the way in. A finance team's vendor list is usually far longer than one jobs portal, and each relationship carries the same question.
Stolen data is what impersonation runs on
The data at stake is the kind attackers use to pose as someone they're not. Independent tech news outlet 404 Media verified a sample of names, home addresses and phone numbers for FBI agents and their spouses against public records. With details like these, an attacker can pose convincingly as an employee, an executive or a vendor contact, and AI tools can make that impersonation faster to produce. Eftsure has also broken down what ShinyHunters claims happened.
The cost of that kind of deception shows up in the FBI's own data. Its Internet Crime Complaint Center (IC3) recorded US$20.9 billion in reported cybercrime losses in 2025, up 26% on the previous year. Business Email Compromise (BEC) accounted for US$3.05 billion of that across 24,768 complaints. BEC can succeed without malware, through a request that looks legitimate enough to be paid.
Building on Cybersecurity Awareness Month
Cybersecurity Awareness Month, led by CISA and the National Cybersecurity Alliance, focuses this year on four everyday steps, from strong passwords and multifactor authentication to recognizing scams and updating software. Those habits give organizations a strong baseline for protecting people and accounts.
The vendor relationship is where finance teams can extend that thinking. A vendor's portal, inbox or payment instructions can be compromised without any sign on your side. When that happens, a request to update ACH or wire details can arrive from a real address and reference a real invoice, and your own security tools may have no way to flag it, because the breach happened outside your environment.
Stop assuming trust at the point of payment
The FBI's statement captures a problem finance teams face with every vendor: when something goes wrong, it can be hard to tell whether the weak point was yours or theirs. If you plan for compromise, you don't need that answer before you protect the payment. No payment is trusted by default, however established the vendor.
That means checking banking details against an independent source instead of the contact information in the request, re-verifying any change to ACH or wire instructions before the next payment run, and removing approvals that rest only on a familiar voice or a senior name.
Verify before money moves
Six controls can be put in place before the month is out:
- Document who can change vendor banking details in your ERP and vendor portal, and require verification on every one of those paths.
- Verify every new vendor and every change to ACH or wire instructions through a source that is independent of the request.
- Require a second, independent check before any urgent or out-of-cycle wire is released, regardless of who approved it.
- Ask critical vendors how they would notify you of a breach, and what payment changes you should treat as suspect afterward.
- Add finance to your cyber incident response plan, with a named owner for contacting the bank and filing an IC3 complaint quickly if funds go to the wrong account.
- Walk AP through a real example of a vendor impersonation request, so the verification steps feel routine rather than theoretical.
Cybersecurity Awareness Month ends on October 31, but data stolen this year can be reused long after. For finance leaders, the goal is making sure that whatever an attacker knows about your people or your vendors, it isn't enough to move money.