Each month, the team at Eftsure monitors the headlines for the latest accounts payable (AP) and security news. We bring you all the essential stories in our cyber brief so your team can stay secure.
Governments warn North Korean IT workers are infiltrating remote hiring
Eleven countries, including Australia, issued a joint statement on 31 July warning that North Korean IT workers are using fake identities and AI tools to land remote jobs and funnel their earnings back to fund the regime's weapons programs.
Australia's Department of Foreign Affairs and Trade signed alongside Canada, France, Germany, Italy, Japan, the Netherlands, New Zealand, South Korea, the UK and the US, noting workers are using "increasingly sophisticated methods, including the integration of AI" to disguise their identities. For finance and HR teams running remote hiring or contractor onboarding, this is a direct instruction to tighten identity verification at the point of engagement, not just at the point of payment.
AFCA membership deadline brings scam liability rules into force
Businesses caught under Australia's Scams Prevention Framework must become members of the Australian Financial Complaints Authority by 1 September, with early applications encouraged from 14 August.
The SPF puts binding obligations on banks, telcos and digital platforms to prevent, detect and disrupt scams, with AFCA set to start handling scam-related complaints from March 2027. For finance teams working with regulated entities, this is the first hard compliance date attached to the framework, and it signals how much scrutiny is coming to payment and onboarding controls in the year ahead.
New research: 70% of finance teams hit by a payment fraud attempt
Yooz's 2026 Payment Fraud Readiness Report, surveying 750 US finance and AP professionals, finds 70% experienced a payment fraud attempt in the past two years or couldn't rule one out, and 39% of successful attempts cost more than $50,000.
Teams relying mainly on manual AP processes lost money in 42% of fraud attempts, against 22% for teams using a mix of automation - a gap large enough to change the ROI case for automation investment. Nearly half of respondents said they'd let, or almost let, a suspicious payment through because it appeared to come from a trusted source, which is the finding that should worry finance leaders most: verified identity no longer means legitimate intent.
Singapore's payments industry launches a voluntary fraud and pricing code
The Singapore Fintech Association launched a Payments Industry Code of Conduct setting common standards on pricing transparency, fraud protection and consumer safeguards for payment institutions, money-changing licensees and other regulated payment service providers.
Adherents must maintain fraud prevention frameworks covering risk assessments, real-time monitoring, incident response and scam education, and adopt card liability standards broadly aligned with banks. Adherence is self-assessed and voluntary, renewed annually, and complements existing MAS requirements rather than replacing them. SFA President Holly Fang said the code "raises the baseline of trust that good businesses are built on" - a useful signal for finance teams assessing Singapore-based payment partners, even without a mandatory floor.
NZ businesses face a coverage gap on business email compromise losses
New Zealand's cyber insurance market has not resolved whether business email compromise and funds transfer fraud losses count as a cyber event or a crime event, and the distinction determines whether a claim is even covered.
Standard crime and fidelity policies typically exclude "voluntary parting" losses, where a deceived employee knowingly authorises a transfer, and social engineering sublimits of $100,000 to $250,000 are increasingly seen as inadequate. The exposure is real - of the $265 million defrauded from New Zealanders through bank accounts in the year to October 2025, roughly $126 million involved authorised payments where someone was tricked into approving the transaction themselves, per Payments NZ data. For finance teams, that gap means a successful BEC scam can be a loss with nowhere to claim it back from.