1. Verify Bank Account Changes by Phone
A common scam involves receiving a fake email from a regular supplier claiming their bank account details have changed. Always verify change-of-details requests by calling the supplier on a trusted phone number before sending payments.
2. Lock Down Your Payment Terminals (POS)
Never let staff browse the web or check personal emails on terminals used for payment processing. A single phishing click can infect the merchant network and capture customer card information.
3. Limit Account Privileges
Staff should use basic “user” accounts rather than administrator accounts. This prevents unauthorized software installations and limits malware from spreading if a device is targeted.