‘Do it now’: Scammers impersonate firm’s chairman on Microsoft Teams chat; company almost lost $120k“立即行动”:诈骗分子在微软Teams聊天中冒充公司董事长;公司险些损失12万美元
Such business e-mail compromise scams exploit trusted communication channels used by employees. Read more at straitstimes.com.
According to the police’s mid-year scam statistics, the number of business e-mail compromise scam cases rose from 156 in the first half of 2025 to 262 in the first half of 2026.
PHOTO: LIANHE ZAOBAO
Published Sep 19, 2026, 10:00 AM
Updated Sep 19, 2026, 10:00 AM
Scammers impersonated a healthcare firm's chairman on Microsoft Teams, nearly tricking the CFO into transferring $120,000 before company protocols stopped the fraud.
Business e-mail compromise scams rose sharply in Singapore, with losses increasing from $19.5 million in early 2025 to $57.3 million in early 2026.
Experts warn that these scams exploit workplace trust and urge firms to verify urgent payment requests independently to prevent sophisticated digital impersonation fraud.
SINGAPORE – When the chief financial officer of a local healthcare firm was asked by her company’s “chairman” and “managing director” to submit the firm’s financial statements, her instinct was to follow orders.
Unbeknownst to her, scammers were impersonating the company’s superiors over a Microsoft Teams group chat.
Acting on instructions from her “bosses” , she almost transferred $120,000 from the firm’s bank account at the scammers’ behest.
She only realised she had been tricked when she spoke to the real managing director, who denied giving such an instruction.
Recounting this case in July, Jane (not her real name), 72, one of the firm’s directors, said: “Everything happened so quickly. The scammers acted with a sense of urgency that made my colleague anxious to get the job done.
“The instruction was just to ‘do it now’.”
The amount lost to such scams, known as business e-mail compromise scams, rose significantly from $19.5 million in the first half of 2025 to $57.3 million during the same period in 2026.
It was the third scam of concern in terms of amount lost in the first half of 2026.
In such scams, scammers impersonate suppliers, vendors, clients or even senior executives within the company to deceive employees into diverting payments to fraudulent bank accounts.
Overall, scam victims in Singapore lost $410.6 million in the first six months of 2026 , with eight in 10 victims being manipulated into handing over their money to scammers.
Tough to reject boss’ request
Jane said the scammers sounded legitimate on the Teams chat and communicated well in English, which made the request more convincing.
She said: “When instructions appear to come from the two most prominent figures in the company, how do you reject that request?”
The scammers failed to get the funds because company protocol called for payment slips to be physically signed for authorisation before any transfers were made.
Said Jane: “If not for that, the $120,000 would have been lost. And the scammers’ next request may be for a larger amount.”
The firm instructed UOB, where the accounts were held , to monitor large transactions and ensure any transfers were made only after proper authorisation.
Carlene Lam, branch manager at UOB, said: “I assured Jane that safeguards were in place and contacted my colleagues in the Risk and Anti-Fraud teams to assess the incident and take the necessary precautions to protect Jane’s organisation, including verifying all payment instructions.”
Daniel Ng, head of group compliance at UOB, said business e-mail compromise scams have evolved beyond traditional e-mails into a broader form of digital impersonation.
“Scammers increasingly exploit messaging, voice and video channels – including AI-enabled impersonation – to pose as trusted executives and trick employees into making fraudulent fund transfers,” he added.
“As these scams become more sophisticated, businesses should treat unexpected or urgent payment instructions with caution and independently verify them through established channels before acting,” Ng said.
Adrian Hia, managing director for Asia Pacific at cybersecurity firm Kaspersky, said business e-mail compromise scams are highly insidious as scammers exploit trusted communication channels that employees use daily.
Hia said such scams are particularly effective as they capitalise on established workplace dynamics and an employee’s inclination to respond quickly to requests from senior leadership, especially those framed as urgent.
He said: “Essentially, the authority associated with a high-ranking executive can work to reduce a recipient’s level of scrutiny and encourage immediate action rather than verification. Business e-mail compromise attacks succeed not only because of technical deception, but because they leverage authority and social workplace expectations.”
Hia said warning signs to look out for include:
Unexpected payment requests, especially if they are made without prior notice or fall outside established procedures.
Requests to transfer funds to new or unfamiliar bank accounts, particularly when payment details differ from those previously used.
Instructions to bypass standard approval processes or keep the request confidential from colleagues.
Unusual sign-in links, unsolicited attachments or login prompts when opening a file .
Helplines and online resources
ScamShield Helpline: 1799
National Mindline: 1771 (24 hours) / 6669-1771 (via WhatsApp)
Nadine Chua is a correspondent covering crime and court at The Straits Times.
根据警方年中诈骗统计数据,商业电子邮件诈骗案件数量从 2025 年上半年的 156 起上升到 2026 年上半年的 262 起。
图片来源:联合早报
发布于2026年9月19日上午10:00
更新于2026年9月19日上午10:00
诈骗分子在微软 Teams 上冒充一家医疗保健公司的董事长,险些骗取首席财务官 12 万美元的转账,幸亏公司规章制度阻止了这起诈骗事件。
新加坡的商业电子邮件诈骗案件急剧增加,损失从 2025 年初的 1950 万美元增加到 2026 年初的 5730 万美元。
专家警告说,这些骗局利用了职场信任,并敦促各公司独立核实紧急付款请求,以防止复杂的数字身份冒用欺诈。
新加坡——当一家本地医疗保健公司的首席财务官被公司“董事长”和“总经理”要求提交公司财务报表时,她的本能反应是服从命令。
她毫不知情,骗子们正在通过 Microsoft Teams 群聊冒充公司上级。
在“老板”的指示下,她几乎按照骗子的要求,从公司的银行账户中转走了 12 万美元。
直到她与真正的总经理交谈后,才意识到自己被骗了,因为总经理否认曾下达过这样的指示。
今年7月,简(化名)——该公司的一位董事,现年72岁——在回顾这起案件时说:“一切发生得太快了。骗子们行动非常迅速,这让我的同事急于完成工作。”
“指示就是‘立即执行’。”
此类诈骗(即商业电子邮件诈骗)造成的损失金额从 2025 年上半年的 1950 万美元大幅上升至 2026 年同期的 5730 万美元。
这是 2026 年上半年损失金额第三高的诈骗案。
在这些骗局中,诈骗分子会冒充供应商、销售商、客户,甚至是公司内部的高级管理人员,欺骗员工将款项转移到欺诈性银行账户。
总体而言,新加坡的诈骗受害者在 2026 年上半年损失了 4.106 亿美元,其中 80% 的受害者被骗子操纵,将钱财交给骗子。
很难拒绝老板的要求
简说,骗子们在 Teams 聊天中听起来很正规,英语也说得很好,这使得他们的请求更具说服力。
她说:“当指示似乎来自公司里两位最杰出的人物时,你怎么能拒绝这样的要求呢?”
由于公司规定在进行任何转账之前,付款单必须经过签字授权,因此诈骗分子未能获得资金。
简说:“要不是这样,那12万美元就打了水漂。而且骗子们下次可能会索要更多钱。”
该公司指示其账户所在的 UOB 银行监控大额交易,并确保所有转账都必须经过适当授权后才能进行。
大华银行分行经理卡琳·林表示:“我向简保证,我们已经采取了安全措施,并联系了风险和反欺诈团队的同事,评估了这起事件,并采取了必要的预防措施来保护简的机构,包括核实所有付款指示。”
大华银行集团合规主管吴丹尼表示,商业电子邮件诈骗已经从传统的电子邮件演变为更广泛的数字冒充形式。
他还补充说:“诈骗分子越来越多地利用即时通讯、语音和视频渠道(包括人工智能辅助的身份冒充)冒充值得信赖的高管,诱骗员工进行欺诈性资金转移。”
“随着这些诈骗手段变得越来越复杂,企业应该谨慎对待意外或紧急的付款指示,并在采取行动之前通过既定渠道进行独立核实,”吴先生说。
网络安全公司卡巴斯基亚太区董事总经理 Adrian Hia 表示,商业电子邮件诈骗非常隐蔽,因为诈骗分子会利用员工日常使用的可信通信渠道。
Hia表示,这类骗局之所以特别有效,是因为它们利用了既定的职场动态以及员工倾向于快速响应高层领导的要求,尤其是那些被包装成紧急要求的。
他说:“本质上,高管的权威会降低收件人的审查力度,促使他们立即采取行动而不是核实。商业电子邮件诈骗之所以能够成功,不仅是因为技术上的欺骗,还因为它们利用了权威和职场中的社会期望。”
希亚表示,需要注意的警告信号包括:
意外的付款请求,尤其是没有事先通知或不符合既定程序的付款请求。
要求将资金转入新的或不熟悉的银行账户,尤其是当付款详情与以前使用过的付款详情不同时。
指示如何绕过标准审批流程或对同事保密请求。
打开文件时出现不寻常的登录链接、未经请求的附件或登录提示。
热线电话和在线资源
诈骗防护热线:1799
全国热线:1771(24 小时)/6669-1771(通过 WhatsApp)
Nadine Chua是《海峡时报》负责报道犯罪和法庭新闻的记者。