CFOtech Asia - Technology news for CFOs & financial decision-makers
Asia
Finance teams face rise of behavioural cyber attacks

Finance teams face rise of behavioural cyber attacks

Fri, 31st Jul 2026 (Today)
Karen Joy Bacudo
KAREN JOY BACUDO Finance Editor

Net-Defence says finance teams have become prime targets for cybercriminals using behavioural manipulation, with attackers focusing on human responses within routine financial processes.

Finance departments are vulnerable because they control payments, payroll, supplier records and approvals, while operating in environments that depend on speed, trust and confidentiality.

Rather than relying only on malware or software flaws, attackers are increasingly crafting messages and scenarios that appear legitimate to employees handling financial transactions. The approach focuses on influencing behaviour under pressure, including urgent approvals and supplier account changes.

Debra Cairns, Managing Director of Net-Defence, said the threat has moved beyond purely technical intrusion.

"Cyber security is no longer just about exploiting technical weaknesses," Cairns said.

"Attackers are studying how finance teams work, how decisions are made under pressure and how organisations naturally operate. If they can manipulate behaviour, they often don't need to hack systems."

Behaviour shift

Criminals are using what Net-Defence describes as behavioural engineering to prompt finance professionals to make transactions or data changes that appear normal within established workflows. The firm argues this makes fraudulent instructions harder to detect because they mirror genuine business communication.

Common tactics include impersonating senior executives, sending urgent payment requests and posing as suppliers seeking changes to bank account details. According to Net-Defence, these messages can be built from information gathered through company websites, LinkedIn profiles and social media accounts.

The firm identified three recurring triggers in attacks aimed at finance functions: authority, urgency and familiarity. It said these elements can reduce the likelihood that staff will stop to verify a request through a separate channel.

Cairns said successful attacks often exploit behaviours companies actively encourage in finance staff.

"Finance professionals aren't making careless mistakes," she said.

"In many successful attacks, employees are behaving exactly as they've been trained to do: responding quickly, maintaining confidentiality and keeping business moving. The challenge is that attackers understand those expectations and deliberately build attacks around them."

One example described by the firm involved a Finance Manager receiving an email that appeared to come from a Chief Executive asking for an urgent supplier payment before the close of business. The message referred to a genuine commercial project and explained that the executive was travelling and unavailable by phone, creating a plausible reason not to verify the request verbally.

Net-Defence says cases like this are too often reduced to employee failure when they are better understood as attacks designed around hierarchy, routine and time pressure. That distinction matters for businesses reviewing internal controls and staff training.

"When a request appears to come from a senior executive and is marked confidential or time-sensitive, people naturally prioritise it," Cairns said.

"Attackers know that urgency reduces verification, while familiarity lowers suspicion."

Broader impact

The fallout from these incidents can extend beyond a single fraudulent payment. Potential consequences include payroll disruption, damaged supplier relationships, delayed financial reporting, regulatory scrutiny and harm to customer confidence.

Net-Defence also warned that greater use of digital finance platforms, automation and artificial intelligence tools could make personalised attacks easier to produce at scale. Publicly available corporate information gives criminals more material to create convincing communications that fit seamlessly into everyday business activity, it said.

Cairns said artificial intelligence is making social engineering more persuasive.

"These incidents are often described as human error, but that's an oversimplification," she said.

"The attack succeeds because the criminal understands organisational behaviour, hierarchy, pressure, confidentiality and decision-making, not because the individual lacks competence."

She added that training focused only on suspicious links no longer addresses the full problem facing finance departments. In her view, organisations need controls that reflect how employees make decisions when deadlines, seniority and commercial urgency collide.

"Artificial intelligence allows attackers to produce increasingly convincing communications at scale. Combined with publicly available corporate information, it has become much easier to create believable scenarios that fit seamlessly into normal financial operations," Cairns said.

For finance leaders, that points to reviewing payment approval rules, tightening supplier verification and encouraging staff to challenge unusual instructions regardless of who appears to have sent them. Net-Defence argues that effective resilience depends on processes that support employees rather than simply warning them to be more cautious.

"Cyber resilience isn't about slowing finance teams down," Cairns said.

"It's about recognising where predictable business behaviours create opportunities for attackers and putting practical verification processes in place that support employees when they're working under pressure."

She framed the issue as one of organisational design as much as cyber defence.

"As organisations become more digitally connected, behaviour itself has become part of the attack surface. The organisations that succeed will be those that understand how people make decisions under pressure and design financial controls that protect both the business and the professionals responsible for keeping it running," Cairns said.