PS ProTech(305) 699-5652
← All posts

Financial advisers

Account takeover: the risk financial advisers can't delegate

· PS ProTech · 2 min read

An adviser's working day runs through a handful of logins: email, the custodian's platform, the planning software, the client portal. Whoever holds those logins can see what you see and, in some cases, do what you do. That's why account takeover is the attack that matters most to an advisory practice.

How it happens

A fake sign-in page. An email that appears to come from your custodian says your account needs verifying. The link leads to a perfect copy of the login page. With AI writing these, there's nothing in the wording to give it away, as we explain in how AI changed phishing.

A reused password. A password you used years ago on another site was stolen in that site's breach, and it's the same one protecting your email. See your firm's passwords are on the dark web.

Your mailbox first. Attackers usually go for email before anything else, because password resets for every other service arrive there.

What they do once inside

  • Read quietly. They learn your clients, their balances, how they write to you and how you reply.
  • Request a transfer as the client, timed for when the client is hard to reach.
  • Impersonate you to your clients, asking them to move money or confirm details.
  • Impersonate a client by phone, with a cloned voice. See the call-back rule.

The controls that stop it

  1. Multi-factor authentication on everything, email first. It makes a stolen password close to useless. See why it comes first.
  2. Alerts on unusual account activity: a sign-in from an unfamiliar place, a new forwarding rule, a change to recovery details.
  3. A different password for every service, kept in a password manager.
  4. Verbal confirmation of every transfer request, on a number you already hold, with a verification question the client has agreed in advance.
  5. Email security that catches impersonation of clients and custodians.

Why it's your problem

Clients trust an adviser with their money and their personal details, and regulators expect that information to be safeguarded with a written program. A client whose funds move on a fraudulent instruction will look to the practice that acted on it. This is general information, not legal advice; check the rules that apply to your registration.

Our page for financial advisers sets out the threats and what a breach can cost. To see where your practice stands, book a free IT and cybersecurity review.

See what it costs for your firm.

Build a plan in two minutes. No call required.