Every story tagged Payment Fraud, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
2 stories · open in the command center
The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without paying.
A UK energy company lost £700,000 (~$1M) through a business email compromise attack where hackers redirected a contractor payment to an attacker-controlled account, highlighting a critical vulnerability in payment authorization processes that the FBI identified as causing over $3 billion in losses across 2025. This incident underscores that standard security practices are insufficient against sophisticated payment fraud schemes and demonstrates the need for enhanced controls around financial transactions, particularly for organizations with distributed subsidiaries and complex payment workflows. CIOs must recognize that email and accounting system access can directly translate to material financial losses and requires multi-factor authentication, payment verification protocols, and transaction monitoring as strategic priorities.