Prevention by design: how to prevent phishing and corporate fraud with multisign
Cybercriminals use AI and sophisticated social engineering to target businesses. However, with built-in security measures such as multisign authentication, you can establish a crucial line of defence. The question is not if your business will be targeted by digital fraud, but when. Do you think this only happens to other people? Stéphane Goddé (Head of Fraud Management & Investigations) and Bert Dobbelaere (Business Lead for Fraud Management) at BNP Paribas Fortis analyse the market. Their conclusion: the focus of defence is shifting from purely technical IT security to your corporate culture and process architecture.
By 2026, corporate fraud will no longer be the work of amateurs, but an organised B2B industry. Criminal networks operate using ready-made scripts, manuals and zip files from the dark web. They launch highly targeted attacks on Belgian companies of all sizes. According to recent Febelfin figures, phishers in Belgium steal nearly €93 million annually. Banks proactively block or recover around 75% of fraudulent transactions, but the pressure is relentless. This is evident from the nearly 10 million suspicious messages that Belgians report to Safeonweb every year. Beyond financial losses, businesses also face threats to continuity, data security and customer trust.
The psychology behind the click: ‘Banks don’t get hacked’
There is a common misconception in the world of cybersecurity that combatting fraud is a technological arms race. “In Belgium, there isn’t a single known case of a bank being hacked where money has simply been taken from an account,” explains Bert Dobbelaere. “The underlying cryptography has so far been foolproof. Instead, criminals are hacking into human psychology.”
Fraudsters don’t attack the bank’s IT infrastructure, but manipulate company staff who have access to the accounts. They capitalise on human emotions: fear of an account being blocked, the temptation of a unique opportunity, or loyalty under time pressure.
Generative AI makes this social engineering even more effective. Whereas phishing messages used to stand out due to grammatical errors, AI now generates flawless, personalised messages in any language.
“The real tsunami is yet to come, but the market is moving in that direction. Criminals are using AI voice cloning to mimic the voice of a business partner or board member using just a few seconds of audio. They are already training AI models to call customers and make promises on their behalf. Video cloning may well be added to this soon.”
— Stéphane Goddé, Head of Fraud Management & Investigations
In CEO or bank helpdesk fraud, criminals pressure finance staff to the point where they ignore the bank’s warnings. Under this duress, victims may install remote access software, such as AnyDesk or TeamViewer, or authorise transactions believing that they are blocking the fraud, when in reality, they are enabling it.
In safe deposit box fraud, scammers first obtain login details via phishing. They then impersonate a bank employee over the phone and convince the victim to transfer money to a ‘secure’ safe deposit box account – which in reality belongs to a money mule.
Another tactic is account takeover. Fraudsters trick victims over the phone into approving an itsme® notification. This allows criminals to link their own device to your Easy Banking Business (EBB) or Mobile (EBBM) environment in the background. Never approve an itsme® request unless you are actively logging in or linking a device yourself.
Prevention by design: control and efficiency through multisign
“To protect businesses, BNP Paribas Fortis employs the ‘Prevention by design’ strategy. Security is not a disruptive layer of control applied after the fact but is woven into the very fabric of all digital channels. The advice to business owners is clear: never leave the bank’s secure digital channels and never trust external links or unsolicited messages,” says Stéphane Goddé.
The strongest barrier in Easy Banking Business is the 4-eyes principle via multisign. Social engineering usually targets 1 employee in isolation. As soon as a second person has to validate the payment via multisign, the fraud chain collapses.
Business owners sometimes fear that such monitoring slows things down. The opposite is true: monitoring and efficiency reinforce one another.
Cet équilibre se construit différemment selon la taille de votre entreprise. La structure digitale s’adapte parfaitement à votre organisation.
- For SMEs and small businesses: multisign acts as an efficient tool. A finance staff member prepares payments, after which the CEO or legal representative approves the entire batch at the end of the day in a single, straightforward step.
- For medium-sized and large enterprises: risk management, segregation of duties and corporate governance are key. Using advanced settings, you can define strict signing groups, whereby payments above a specific threshold require approval by multiple authorised signatories.
This keeps the day-to-day administrative burden to a minimum while ensuring that internal controls and fraud prevention are watertight.
Did you know you can easily configure multisign online?
A secure corporate culture starts with the setup of your digital channels. As a contract manager, you can set your own signing rules and signing groups via the Administration module. View all practical information on the official Easy Banking Business page.
Conclusion: a shared responsibility
A watertight defence against corporate fraud depends on 2 pillars: the bank’s technology and your company’s culture. BNP Paribas Fortis continuously invests millions in real-time fraud detection and secure channels. But the defence breaks down when human decisions circumvent security protocols.
Fraudsters create acute pressure to override common sense. You can break through this psychological ‘hypnosis’ with a clear corporate culture. Give staff the freedom to pause the procedure when in doubt and consult internally. By 2026, secure banking will no longer be an IT issue, but a strategic management discipline focused on prevention.
The 10 golden rules for a resilient business:
- Always enter URLs yourself: never click on links in emails, text messages or WhatsApp to access online banking. Use bookmarks, the official app or type the URL in yourself.
- Keep banking codes strictly confidential: never share your PIN or card reader response codes via email, phone or social media. The bank will never ask for these details.
- Enforce multisign authorisation: always ensure that payments above a certain threshold are signed off by at least 2 people.
- Check master data rigorously: always verify a supplier’s changed account number via a phone number from your own database, never via the invoice itself.
- Check email addresses carefully: check the sender’s domain name for every payment. Fraudsters often mimic the email addresses of senior management with a difference of just one letter.
- Never install software on request: hang up immediately if a so-called bank employee asks you to install new software.
- Be wary of urgency: emails marked ‘confidential’ or ‘extremely urgent’ are typical red flags of social engineering.
- Personalise banking authorisations: give each employee strictly personalised access. Sharing access codes, cards or PINs leaves you vulnerable.
- Set up proactive limits and alerts: configure notifications via the Easy Banking Business Mobile app for outgoing transactions exceeding a chosen threshold amount.
- Invest in continuous training: your finance team is your first line of defence. Provide them with regular training to recognise emerging threats like invoice fraud and AI-driven deception.
Would you like to add extra security to your business accounts with multisign? Configure your settings directly in Easy Banking Business or contact your account manager.

