From phishing to greenwashing

15 September 2026Insights
FS-Campus-and-Skyline-Droneshot.Webp

Why fraud prevention needs a rethink

Summer 2020, Wirecard: €1.9 billion supposedly held in Philippine trustee accounts – accounts that never existed. For many, this was the moment it became clear that accounting fraud was not a peripheral issue, but a genuine risk, even at a DAX-listed company. What remains striking is how long the fraud went undetected because no one looked closely enough.

And spotting fraud is becoming more difficult as the landscape changes. Today, any serious discussion about fraud must include two areas that, a decade ago, were largely considered separately: cyber security and ESG.

 

When an email becomes a weapon

 

It starts with one of the most underestimated points of entry. Today, gaining access to an organisation does not necessarily require exploiting a vulnerability in its systems. Often, a convincing email is enough.

Social engineering and phishing do not target firewalls. They target people – their willingness to help, their response to time pressure and their respect for authority. The classic CEO fraud case at automotive supplier Leoni demonstrates just how effective this can be: the company lost around €40 million as a result.

Since then, the threat has evolved. In 2024, an employee of an international company in Hong Kong joined a video conference and subsequently transferred around US$25 million. Only afterwards did the employee discover that every ‘colleague’ on the call, including the chief financial officer, had been an AI-generated deepfake.

And the scale can be even greater. In 2017, the NotPetya attack on shipping company Maersk spread through compromised accounting software and brought the IT systems of the world’s largest container shipping company to a standstill within hours. Terminals stopped operating and tens of thousands of computers had to be rebuilt. The estimated damage: around US$300 million.

The case demonstrates that a single targeted cyberattack can disrupt an entire global supply chain, not just one company. This is why cyber security and financial forensics belong together. The attack may be digital, but its consequences can ultimately be measured in financial terms. Those who understand payment processes, authorisation procedures and control weaknesses also understand where the next attacker is likely to find an opening.

 

The perpetrator is often sitting at the next desk

 

Yet the threat from within is often more common than an external attack. The Association of Certified Fraud Examiners (ACFE) estimates that organisations worldwide lose around 5% of their revenue to fraud. On average, a case continues for a year before it is detected. Most cases are uncovered through a tip rather than by the controls that were supposed to identify them.

And the typical perpetrator rarely fits the stereotype. It is not necessarily a hacker in a hoodie, but often a long-standing, inconspicuous and trusted employee with the right access privileges.

Procurement is one area that is particularly vulnerable in practice: supplier kickbacks, shell companies using an employee’s bank account, manipulated tenders or maintenance contracts for services that were never provided. Wherever high purchasing volumes coincide with close personal supplier relationships and weak segregation of duties, opportunities for fraud arise.

Two cases illustrate how significant the consequences can be. In 2018, it emerged that of the 1.6 million freight containers sold to investors by Munich-based container investment company P&R, only just over a third actually existed. The estimated loss was around €3.5 billion.

Then there is the collapse of cryptocurrency exchange FTX. Billions in customer funds were channelled into an affiliated trading firm while the company publicly cultivated the image of a model enterprise. Its founder, Sam Bankman-Fried, was sentenced to 25 years in prison in 2024.

Whether the asset is a freight container or cryptocurrency, the underlying patterns are remarkably similar. That is precisely why internal audit and fraud management need people who can identify these patterns before they result in losses running into the billions. Well-trained fraud managers are no longer simply a useful addition. They are a key component of modern governance.

 

When marketing becomes a criminal matter

 

While organisations are increasingly strengthening their response to these established risks, the frontline continues to shift.

For a long time, greenwashing was treated as a relatively minor offence in corporate communications. Sustainability claims might have been presented a little too positively, but little more was thought of it. Those days are over.

The case of asset manager DWS shows how quickly ambitious sustainability claims can lead to regulatory investigations. The statement ‘ESG is part of our DNA’ did not stand up to scrutiny. The result was a multimillion-dollar penalty imposed by the US Securities and Exchange Commission (SEC), followed in April 2025 by a €25 million fine from Frankfurt prosecutors.

This is not an isolated case. It reflects a broader trend. Since September 2025, companies in the UK can face criminal liability if they fail to prevent fraud – expressly including greenwashing – through reasonable prevention procedures.

Meanwhile, through the Corporate Sustainability Reporting Directive (CSRD), the EU Taxonomy Regulation and the Corporate Sustainability Due Diligence Directive, the EU is bringing sustainability reporting increasingly close to financial reporting. As a result, false ESG disclosures are set to face the same standards of scrutiny and liability as conventional financial reporting metrics.

ESG fraud also extends beyond the ‘E’. False disclosures relating to social factors (‘S’) or corporate governance (‘G’) offer considerable scope for manipulation.

 

One toolkit for three different worlds

 

A phishing email, a kickback in procurement, an embellished sustainability report – these cases may appear very different. Yet the skills required to detect them are remarkably similar: forensic thinking, an understanding of digital attack vectors and a firm grasp of the regulatory landscape, from CSRD to the Green Claims Directive.

The Certified Fraud Manager (CFM) at Frankfurt School of Finance & Management provides precisely this toolkit, combining practical application, case-based learning and insights into current regulatory developments.

Wirecard, P&R and FTX have shown what can happen when no one asks the uncomfortable questions. The next generation of fraud cases may begin with a deceptively convincing email or be hidden in emissions factors and supply chain certificates.

Detecting them requires knowing what to look for. And that can be learned. The CFM provides the opportunity to develop these skills.

Marc Gittler

Marc Gittler works in Internal Audit at an international technology and financing group, where he establishes international group audit processes and develops data-driven audit approaches. Previously, he spent more than ten years managing national and international audits at a DAX-listed company, where he also introduced digital audit methodologies. He is a Certified Internal Auditor (CIA), Certified Financial Services Auditor (CFSA) and holds the Certification in Risk Management Assurance (CRMA). At Frankfurt School of Finance & Management, he teaches Financial Forensics and ESG & Cyber Security as part of the Certified Fraud Manager programme.
Connect on LinkedIn
Marc-Gittler.Webp