For fund managers, cyber risk is often associated with ransomware, data breaches and malware. Increasingly however, one of the biggest threats does not involve breaking through sophisticated technology at all. It involves tricking a person.
Social engineering fraud is where criminals manipulate employees into revealing information, providing access or authorising transactions. This is becoming an increasingly serious risk for Singapore fund managers, private equity firms, venture capital firms, family offices and other financial services businesses.
The financial consequences can be significant. The Singapore Police Force recorded S$35.3m in losses from Business Email Compromise (BEC) scams in 2025. BEC involves scammers impersonating vendors, clients or senior employees, often through spoofed or compromised email accounts, to persuade businesses to make payments or carry out fraudulent instructions.
More recently this year, Singapore authorities highlighted a case in which scammers impersonated the chairman of a Singapore based company, ultimately resulting in US$36.3 million being transferred from local and overseas accounts.
For fund managers where transactions can involve very large sums, this type of fraud deserves particular attention.
What is Social Engineering?
Social engineering is a fraud technique that exploits trust, authority and urgency to manipulate employees into disclosing information, granting access or authorising actions such as fraudulent payments.
Rather than hacking directly into a system, criminals may convince an employee to:
- Reset a password
- Enter their login credentials into a fake website
- Approve a multi-factor authentication request
- Share confidential information
- Change bank account details
- Authorise a payment
- Transfer funds
- Provide access to a third-party platform
- Follow instructions that appear to come from a senior executive, investor, administrator or other trusted contact
The attacker is exploiting trust and human behaviour. Increasingly, these attacks can be extremely convincing.
Consider this scenario
The fake password reset
Take for example an employee at a fund receives an email appearing to come from the company’s IT provider:
“Your Microsoft 365 password expires today. Click here to keep your account active.”
The branding looks legitimate. The email appears professional. It may even contain the employee’s name and company information. The employee clicks the link and is taken to a login page that looks almost identical to the genuine Microsoft login page. They enter their username and password. Within seconds, the attacker may have obtained the credentials needed to access the employee’s mailbox.
The attacker does not necessarily need to do anything immediately. They can monitor emails, learn how the organisation operates and identify who is responsible for payments. They may wait until the right opportunity arises. The attacker is often looking for the payment process, which is where social engineering becomes particularly dangerous for fund managers.
Imagine an attacker has compromised the email account of someone involved in finance or fund administration.
Through monitoring communications, they learn:
- Which investors are making payments
- When capital calls are being issued
- Who approves transactions
- Which fund administrator the business uses
- Which banks and law firms are involved
- Who has authority to make payments
- How payment instructions are normally communicated
- When senior executives are travelling or unavailable
Eventually, they intervene. A fraudulent email might say:
“Please use the attached updated bank details for this capital call.” Or, “We need to make this payment urgently. Please process it today.” The request may appear completely legitimate.
Why Fund Managers are Particularly Exposed
Fund managers have several characteristics that make them attractive targets for social engineering.
1. High Value Transactions
A successful fraud does not need to involve hundreds of transactions. One fraudulent payment could potentially result in a very substantial loss.
2. Multiple Trusted Counterparties
Fund managers regularly communicate with investors, fund administrators, banks, lawyers, accountants, portfolio companies and other professional advisers. This creates a complex web of trusted relationships that attackers can exploit.
3. Lean Teams
Many fund managers operate with relatively small teams. An individual employee may have significant responsibility for finance, investor communications or operational matters. This can create a concentration of risk.
4. Highly Valuable Information
A compromised mailbox can provide access to information about investors, transactions, portfolio companies, valuations and future activities. Even if the attacker cannot immediately steal money, this information can help them construct a much more convincing fraud.
5. Seniority and Trust
Investment businesses are often highly relationship driven. An email that appears to come from a managing partner or CFO saying “Can you take care of this urgently?” may receive less scrutiny than a generic phishing email.
The Threat is Moving Beyond Email
Email remains a major attack vector, but social engineering is no longer limited to email. Singapore Police have also warned about scammers impersonating company senior executives through WhatsApp, including fraudulent instructions involving company funds.
This creates an additional challenge for fund managers. In addition, with generative AI making it easier to produce convincing written communications, and potentially convincing voice or video impersonations, these attacks are becoming increasingly sophisticated.
Why Cybersecurity Controls aren’t Enough
Strong cybersecurity remains essential. This includes appropriate controls around:
- Multi-factor authentication
- Email security
- Endpoint protection
- Password management
- Access controls
- Security awareness training
- Backup and recovery
- Monitoring for suspicious activity
But social engineering demonstrates an important limitation: The attacker does not always need to defeat the technology. They can persuade the person using it.That means cybersecurity needs to be supported by financial and operational controls such as:
Independently Verify Payment Changes
Any change to bank account details should be verified using a trusted communication channel and not simply by replying to the email requesting the change.
Introduce Dual Approval
High-value payments should require approval from more than one authorised person.
Treat Urgency as a Warning Sign
Urgency is one of the most powerful tools used by social engineers. Requests such as “today only”, “keep this confidential” or “I’m travelling so please handle this immediately” should trigger additional verification.
Train Employees Using Realistic Scenarios
Generic cybersecurity training is useful, but employees should also be shown realistic examples of the types of attacks that could target their specific business.
What about Cyber Insurance?
This is where fund managers should look beyond simply asking whether they have a cyber insurance policy. Not all cyber policies provide the same protection for social engineering or fraudulent transfers.
Working with a specialist broker such as Anapi can help identify the specific cyber and financial crime exposures facing a fund manager, and assess whether the available insurance cover adequately addresses risks such as social engineering, Business Email Compromise and fraudulent transfers.
Ready to have a chat to us about your risks?



