The Straits Times reported today, 19 September 2026, that a healthcare company's CFO nearly transferred S$120,000 to scammers after they impersonated the firm's chairman and managing director on Microsoft Teams. The CFO only realised something was wrong when she spoke to the real managing director, who denied giving the instruction. The transfer did not go through. The S$120,000 stayed in the account.
But the story does not end there, and for most Singapore businesses reading this, the more important question is not whether the transfer was stopped. It is what would have happened if it had not been.
Business email compromise scams, which now include voice, video, and messaging platform impersonation well beyond email, reached S$57.3 million in losses in the first half of 2026, up from S$19.5 million in the same period of 2025, according to Singapore Police Force mid-year scam statistics. The number of cases rose from 156 to 262 in the same comparison period, making BEC the third-largest scam category by amount lost in Singapore.
The mechanism that nearly worked in this case was not a sophisticated technical exploit. It was two words: do it now.
How a Microsoft Teams impersonation works
In this incident, scammers created or compromised accounts that appeared to be the company's chairman and managing director and added them to a group chat on Microsoft Teams. From inside that chat, they instructed the CFO to transfer funds urgently.
The CFO had no reason to question the instruction immediately. The accounts looked right. The request came through a platform the company uses for internal communication. The urgency was framed as business-critical. The instruction came from what appeared to be senior leadership.
This is the evolution of business email compromise. The original version sent fraudulent emails from spoofed or compromised email addresses. The updated version operates inside the collaboration tools that have replaced email as the primary internal communication channel for most businesses: Microsoft Teams, Slack, WhatsApp Business, and similar platforms.
As scammers increasingly exploit messaging, voice, and video channels, including AI-enabled impersonation, to pose as trusted executives and trick employees into making fraudulent fund transfers, the attack surface has moved from the inbox to the platforms businesses use to run themselves day to day, according to cybersecurity commentary cited in The Straits Times.
The three insurance products that are relevant and how they interact
For a Singapore business whose employee receives an instruction through a collaboration platform and transfers funds to a fraudster, three insurance products are relevant. Understanding which one responds, under what conditions, and where the gaps are between them is the practical insurance question.
Social Engineering Fraud (SEF) insurance is the product specifically designed for this scenario. It covers the financial loss a business suffers when an employee is deceived by a fraudulent impersonation of a trusted party, such as a senior executive or a known supplier, into authorising a fund transfer.
SEF cover is not automatic. Most SEF policies include a verification procedure condition: the policy responds only if the insured had a pre-arranged, documented verification procedure in place and the employee followed it before authorising the transfer. The standard verification procedure is an independent callback to the requestor's known, separately confirmed contact, through a channel other than the one used to deliver the instruction, before any transfer is made.
In the Teams case, the CFO spoke to the real managing director after receiving the instruction and before completing the transfer. That independent verification stopped the loss. In a case where the transfer went through before verification, whether the SEF policy responds depends entirely on whether the company had a documented procedure in place and whether the employee followed it. A verbal understanding of always double-checking is not a documented procedure under most SEF wordings. A written protocol confirmed with the insurer is.
Cyber insurance addresses the digital access dimension of the attack. Where scammers gained access to a company's internal Microsoft Teams environment by compromising employee credentials or exploiting a configuration vulnerability, the cyber policy's coverage for unauthorised access to a computer network is engaged. The forensic investigation to establish how access was obtained, the costs of securing the environment, and the business interruption during the response are first-party cyber costs.
The interaction between SEF and cyber matters here. The SEF policy covers the fund transfer loss. The cyber policy covers the incident response costs. The two address different parts of the same event. Where a company holds both, the policies need to work together without each excluding the other's territory.
Commercial crime insurance covers dishonest or fraudulent acts, including computer fraud and funds transfer fraud, depending on the specific wording. The distinction between what commercial crime covers and what SEF covers varies by policy, and some wordings overlap. For a Singapore SME reviewing its programme, confirming which of these products covers a fraudulent transfer instruction received through an internal communication platform, and at what limit, is worth doing before an incident occurs rather than after.
You can read more about our Social Engineering Fraud cover and cyber insurance on the products page and about the earlier BEC advisory in our post on The S$15 Million LinkedIn Job Scam and What It Means for Singapore Business Insurance.
The verification procedure: the clause that decides everything
For Singapore businesses reviewing their SEF cover or arranging it for the first time, the verification procedure is the single most important element to understand and implement.
The procedure does not need to be complicated. It needs to be documented, communicated to all staff who handle payment instructions, and consistently followed. A practical procedure for a Singapore SME: any payment instruction received through email, messaging, or collaboration platforms that is outside the normal payment workflow must be verified before action is taken. Verification means placing a call to the requestor's known, separately confirmed contact number, not calling back a number provided in the instruction itself. The verification call must happen regardless of the apparent seniority of the requestor and regardless of the urgency communicated in the instruction.
The do it now framing is not a reason to skip verification. It is a reason to slow down. The urgency is the mechanism of the scam. A documented procedure that explicitly treats urgency as a flag rather than a reason to comply gives employees a framework for responding to exactly the pressure the Teams case illustrates.
Once the procedure is documented, confirm with the insurer that it meets the policy's verification condition. Get that confirmation in writing.
What the Teams case means for Singapore SMEs beyond the headline
The S$120,000 was not nearly lost because the CFO was careless. It was nearly lost because scammers operated inside the exact environment that builds trust in business communication, the internal platform, the familiar interface, the names of known colleagues, and combined it with psychological pressure that is designed to override the instinct to pause and check.
For a Singapore SME, the defence is not seniority or experience. It is a documented procedure that creates a pause between instruction and action, every time, regardless of which platform the instruction arrives on and regardless of who appears to be asking.
If you are a Singapore business owner and would like to understand whether your current insurance programme addresses the social engineering and BEC exposure your team faces, or whether your verification procedure meets the conditions of your SEF policy, we would be glad to work through it with you.
This article provides general information only. It is not insurance advice. The Microsoft Teams BEC case is sourced from The Straits Times reporting published 19 September 2026. BEC scam loss and case volume statistics sourced from Singapore Police Force mid-year scam statistics 2026. The verification procedure description reflects general market practice for SEF policy conditions and individual policy wordings vary. Policy availability, terms, conditions, and exclusions vary by insurer and product, and cover is subject to the full policy wording. Please contact TZY CO for advice on your specific situation.