Some good news: our filters blocked about 215 phishing emails aimed at OV this week, and no accounts were compromised. But around 97 still slipped into inboxes. Those are the ones where you're the last check. If something looks off, you're probably right. Send it my way and I'll take a look.
For the finance team
"Update my direct deposit" or a vendor's "new bank account."Confirm any direct-deposit or vendor bank change by phone, on a number from your own records. Not the email, and not the invoice.
Rushed "boss" payments, gift cards, quarantine releases.Confirm odd payment requests with the person directly. Never buy gift cards off an email. If a held message is one you wanted, send it to me before releasing it.
For the investments team
Fake capital calls.Real-looking notice, tight deadline, a "new" account. Verify every capital call and any wire-instruction change with the GP or fund admin on a number from your own records, before anything moves.
Deal and data-room "opportunity" emails.Links can lead to a fake login page. Don't sign in from the email. Go to the portal directly, and be extra suspicious of unsolicited offers.
For the real estate team
Wire fraud around closings.Fake "updated wiring instructions" that look like the title company or lender. Follow our verification steps every time, confirm on a known number, and be most careful right before a closing.
Fake "review and sign this document" emails.DocuSign, Adobe, or SharePoint lookalikes with a button to a fake login page. Go to the service directly instead of clicking, and check the sender is real.
Spot it and flag it
If you see this…
It might be…
Do this
A rushed, secretive request from a "boss" or partner
Impersonation / BEC
Confirm directly (call or ask in person)
A capital call or fund wire to a "new" account
Investment fraud
Verify the GP (a number you already have)
A login-approval push you didn't start
Stolen password
Deny it and tell Chris
"Update my direct deposit" / "our bank account changed"
Payroll or vendor fraud
Verify the person (on a known number)
"Buy gift cards and send me the codes"
Always a scam
Never do it and flag it
"A document is ready to review / sign"
Fake-login phishing
Don't use the link (go to the site directly)
A QR code leading to a sign-in page
Quishing
Don't scan (type the address yourself)
"Your wiring / payment details have changed"
Wire fraud
Follow the wiring steps (verify, don't shortcut)
Anything that just feels "off"
Trust that instinct
Ask Chris (no question is too small)
To flag something: in Outlook use the Report button and choose Report phishing, or just forward it to me. You won't be blamed for flagging something harmless. And if you think you already clicked a link or typed a password, tell me right away. The sooner I know, the more I can do.