EPC183-22/Version1.0/ Date issued:23November2022Public www.epc-cep.eu1/69©2022Copyright European Payments Council (EPC) AISBL:This document is public and may be copiedor otherwise distributed provided attribution is made and the text is not useddirectly as a source of profit Report 2022Payment Threats and Fraud Trends EPC183-22Version1.0Date issued:23/11/2022 Abstract This new edition of the threatstrends report reflects the recent developmentsconcerning securitythreats and fraud in the payments landscape over the past year. Table of Contents Executive Summary....................................................................................................................51Document Information.........................................................................................................81.1Scope and Objectives.................................................................................................................81.2Audience....................................................................................................................................81.3References..................................................................................................................................81.4Definitions and Abbreviations...................................................................................................92Threats and other Fraud Enablers.......................................................................................142.1Social Engineering....................................................................................................................142.1.1Impact and Consequences.............................................................................................142.1.2Suggested Controls and Mitigation................................................................................142.2Malware...................................................................................................................................162.2.1Impact and Consequences.............................................................................................172.2.2Suggested Controls and Mitigation................................................................................172.3Advanced Persistent Threats (APT)..........................................................................................202.3.1Impact and Consequences.............................................................................................212.3.2Suggested Controls and Mitigation................................................................................222.4Denial ofService (DoS).............................................................................................................242.4.1Impact and Consequences.............................................................................................272.4.2Suggested Controls and Mitigation................................................................................292.5Botnets.....................................................................................................................................302.5.1Impact and Consequences.............................................................................................312.5.2Suggested Controls and Mitigation................................................................................322.6Monetisation Channels............................................................................................................332.6.1Impact and Consequences.............................................................................................332.6.2Suggested Controls and Mitigation................................................................................353Fraud per Payment-Relevant Process.................................................................................373.1Introduction.............................................................................................................................373.2On-boarding and Provisioning.................................................................................................373.2.1Suggested Controls and Mitigation................................................................................393.3Request-to-Pay and Invoicing..................................................................................................403.3.1Suggested Controls and Mitigation................................................................................423.4Payment Initiation & Authentication.......................................................................................43 Report2022Payments Threats and Fraud TrendsEPC183-22/Version1.0 3.4.1Suggested Controls and Mitigation................................................................................433.5Payment Execution..................................................................................................................433.5.1Sugg