But help is available to vulnerable firms. Here's how to stay safe.
Kimberly Redmond//October 6, 2025//
PHOTO: DEPOSIT PHOTOS
PHOTO: DEPOSIT PHOTOS
But help is available to vulnerable firms. Here's how to stay safe.
Kimberly Redmond//October 6, 2025//
If you’re a small business owner in New Jersey, there’s a good chance someone may try to scam you. From fake vendor invoices to AI-generated imposters to spoofed emails, local companies are facing a growing wave of financial fraud that’s costing them time, money and business.
Cybercrime is hitting New Jersey-based ventures harder than ever, with the state ranking fifth nationwide in total cybercrime losses in 2024, according to the FBI’s annual Internet Crime Report. Last year, victims reported losing over $435 million. That figure includes a range of schemes like phishing emails, texts and phone calls; deepfake voice and video impersonations; wire fraud and cryptocurrency schemes.
Experts warn that rising breach costs, driven by phishing, ransomware and insider threats, make proactive security essential. But small and mid-size companies are vulnerable because they typically lack dedicated IT staff or fraud prevention tools of bigger organizations.
When it comes to cyber insurance, coverage gaps remain. According to a 2024 report by the U.S. Government Accountability Office, roughly 60% to 70% of U.S. companies now carry some form of cyber insurance, a steady increase from just under 50% a few years ago. Adoption is highest among large corporations and sectors like finance and health care. But, at smaller ventures, less than half have coverage due to barriers such as cost, the study found.

Ahead of Cybersecurity Awareness Month in October, NJBIZ spoke with Ken Helmrich, a senior vice president at Fairfield-based Kearny Bank, about the trend, as well as ways small businesses can protect themselves.
A certified financial crimes specialist, Helmrich is responsible for managing the institution’s Bank Secrecy Act /Anti-Money Laundering (AML) and Office of Foreign Assets Control (OFAC) compliance program, including client due diligence, enhanced due diligence for higher risk clients, transaction monitoring, case investigation and BSA reporting.
“Every once in a while, there will be a news article published about some kind of big incident and then it’s all anybody talks about for a few weeks. But then it dies down and everybody kind of waits for the next incident … We do have a few businesses that are a little bit more proactive in the attorney space. I think that’s because they’ve been targeted so hard … So they meet and talk as an industry more often than some of the other groups. But by and large, I think it’s still been very reactionary.”
“I think a lot of times fraud prevention takes a back burner until it’s too late,” Helmrich said. “Until you’ve been hit with an incident of fraud and you’re out a couple hundred thousand dollars, that’s when it really sinks in that, ‘Man, we should have been doing something about this all along.’”
I think a lot of times fraud prevention takes a back burner until it’s too late.
– Ken Helmrich, SVP, Kearny Bank
“Even if an incident like this has never happened at your business before, you should have some sort of plan for how you’re going to respond if and when something does happen,” he said.
“I think what a lot of businesses can and should do is look to similar examples of similar businesses to their own and what’s happened to those businesses when they’ve been hit by data breaches or business email compromises or whatever,” he said. “And then take a page from their book and do some of the preparation beforehand.”
On a national level, the FBI reported a record $16.6 billion lost to cybercrime in 2024, a 33% year-over-year increase. Of the losses, $6.57 billion stemmed from investment fraud, $2.77 billion came from business email compromise and $1.46 billion from tech support scams.
Americans aged 60 and older were hit hardest, with more than 147,000 complaints and nearly $4.9 billion in losses. However, ransomware attacks against critical infrastructure like health care, manufacturing and government services increased 9%, the report noted.
Just a few locally known entities that experienced some type of cybersecurity incident over the past year include Cooper University Health Care, Aldi, Rite Aid, American Water and the City of Hoboken.
According to IBM’s Cost of Data Breach Report, the average cost of a data breach for a U.S.-based organization last year was $9.48 million. Smaller companies typically experienced losses of around $2.98 million while mid-sized companies averaged between $4 million to $5 million.
For its analysis, IBM considered direct costs, such as detection, legal fees, customer notification and system recovery, as well as indirect impacts like reputational damage, customer churn and operational downtime.
Of the 200 executives who participated in a recent survey by software developer Trustpair, 90% said their companies were targeted by cyber fraud in 2024. That’s up from 73% the prior year.
Business email compromise, wire transfer schemes and imposter scams were among the top tools used by fraudsters against businesses (63%), however the use of generative AI tactics, like deepfakes and voice cloning, is on the rise, the report said.
Among other findings, the study revealed that vendor fraud (69%) and wire transfer fraud (63%) are the top two fraud categories targeting companies — and the type that businesses said they are least prepared to deal with.
Only 9% of executives said fraud prevention should be the responsibility of multiple departments. Less than half say they have segregation of duties in place across teams involved in payments (45%) or that they collaborate across procurement, accounts payable, finance, treasury and IT (47%).
In addition, nearly 70% of companies still use manual methods, such as human callbacks or emails, to handle bank account verification, which risks payments being sent to the wrong party. Only 31% use an automated account validation tool and just 8% check supplier credentials across all stages of the procurement process.
And outside of financial losses, the reputational impact with customers (53%), investors (49%), and vendors and suppliers (48%) is what keeps most executives up at night.
The fraud landscape is constantly shifting. … Companies need to stay vigilant and can’t afford to be complacent with their defenses.
– Baptiste Collot, Trustpair CEO and co-founder
Although 43% of companies said they invested in fraud awareness training over the past 12 months, they reported that one of the biggest challenges is that employees don’t always follow fraud prevention policies.
Commenting on the report, Trustpair CEO and co-founder Baptiste Collot said, “While many executives express confidence in their organizations’ ability to identify sophisticated fraudsters, nearly the same percentage said their organizations experienced successful attacks, indicating the confidence is misplaced.”
“The fraud landscape is constantly shifting. Macroeconomic factors such as economic volatility (47%) and geopolitical uncertainty (31%) are expected to add to the pressure in 2025 and create conditions that increase organizations’ vulnerability to fraud. Companies need to stay vigilant and can’t afford to be complacent with their defenses,” he said.
Helmrich said, “Probably the biggest one lately has been business email compromise. We see this a lot, and it affects various industries – lawyers, doctors, financial professionals. Anyone with an email address. We’ve seen business email compromise scams targeting convenience store owners. Fraudsters cast a wide net. They’ll try a hundred times and if it hits once, it was worth it for them.”
He recalled an incident at a company nearly a decade ago, when BEC scams were “still kind of new and there wasn’t much awareness of it.”
“An employee did a $4 million wire transfer to an offshore overseas account thinking they were doing it at the behest of their boss, and all of it was fake. The money was gone later that day. And unfortunately, I think the employee ended up getting fired,” he said. “We see businesses with complex supply chains get targeted a lot in businesses that have a lot of complex transactions. People with international activity, we see them targeted definitely more often than not.
“We see imposter scams a lot too, where somebody will contact a business and either claim to be from the bank or claim to be from a software provider or any number of companies they might work with. And, through social engineering and things like that, they’ll either get information out of them or get the employee to do some kind of transfer or perform some kind of action,” Helmrich said.
“Another big one we see, particularly in small businesses, is that one person handles the entire process. They’re taking the call from the customer, they’re entering it into some system, they’re producing an invoice, they’re approving the transaction, they’re doing every step along the way. So, segregating those duties a little bit and having some dual control and some other folks looking at things before they go out the door can help stop a lot of this kind of stuff,” he said.
For its personal banking customers and business clients across New Jersey and New York, Kearny Bank has a “pretty robust money laundering and anti-fraud systems in place,” Helmrich said.
“One of the things we’re proud of at Kearny is that we leverage technology as much as our really bigger counterparts. So, we use things like various systems for automated monitoring. We’re leveraging AI in a couple of instances. We do data analytics. We like to think that we’re a little bit ahead of the curve in terms of the stuff that we’re doing and the stuff that our peers are doing,” he said.
Kearny also offers tools like Positive Pay, which flags suspicious checks before they’re cashed and real-time transaction alerts to catch unusual account activity as it happens. Business customers also can take advantage of multifactor authentication, customizable debit card controls and advanced treasury services to keep their finances secure.
“We do what we can to try to put as many tools as we can in the customer’s hands,” Helmrich said. “We also try to do a lot of work to educate our customers and let them know what’s going on out there, what kind of threats are they facing.”
On its website, Kearny Bank’s Security Center provides straightforward tips for businesses on how to spot scams, protect employee data, and avoid common schemes like phishing emails and fake vendor invoices. And, if something does go wrong, the bank has dedicated fraud support to help customers respond to the situation.
Along with strengthening internal controls, adopting fraud detection tools and training employees, Helmrich said it’s crucial for companies to look at who they are doing business with.
“If you’re working with other partners and vendors, make sure you understand what those businesses are, what their controls are, what they’re doing to protect you and your business. And then also taking steps to make sure you understand who your clients are,” he said.
“I can’t tell you how many times we’ve seen businesses be targeted by different scams … and when we ask them, ‘Well, how did this all start?’ they will say, ‘Oh, I got an unsolicited email that I just responded back to.’”
If you’re working with other partners and vendors, make sure you understand what those businesses are, what their controls are, what they’re doing to protect you and your business.
– Ken Helmrich, SVP, Kearny Bank
“I understand that a lot of business is generated from those kind of cold calls and things like that, but you really have to make sure you know who you’re doing business with before you start taking steps to make transfers and things like that,” he said.
Also, Hemrich said, “The tone from the top, particularly in a small business, is really important. The culture that the owners and managers are establishing does trickle down. So, I’d tell business owners to model the behavior they want to see in their employees. If you don’t want them answering off-hours emails requesting wire transfers, don’t send off-hours emails requesting wire transfers. That tone from the top, I think, is critically important.”
Beyond that, Helmrich stressed the importance of having a cyber incident response plan in place that includes how to report it.
Under New Jersey’s Identity Theft Prevention Act, businesses that experience a data breach involving personal information are required to report the incident to the New Jersey State Police Cyber Crimes Unit before notifying affected individuals. If more than 1,000 people are affected, companies must also notify major consumer credit reporting agencies.
Public agencies and government contractors face even stricter rules. They must report any cybersecurity incident within 72 hours to the New Jersey Office of Homeland Security and Preparedness.
Companies are not legally required to report incidents like attempted hacks or ransomware with no data theft but are encouraged to notify the New Jersey Cybersecurity and Communications Integration Cell. A division within the New Jersey Office of Homeland Security and Preparedness, the NJCCIC plays a key role in threat sharing and offers resources to help organizations respond to and prevent future attacks.
Nonetheless, reporting gaps persist, especially among small and mid-sized businesses, due to a lack of awareness, reputational concerns or misunderstanding of legal obligations. Reporting is also inconsistent among companies without formal cybersecurity plans or cyber insurance.
Helmrich suspects some incidents may go unreported because businesses may feel embarrassed about being victims.
“I think a lot of times you hear about these scams and you go, ‘How could somebody fall for that? How could you be so gullible?’ But then when you get the email and you’re looking at it, it’s the middle of your workday — you can fall for these kinds of things,” he said. “People don’t want to admit that they fell for something, they don’t want to look gullible. With the business, it’s no different, particularly a small business where it’s maybe one or two principles, they think it’s easier to not report these types of incidents.”