The Employee Benefits Security Administration clarified in September 2024’s Compliance Assistance Release No. 2024-01 that the DOL’s cybersecurity guidance issued in 2021 applies to all employee benefit plans, including apprenticeship plans. This means apprenticeship plan fiduciaries are responsible for implementing cybersecurity practices to prevent cyberattack or cybercrime incidents. Funds Transfer Fraud is a particularly dangerous type of cybercrime for benefit offices.
In Funds Transfer Fraud, someone tricks a person or organization into electronically transferring money to the wrong account, usually controlled by the individual perpetrating the fraud. It’s especially common with wire transfers, ACH payments, and real estate closings, but apprenticeship funds and other Taft-Hartley plans — especially self-administered plans — can be subject to it.
Common types of Funds Transfer Fraud:
Business Email Compromise
A criminal hacks an executive or vendor and asks you to redirect a payment, often saying something like, “we changed our bank account information, please send payment here…”
Vendor Payment Fraud
A criminal poses as an existing vendor and requests updated ACH or wire details. They use this to route future invoices to the scammer.
Payroll Diversion
A criminal impersonates an employee or participant and requests a direct deposit change for benefit payments or employee wages.
Romance or Social Engineering
A criminal builds personal trust and requests urgent wires for emergencies.
Funds Transfer Fraud is difficult to recover from because wires settle quickly, and criminals often move the money rapidly through multiple accounts.
The best way to prevent Funds Transfer Fraud is to train staff and training directors on how to identify it. This includes implementing policies requiring mandatory call-back verifications for payment changes, dual approval of wire transfers, and segregation of duties to ensure that a select few staff members have the authority to provide payment and wire information.
It’s also highly recommended that apprenticeship plan fiduciaries implement or attempt to implement the DOL’s Cybersecurity Program Best Practices to the best of their abilities. These best practices include having a well-documented cybersecurity program, conducting risk assessments, having controls and procedures in place, conducting periodic cybersecurity training, encrypting sensitive data, and having a cybersecurity incident response plan. It is also important to work with your insurance broker to ensure that your cyber liability insurance provides maximum coverage for Funds Transfer Fraud, including social engineering coverage.
Implementation of all the DOL’s cybersecurity best practices and guidance can be cost prohibitive to many apprenticeship plans. However, awareness is the most important factor to cybercrime prevention, so apprenticeship plan fiduciaries and training directors should make cybersecurity awareness training and Funds Transfer Fraud awareness training for their staff a priority.

Why does this matter?
Fiduciaries of apprenticeship plans who do not take steps to prevent Funds Transfer Fraud and other cybercrimes could be personally liable for the consequences. It is vital for training directors and Boards of Trustees to work hand in hand to ensure that they do the following:
Have the right team in place. The fiduciaries should have experienced legal counsel, a cybersecurity vendor familiar with benefit plans, a banker and bank that offer appropriate fraud protection options, and an insurance broker that understands benefit plans as part of their team to best protect plan assets.
Review all service providers’ IT and cybersecurity practices periodically in accordance with DOL policies and ensure staff are trained to identify Funds Transfer Fraud risks.
Implement the DOL’s cybersecurity best practices to the best of your abilities (or even go beyond!) to ensure plan assets are protected.
Filter articles

The Department of Labor emphasizes the importance of cybersecurity for those responsible for plan-related IT systems and data.
Don’t leave your prudent process to chance. Reasonable safeguards, independently checked and documented — Cyber Prudence™ for union funds.