Skip to main content
Welcome to Deloitte

If we have selected the wrong experience for you, please change it above.

The cost of fraud: Protecting your business from threats outside and within

The latest fraud risk data and what it means for your organisation

Fraud is costing Malta's businesses millions every year, cutting across sectors and organisation sizes. According to the Association of Certified Fraud Examiners (ACFE) 2026 Report to the Nations, organisations globally lose a median of 5% of revenue to fraud annually. For Malta's business leaders, where fraud prevention controls remain underdeveloped, the exposure is particularly acute.

The approach to fraud risk needs to shift from a post incident reaction to a risk managed one. Fraud loss is becoming increasingly material and common. When a fraud is perpetrated on your business, it can be devastating. Investment in prevention will always be more cost effective than trying to deal with the consequences after fraud occurs.

Ian Coppini, Partner, Strategy, Risk & Transactions at Deloitte Malta

The numbers tell a sobering story

The 2026 ACFE report analysed 2,402 fraud cases across 143 countries. The findings are stark:

  • Median loss per case: $104,000.
  • Average loss per case: $1.46 million.
  • Typical fraud duration: 12 months before detection.
  • 5% of organisational revenue lost annually to fraud globally.

A €500,000 fraud related loss for a €10 million turnover business is material hit to profitability and shareholder value. But the financial loss is only part of the story. Fraud also brings reputational damage, potential regulatory implications and operational disruption that can linger long after discovery.

The insider threat

Asset misappropriation is the most common fraud type, occurring in 90% of cases with median loss of $100,000. These schemes involve theft of cash, inventory, or company property. Many organisations dismiss stock theft as acceptable shrinkage, but a lax approach invites fraudsters to escalate their behaviour. Corruption is also prevalent; it appears in 45% of cases with a median loss of $150,000. (Note: a single fraud case can include more than one fraud type).

The most damaging internal threat is financial statement fraud (6% of cases), with a median loss of $1 million, a 31% increase from 2024 and a 69% increase from 2022. While often associated with listed companies seeking to inflate stock prices, financial statement fraud also occurs in private firms and family businesses, where owners manipulate financials to secure loans, hide profits, or evade taxes. These fraud schemes involve deliberate manipulation of financial records and typically originate from trusted senior figures with authority and discretion.

The data shows that fraud perpetrated by owners and senior executives are nine times greater in value than those perpetrated by employees. This disparity reflects a fundamental governance challenge for business leaders. In Malta, where many organisations have evolved from family businesses, familiar trust is often a central element of business culture. However, issues can arrive where trust is misinterpreted as "blind trust" and a trusted person is allowed to execute their functions without any external validation or oversight. In mature fraud prevention frameworks, trust and transparency work together. Oversight is good governance, not a sign of insufficient confidence.

The external threat

External cyber-enabled fraud is rising in sophistication and frequency. In 2024, one Maltese bank reported 23 cases of Business Email Compromise (BEC) fraud totalling €1.5 million in losses. These attacks are deliberate and calculated. Fraudsters gain access to email systems, monitor communications, then strike at critical transaction moments. They typically intercept payment instructions just as funds that are about to be transferred. By the time the fraud is discovered, money has been diverted to accounts in other jurisdictions.

Beyond BEC, organisations face a growing array of often multipronged external threats:

  • Phishing and spear-phishing attacks trick employees into revealing credentials or transferring funds.
  • Invoice fraud schemes involve fake or altered invoices sent to accounts payable departments, exploiting the trust placed in vendor relationships.
  • Vendor and supplier fraud, including false billing and non-delivery of goods, can disrupt operations and drain resources.
  • Social engineering scams impersonate executives, customers, or partners to manipulate staff into authorising unauthorised transactions.

The sophistication of these attacks is accelerating as cyber criminals gain access to artificial intelligence tools enabling deepfakes, voice cloning, and highly targeted campaigns. SMEs are particularly vulnerable: most lack the resources to scale cybersecurity infrastructure proportionately and are increasingly targeted by criminals with AI-enhanced capabilities.

Anti-fraud controls and prevention measures

More than half of all frauds involve weak or overridden internal controls: 32% occur due to lack of controls, 19% from override. When controls are absent, median losses are 43% higher than average. Organisations that implement proactive fraud prevention measures significantly reduce both financial impact and duration. The most effective controls include:

  • Management review: 55% reduction in median loss, 44% faster detection.
  • Proactive data monitoring and analysis: 53% reduction in median loss, 44% faster detection.
  • Surprise audits: 50% reduction in median loss and duration.
  • Fraud awareness training: Reduces median losses from $150,000 to $84,000.
  • Whistleblowing hotlines (with fraud awareness training): Reduces median losses from $175,000 to $85,000.

Organisations with formal reporting mechanisms detect fraud 6 months faster on average (17 to 11 months). Behavioural red flags offer another detection opportunity: 84% of fraudsters display at least one observable red flag such as living beyond means, financial stress, unusual vendor relationships, control issues, or defensiveness about transparency. In Malta's business community, these warning signs are sometimes dismissed as personal matters rather than fraud indicators.

SMEs should start with the basics: segregation of duties, a confidential reporting mechanism, and fraud awareness training. These foundational controls don't require large investments but deliver measurable protection.
 

The path forward: a C-level imperative

Fraud prevention is a governance responsibility led from the top. Organisational culture flows from leadership: when the CEO and board prioritise fraud prevention and demonstrate genuine commitment to transparency and accountability, the broader organisation follows. The first step is an assessment to understand specific vulnerabilities, actual and potential losses, and where fraud risk is most likely. This data-driven approach enables targeted, right-sized prevention investments. Malta's business leaders must decide whether they will invest in targeted prevention measures or deal with the far more expensive and disruptive consequences of fraud after it occurs.

Deloitte's fraud risk management services help organisations assess fraud risk, design and implement prevention controls, and respond effectively to incidents. We offer comprehensive support tailored to each organisation's specific vulnerabilities and risk profile. The time to act to protect your business is now.
 

Did you find this useful?

Thanks for your feedback