From my experience of working in corporate Kenya, I consider employee theft as one of the biggest risks facing businesses. In fact, according to a recent report by the Kenya National Bureau of Statistics the number of Kenyan workers convicted for employment related offences rose by 60% last year. Similarly, a recent Microsoft Security Intelligence Report noted that in 2018, the incidences of cybercrime in Kenya rose by 167%.
Types of Employee Theft
1. Skimming: also known as “off the books theft”, it arises whenever an employee steals monies or assets prior to book entry posting.
2. Larceny and Embezzlement: Larceny occurs where there is outright theft of a firm’s assets by a person who is not in authority for such assets. For example, a store clerk or cleaner may steal cash from the cash register while the cashier is away. In contrast, embezzlement arises in situations where an employee is entrusted with authority over assets and decides to misuse such authority. Thus, in the preceding example, embezzlement would arise if the cashier were to steal the cash as opposed to the cleaner.
3. Theft of Time: Employees can also steal their employer’s time through failing to put in requisite hours of work. As a result, the productivity and output of the organisation becomes seriously hampered.
4. Cybercrime: Cyber crimes or computer related crimes can be broadly categorised into two areas. The first relates to crimes that target networks and computer devices. The listing below provides some examples of crimes under this category.
- Distributed Denial of Service (DDOS) attacks – these are malicious attacks on user networks. They arise when hackers incessantly drive lots of unauthorised traffic through the user’s site to the point where the network becomes overwhelmed. Eventually the hacker gains unauthorised access to user systems.
- Malware – malicious software that tries to attack a computer system. It includes viruses, worms, Trojan horses etc
- Ransomware – occurs when malware attacks or threatens attack on a computer system until specified ransom is paid to the attackers.
- Phishing – this crime involves hackers sending malicious email attachments or URL’s to users to gain access to their computing devices.
- Identity Theft: arises where unauthorised users gain illegal access to users’ personal information and use such information to steal or commit fraudulent activities . The stolen information may include computer credentials, national identification numbers, phone numbers, etc.
- Fraudulent Disbursements – here, employees embezzle funds by working around a firm’s financial system. For instance, they may authorize wire transfers to fake customer of vendor accounts or forge signatures to process payments.