What it means
Eavesdropping, also called sniffing or snooping, works by capturing data as it travels between two points. The attacker might tap into an unprotected wireless network, install malicious software on a device or place a rogue device on a network.
Because the communication itself usually continues as normal, the victims often do not notice anything. The information at risk is wide-ranging.
It can include login details, payment card numbers, invoices, email conversations about payments and confidential plans. A finance team is a particular target, because intercepted payment instructions can be used to commit fraud, for example by changing the bank account on a genuine invoice.
Common settings for attacks include public Wi-Fi in cafes and airports, poorly protected office networks and unprotected voice or video calls. Attackers may also use a fake wireless hotspot that looks genuine, so that anyone who connects sends their data through the attacker's device.
Employees who work remotely increase the exposure unless their connections are secured. Defences focus on encryption, which scrambles data so that intercepted information is unreadable without the key.
Companies use secure website connections, encrypted email, virtual private networks (VPNs), strong wireless security and multi-factor authentication. They also train staff to avoid public networks for sensitive work and to verify any change in payment details by calling a known number.
Eavesdropping differs from hacking into a system in that the attacker is usually passive, listening rather than changing anything. This makes detection harder, and the harm often appears later, when stolen details are used.
Businesses should treat prevention as part of their risk management and their duty to protect customer data. There are financial consequences beyond the immediate theft.
A data breach can lead to regulatory fines, legal claims, higher insurance premiums and lost customer trust, all of which dwarf the cost of basic security. Finance leaders should therefore treat security spending as protection of the balance sheet, not as an optional extra.
In practice
Real-world examples.
Example
A finance manager uses free airport Wi-Fi to approve a $75,000 supplier payment. An attacker on the same network captures her login details and later accesses the company's banking portal. The company discovers the problem only when its bank queries an unusual payment.
Example
A law firm sends an unencrypted email containing the account details for a property purchase. A criminal who has been reading the email traffic changes the account number and diverts the buyer's $400,000 deposit. By the time the error is found, the criminal has moved the funds to other accounts.
Example
A retailer sets up a payment terminal that sends card data without encryption. A person who has hidden a device in the shop network collects hundreds of card numbers over several weeks. The retailer later faces fines and the cost of reissuing the cards.
Case study
Seen in the real world.
Pinecrest Engineering is a fictional firm with 80 employees. One of its project managers regularly worked from a coffee shop, using the open wireless network to access the company's accounting system. Unknown to him, an attacker nearby was capturing network traffic.
The attacker obtained his login and, a few days later, emailed the accounts team a message that appeared to come from a regular supplier, asking them to change the bank details for an invoice of $62,000. The money was paid to the wrong account before anyone noticed.
This illustrative case led Pinecrest to require a VPN for all remote work, to use multi-factor authentication and to confirm any change in bank details by phone. The firm also set a rule that payments over $10,000 need a second approver, which made a repeat of the loss much less likely. The firm also notified its bank and its insurer as soon as the fraud was discovered.
Watch out
Common mistakes.
- Using public Wi-Fi for banking or payment approvals without a VPN or other protection. Even a short session can expose login details to anyone nearby.
- Sending sensitive financial details by unencrypted email, where they can be intercepted. A secure portal or encrypted attachment is a safer route.
- Assuming that a connection with a familiar network name is safe, when attackers can copy network names.
Questions
People also ask.
What is the difference between eavesdropping and phishing?
Eavesdropping secretly listens to communications, while phishing tricks people into handing over information or money.
Does encryption stop eavesdropping?
It does not stop interception, but it makes the captured data unreadable without the key, which removes most of the value to the attacker. Strong, up-to-date encryption methods matter, because old ones can be broken.
How can I tell if I have been a victim?
It is often hard to detect, so look for unusual account activity, unexpected password resets and payments you did not authorise, and report any concerns to your IT team. Acting quickly can help a bank recall a payment before the money disappears.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%Related
