Skip to main content
The state of ai impact assessment
Academic Hoax Reports Cost Firms MillionsInternal Controls & Audit
5 min readFor Internal Auditors

Academic Hoax Reports Cost Firms Millions

The Challenge

In spring 2021, compliance and legal teams at numerous companies received anonymous reports alleging serious financial misconduct, including accounting fraud and kickbacks. These reports arrived through various channels, some directly to executives and others via online systems. Due to the severity of the allegations, organizations referred them to outside counsel for investigation.

WilmerHale partners Susan Muck and Kevin Muck noticed something unusual: multiple clients had received identical reports. By June 2021, they identified the pattern and exposed a coordinated hoax. The reports were fictitious, part of an academic research project by a PhD student at the National University of Singapore (NUS). The study had been reviewed and approved by the university's Institutional Review Board.

This wasn't an isolated incident. In 2020, Harvard professor Eugene Soltes published research in the Journal of Accounting Research using a similar method. He sent fake reports of financial misconduct to 250 companies, submitting multiple scenarios to each.

The Environment and Constraints

By summer 2021, compliance officers were already stretched thin by COVID-19 challenges, including remote work risks and operational disruptions. The hoax reports added to their burden.

The timing was problematic. These reports arrived as the SolarWinds hack was making headlines. Compliance teams couldn't ignore the possibility of coordinated attacks. Some organizations feared malware or phishing attempts embedded in the reports.

The nature of the allegations made them impossible to ignore. Financial misconduct reports trigger specific obligations under the Sarbanes-Oxley Act for public companies. Allegations of accounting fraud require immediate escalation to audit committees and often demand self-reporting to the SEC before internal investigations conclude.

Compliance teams faced a dilemma: the reports contained serious allegations but lacked the detail needed to substantiate or dismiss them quickly. As NUS later acknowledged, "The claims brought forth were completely fictitious and deliberately did not bear enough details to necessitate the launch of an investigation." This miscalculation proved costly.

The Approach Taken

Organizations followed standard protocols for serious allegations. They engaged outside counsel, allocated investigative resources, and briefed audit committees. Some external auditors, skeptical of the reports' authenticity, required additional validation.

WilmerHale's pattern recognition broke the case open. When a client received an email from someone claiming to be a PhD student at NUS, explaining the report was part of research, the firm pursued verification. NUS eventually confirmed the study's termination and assured that no data would be used.

NAVEX Global, whose platform was used for some submissions, published warnings and recommended temporarily restricting public web access to reporting links. This was a significant step, potentially limiting legitimate reporting, but the cybersecurity risk seemed real.

Multiple law firms issued client alerts. TheCorporateCounsel.net ran a poll asking readers to guess the endgame; two-thirds suspected malware or phishing.

Results and Metrics

The financial impact remains unmeasured but substantial. Engaging outside counsel to investigate serious financial misconduct claims costs thousands of dollars per case. With Professor Soltes' research involving 250 companies and the NUS study likely on a similar scale, the total expense runs into millions.

This calculation covers only direct legal costs. It doesn't account for:

  • Internal compliance and legal team time diverted from authentic investigations
  • External audit fees for skeptical auditors
  • Potential SEC self-reporting triggered by fraud allegations
  • Skewed compliance metrics before discovery
  • Lost productivity from executives and board members briefed on nonexistent misconduct
  • Reduced reporting system availability for organizations that restricted access

For organizations under enforcement actions, the cost included mandatory reporting to regulators before completing internal investigations, forcing agencies to review fictitious allegations.

The broader impact on trust in reporting systems is harder to quantify but potentially more damaging. When executives and board members realize they've spent significant resources investigating hoaxes, their confidence in the reporting mechanism erodes, affecting future support and potentially delaying responses to legitimate reports.

What They Would Do Differently

The researchers' fundamental error was assuming sparse detail would prevent substantive investigation. Both the NUS student and Professor Soltes designed their fake reports to lack specifics, believing this would limit response. The opposite occurred: serious allegations with minimal detail often trigger more extensive investigation because organizations must rule out significant risk with limited information.

Professor Soltes' research acknowledged concerns around fraudulent misrepresentation but concluded the scenarios were "designed in a way to make it unlikely that a firm could engage in a substantive or costly investigation without additional information." This assumption failed to account for regulatory obligations and audit committee oversight.

NUS characterized the impact as an "inconvenience," revealing a disconnect between academic research design and operational reality.

Takeaways for Your Team

Institutional Review Board approval doesn't insulate you from harm. The Harvard IRB deemed Professor Soltes' research "not human subject research" because it targeted firms rather than people. This distinction misses the point: real people staff those firms and bear the cost of responding to fictitious allegations.

Build pattern recognition into your intake process. WilmerHale identified the hoax by noticing identical reports across clients. If you're managing investigations across business units or coordinating with peers, share metadata about report patterns. Identical language or coordinated submissions can signal campaigns.

Document your investigation triggers and thresholds. When you receive a serious allegation with minimal detail, your protocol should specify the level of inquiry before escalating. This doesn't mean dismissing sparse reports, it means having a structured triage process to prevent every vague allegation from triggering maximum response.

Recognize that your reporting system is infrastructure, not just a compliance checkbox. These hoax campaigns showed that reporting systems can be exploited. Your cybersecurity team should understand submission pathways and potential attack vectors. Your business continuity planning should account for scenarios where you need to restrict access.

The academic community needs to reconsider research methodologies that impose unmeasured costs on third parties. If your organization participates in academic research, ask about their IRB review process and whether it accounts for operational impact. The fact that this methodology appeared in peer-reviewed journals suggests the academic ethics framework hasn't caught up to the operational reality of compliance programs.

Most importantly, when researchers claim their fake reports were designed to avoid triggering costly investigation, they're demonstrating they don't understand how compliance programs work. That misunderstanding should disqualify the methodology, not excuse it.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like