I'm surprised I'm the first person to point this out, but you have not lost any money, your client has. You sent the goods to the client, and they have yet to remit the payment to you. So they still owe you the money and you should insist they pay it. Granted, they're not going to like that, but the reality is they sent payment due to you to some other person. That's something they did not something you did. They may…
Ask HN: Lost $10k as my email was hacked. Any ways to recover it?
41–50 of 88 posts
Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?
#42I wonder if a client has ever set up a scam like this. They send a fake-looking email to themselves (using existing invoices as a template), then feign ignorance and refuse to pay for goods/services because "we sent the money, not our fault you didn't get it". Even better that they'd send a few emails saying "we're working on paying you, don't bug us about it" -- payments are harder to collect as time passes for a nu…
Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?
#43Email headers of the fake email I received are below. Can anyone identify anything out it? ------- Received: (qmail 30963 invoked by uid 30297); 16 Oct 2018 19:04:18 -0000 Received: from unknown (HELO sg2plibsmtp01-1.prod.sin2.secureserver.net) ([182.50.144.11]) (envelope-sender ) by sg2plsmtp19-01-25.prod.sin2.secureserver.net (qmail-1.03) with SMTP for ; 16 Oct 2018 19:04:18 -0000 Received: from se1-lax1.servconfig…
Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?
#44Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?
#45Earlier quoted context omitted.
> The scammer has already accessed your account because you fell for a phishing scam > It's not your fault that they paid the wrong person. How is this not the OP's fault? It's absolutely their fault - the fault that lead to their email being compromised
I stated in the next paragraph that the situation could just as easily be reversed. We do not have any way to know in this situation whose mailbox was accessed, the OP, or their client.
Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?
#46I'm surprised I'm the first person to point this out, but you have not lost any money, your client has. You sent the goods to the client, and they have yet to remit the payment to you. So they still owe you the money and you should insist they pay it. Granted, they're not going to like that, but the reality is they sent payment due to you to some other person. That's something they did not something you did. They may…
> my client received an email from "abicde@mydomain.com" stating that there is a change in invoice and revised invoice is again sent which had bank account details of a UK bank account. Emails sent from your domain usually constitute valid contracts. If you're letting other people send emails from your domain because you don't have SPF configured then there's a good chance a court would either rule that you've allowe…
I could see the instance of an ex-employee that still can login can enter into contracts on your company's behalf, but a hacker doing so gets the same protections (for lack of a better word)?
That seems very wrong to me. I'm sure it makes things harder to determine the actual issue, but I just don't believe that a judge would look at this and conclude that fraud is ok as long as it comes from your email address...
(ignoring issues like gross negligence where a company is doing significantly less to secure their systems than should be expected)
Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?
#47I'm surprised I'm the first person to point this out, but you have not lost any money, your client has. You sent the goods to the client, and they have yet to remit the payment to you. So they still owe you the money and you should insist they pay it. Granted, they're not going to like that, but the reality is they sent payment due to you to some other person. That's something they did not something you did. They may…
> my client received an email from "abicde@mydomain.com" stating that there is a change in invoice and revised invoice is again sent which had bank account details of a UK bank account. Emails sent from your domain usually constitute valid contracts. If you're letting other people send emails from your domain because you don't have SPF configured then there's a good chance a court would either rule that you've allowe…
I think it would maybe be arguable if someone actually hacked the OP’s account and the emails really did come from their outbox, but spoofed email is a different thing entirely.
It seems more equivalent as a legal precedent to someone sending a forged letter from a nonexistent employee on similar looking letterhead. Or maybe someone showing up at the door and collecting payment wearing a stolen or counterfeit uniform.
If you think of it in legal terms, in a lawsuit say, the client would have to acknowledge the existence of a contract and an obligation to pay the supplier, and then somehow make an argument that a spoofed email from a third party that the supplier had no awareness of, that never entered the posession or control of the supplier at all, somehow invalidates that contract, or proves that the client has satisfied their obligation.
That’s quite a stretch.
Arguing negligence on the part of the supplier still wouldn’t do anything to satisfy the payment obligation, at best it would seem to be a counter-claim, saying they they suffered a loss because of the suppliers negligence, but then that’s a separate tort and the burden of proof would be on them.
Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?
#48I'm surprised I'm the first person to point this out, but you have not lost any money, your client has. You sent the goods to the client, and they have yet to remit the payment to you. So they still owe you the money and you should insist they pay it. Granted, they're not going to like that, but the reality is they sent payment due to you to some other person. That's something they did not something you did. They may…
> my client received an email from "abicde@mydomain.com" stating that there is a change in invoice and revised invoice is again sent which had bank account details of a UK bank account. Emails sent from your domain usually constitute valid contracts. If you're letting other people send emails from your domain because you don't have SPF configured then there's a good chance a court would either rule that you've allowe…
Gonna need a source on that one, chief.
Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?
#49I'm surprised I'm the first person to point this out, but you have not lost any money, your client has. You sent the goods to the client, and they have yet to remit the payment to you. So they still owe you the money and you should insist they pay it. Granted, they're not going to like that, but the reality is they sent payment due to you to some other person. That's something they did not something you did. They may…
> my client received an email from "abicde@mydomain.com" stating that there is a change in invoice and revised invoice is again sent which had bank account details of a UK bank account. Emails sent from your domain usually constitute valid contracts. If you're letting other people send emails from your domain because you don't have SPF configured then there's a good chance a court would either rule that you've allowe…
>Now on the next day my client received an email from "abicde@mydomain.com" stating that there is a change in invoice and revised invoice is again sent which had bank account details of a UK bank account. > >Now an email like "abicde@mydomain.com" doesn't exist at all.
Notice the "i", different from abcde@mydomain.com. He's saying it wasn't sent from the normal email account. The question I'd have is that OP uses "hacked" but there aren't actually any technical details here at all. Was one or the other mail servers genuinely compromised, or someone phished? Or were these emails simply spoofed? Or what? It sounds like it could have just been a forged From which is utterly trivial, every mildly serious spammer let alone spearphisher has done that forever. If the client "asked for a confirmation email" but the "email never reached" because it was a spoofed From and got blackhole'd but the client then took no response as confirmation that would probably be on the client.
Of course whatever the legal case there are other practical considerations, if this is a very valuable client then a certain amount of bending may be in order. It sounds like a pretty hokey order mechanism all around vs even just a simple HTTPS LE plain text web form and static invoice. And there is still the question of how exactly the phishing (if that's what it was) information was gathered for the spoofed invoice in the first place, insider job? Some other leak or hack?
But at least asking the client to try to get the money back seems fair enough. Money in that amount to a developed world bank should absolute be traceable. Alerting the banks and law enforcement should have been the absolutely immediate first move the instant anything amiss was realized. If it was the client's fault and the money really is gone somehow (or even will just take along while to recover) then at least splitting the different shouldn't be unreasonable.
Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?
#50Banking standards here in the EU impose a 13 months period during which the sender (order sender) can ask for a full refund. Check your local rules. This has to be talked about with the respective banks involved (that of your client + the one that received payment), as I believe you can't do anything anymore. Next time, use more than one communication channel (Facebook, phone, signal, telegram, whatsapp... anything,…
Is this really true? Do EU bank transactions really take 13 months to fully clear?