A fraudster got $12M out of a Canadian university
1–10 of 119 posts
Re: A fraudster got $12M out of a Canadian university
#2Re: A fraudster got $12M out of a Canadian university
#3This seems like a technology problem, not a personnel problem. There should be more checks in a system when you are changing bank accounts where so much money is going to be deposited.
Re: A fraudster got $12M out of a Canadian university
#4I suppose business dealings between the university and contractors is public to some extent, but it seems plausible that this attack came from within the university or the contractor.
Re: A fraudster got $12M out of a Canadian university
#5This seems like a technology problem, not a personnel problem. There should be more checks in a system when you are changing bank accounts where so much money is going to be deposited.
Really? It is pretty obvious that it is social engineering. Can't you check the email domain?
Re: A fraudster got $12M out of a Canadian university
#6This seems like a technology problem, not a personnel problem. There should be more checks in a system when you are changing bank accounts where so much money is going to be deposited.
Re: A fraudster got $12M out of a Canadian university
#7Apologies if it was mentioned in the article, but I am curious as to how the original attacker acquired the information needed for spear phishing. I suppose business dealings between the university and contractors is public to some extent, but it seems plausible that this attack came from within the university or the contractor.
Re: A fraudster got $12M out of a Canadian university
#8Earlier quoted context omitted.
Really? It is pretty obvious that it is social engineering. Can't you check the email domain?
From the article: the email was spoofed to appear to be from the building company.
There were many red flags that weren't caught, this being one of them.
Re: A fraudster got $12M out of a Canadian university
#9This seems like a technology problem, not a personnel problem. There should be more checks in a system when you are changing bank accounts where so much money is going to be deposited.
> As a result, one particular email, sent June 27, didn’t set off any alarms. Sent by a James Ellis of Clark Builders, a construction company working on the project, the email opened with the affable “Hiya” before asking the school’s accounts receivable department to reroute payments to a new National Bank of Canada account.
The order to change bank accounts should not have been trusted without another factor of authorization, such as a phone call (from the CFO's office) or an in-person confirmation. Yes, a software solution could be implemented to enforce this process, but that doesn't seem worth the time or effort and provides yet another vector of attack. The university, being a public institution, likely already has a legacy system of paperwork and manual processes. It should be less work to enforce existing rules or add an old-fashioned verification step than to build a new software system. Especially for something as rare as changing bank account numbers.
edit: at the end of the article, it seems that the university's solution has indeed been to go for old-fashioned verification:
> Employees are now required to verify all changes to vendor files by phone and a followup email, and all financial changes must first be reviewed by a supervisor, manager or director. A supplied audit report system was also implemented, tracking every change made to vendor files. The university has made employee training in social engineering attacks, phishing and other online scams mandatory.
I think the social engineering training is key, though. An employee could still follow the above rules and still be fooled, based on the letter used in the phishing attack:
https://www.thestar.com/content/dam/thestar/edmonton/2018/10...
I'm assuming a supervisor or manager don't have a special ability to know the vendor's actual financial details, and thus a "review" may be little more than a rubber stamp. What's key is that the office person fielding the request not only use a second form of authentication -- such as a phone call -- but that they call the number as recorded on university file and not the phone number listed in the spoofed email.
Re: A fraudster got $12M out of a Canadian university
#10Apologies if it was mentioned in the article, but I am curious as to how the original attacker acquired the information needed for spear phishing. I suppose business dealings between the university and contractors is public to some extent, but it seems plausible that this attack came from within the university or the contractor.
This was the real breach. Bank account numbers, company letterhead, the CFO's signature, these were all gathered before any attack took place!
I agree with the original comment - how did these scammers gain the knowledge that these transactions were ongoing, and know exactly who to target?