This is why all staff, whether at a corporation, nonprofit or government that handle money should be put through a two hour anti-phishing training course. There's lots of good free training material out there. There are also services which you can hire. You give them a list of staff emails, and they send test phishes to everyone. Those who respond or click on links (there's a GUID in each phish) can be sent for furth…
A fraudster got $12M out of a Canadian university
21–30 of 119 posts
Re: A fraudster got $12M out of a Canadian university
#22This is why all staff, whether at a corporation, nonprofit or government that handle money should be put through a two hour anti-phishing training course. There's lots of good free training material out there. There are also services which you can hire. You give them a list of staff emails, and they send test phishes to everyone. Those who respond or click on links (there's a GUID in each phish) can be sent for furth…
Re: A fraudster got $12M out of a Canadian university
#23Earlier quoted context omitted.
This was the real breach. Bank account numbers, company letterhead, the CFO's signature, these were all gathered before any attack took place!
Bank account numbers weren't leaked - the scammers simply requested the payments be rerouted to a different account. The letterhead could likely be easily reverse engineered, and I doubt the University rep knew what to look for, and the CFO's signature also doesn't carry any weight - any decent signature font could duplicate that signature (especially a digital one). I agree with the original comment - how did these…
That's assuming no prior knowledge, in which case it would be even easier.
Re: A fraudster got $12M out of a Canadian university
#24> Yangjiang City Jixie Zhulu Engineering made four payments to the Mas totalling ¥6.7 million, which would have been worth approximately $1.2 million. In August, Hoi Fu Enterprises received three wire transfers totalling $1 million. Interesting to see that a dollar in Canada is worth 16.7% more than the same dollar in China. And that was for a deal that was too good to be true. I wonder what the real going rate is fo…
China has really strict controls on the amount of money that a Chinese citizen can legally wire transfer out of the country, to a foreign domestic bank account, per year. People have come up with all sorts of "creative" grey and black market things involving Vancouver real estate and BC casinos. Google "china money laundering BC" for news about it.
This is really disturbing.
Re: A fraudster got $12M out of a Canadian university
#25I'd love to fund a startup fixing this problem. It's a clear space where technology has the edge over humans and there's huge network advantages (e.g. you see a new account # for a known entity, especially at a different bank it's a big red flag).
Re: A fraudster got $12M out of a Canadian university
#26I'd love to fund a startup fixing this problem. It's a clear space where technology has the edge over humans and there's huge network advantages (e.g. you see a new account # for a known entity, especially at a different bank it's a big red flag).
there has to be offerings already out there that address that kind of thing, but maybe not. Either way, I agree, tech has the clear edge on this, so long as the rulesets (or whatever parameters are defined) are correct.
Re: A fraudster got $12M out of a Canadian university
#27Why does a college need a building that costs a large fraction of a billion dollars? Early this week we had an article about college education costs being one corner of the "Bermuda triangle" of personal finance. Out of control spending on new, shiny things is part of the problem, I think.
Re: A fraudster got $12M out of a Canadian university
#28> They quickly discovered that while the email appeared to have been sent by “accounts.recievable@clarkbuilders.com” the email address had been “spoofed.” The display name of the email was different than the actual originating account. Um, and it was mis-spelled apparently.
https://www.thestar.com/content/dam/thestar/edmonton/2018/10...
The email was sent containing the email address "accounts.receivable@clarkbuilders.us" and the name field "accounts.receivable@clarkbuilders.com"
Re: A fraudster got $12M out of a Canadian university
#29I'd love to fund a startup fixing this problem. It's a clear space where technology has the edge over humans and there's huge network advantages (e.g. you see a new account # for a known entity, especially at a different bank it's a big red flag).
In particular, this kind of low-tech spoofing could have been mitigated if the email client had highlighted the fact that the sender’s “name” was nearly identical to the sending address, and therefore likely a phishing email.
Re: A fraudster got $12M out of a Canadian university
#30This seems like a technology problem, not a personnel problem. There should be more checks in a system when you are changing bank accounts where so much money is going to be deposited.
This scam has been going on in the UK for a few years. It's called "authorised push payment (APP) fraud". Typically you're having some building work done (or any other large project or purchase), and an email will arrive from the builder saying they've changed their account details, could the purchaser please send future bank transfers to the new account. Of course the email is fraudulent and usually happens because…
1) the check will be handed over in person to someone you've met before, or at least mailed to a known postal address which is harder to spoof than email.
2) If you present a check for $12m to a bank, it will get the scrutiny it deserves, and won't clear immediately.