This is why all staff, whether at a corporation, nonprofit or government that handle money should be put through a two hour anti-phishing training course. There's lots of good free training material out there. There are also services which you can hire. You give them a list of staff emails, and they send test phishes to everyone. Those who respond or click on links (there's a GUID in each phish) can be sent for furth…
While I think everyone should be aware of phishing, I don't think any amount of education can reliably prevent this sort of fraud. I see this fundamentally as a process problem, as I assume email was a common way of changing payment information. Email needs to be taken out of the loop.
A fraudster got $12M out of a Canadian university
71–80 of 119 posts
Re: A fraudster got $12M out of a Canadian university
#72This is why all staff, whether at a corporation, nonprofit or government that handle money should be put through a two hour anti-phishing training course. There's lots of good free training material out there. There are also services which you can hire. You give them a list of staff emails, and they send test phishes to everyone. Those who respond or click on links (there's a GUID in each phish) can be sent for furth…
While I think everyone should be aware of phishing, I don't think any amount of education can reliably prevent this sort of fraud. I see this fundamentally as a process problem, as I assume email was a common way of changing payment information. Email needs to be taken out of the loop.
The ease of forging emails is more of an issue where the spear phish email is trying to disguise itself as coming from inside the company.
Re: A fraudster got $12M out of a Canadian university
#73Earlier quoted context omitted.
From the article: the email was spoofed to appear to be from the building company.
You can see in the screenshot (scan of the email) it was a low-tech spoof. They simply bought the same domain with a different TLD (.com vs .us) There were many red flags that weren't caught, this being one of them.
Re: A fraudster got $12M out of a Canadian university
#74Earlier quoted context omitted.
China has really strict controls on the amount of money that a Chinese citizen can legally wire transfer out of the country, to a foreign domestic bank account, per year. People have come up with all sorts of "creative" grey and black market things involving Vancouver real estate and BC casinos. Google "china money laundering BC" for news about it.
I know it's fiction, but the show "Ozark" on Netflix shows as interesting adaptation of money laundering through casinos and real estate.
Re: A fraudster got $12M out of a Canadian university
#75Earlier quoted context omitted.
While I think everyone should be aware of phishing, I don't think any amount of education can reliably prevent this sort of fraud. I see this fundamentally as a process problem, as I assume email was a common way of changing payment information. Email needs to be taken out of the loop.
I wonder if GPG could have ensured this didn't happen.
Re: A fraudster got $12M out of a Canadian university
#76Any invoice would be expected to be signed using a physical security key. The University or a trusted third party would have a list of vendor keys, signed by the university's master key.
Any request to change account details or for payments would require a new signed invoice. Then any user receiving such an email could easily see if the invoice had been signed by a person who can cryptographically prove they have a key that is trusted to be in the vendor's possession.
Re: A fraudster got $12M out of a Canadian university
#77Earlier quoted context omitted.
It’s not clear to me that $180 million is an unreasonable amount of money to spend on a state-of-the-art building with multiple music studios and dance halls, necessary for music or dance programs that the school (presumably) offers. Between the tuition the students pay, grants from government, and potential commercial use of the space (for concerts, shows, etc.) it’ll likely pay for itself soon enough. Also bear in…
>it’ll likely pay for itself soon enough. Thats the problem though right? "Paying for itself" means students paying higher costs which is the problem.
Re: A fraudster got $12M out of a Canadian university
#78Re: A fraudster got $12M out of a Canadian university
#79This seems like a technology problem, not a personnel problem. There should be more checks in a system when you are changing bank accounts where so much money is going to be deposited.
It's a multifaceted problem. Certainly a social engineering problem here. I think anyone that's ever seen how an ACH file works would agree there's room to improve on the technology side.
Re: A fraudster got $12M out of a Canadian university
#80This seems like a technology problem, not a personnel problem. There should be more checks in a system when you are changing bank accounts where so much money is going to be deposited.
This scam has been going on in the UK for a few years. It's called "authorised push payment (APP) fraud". Typically you're having some building work done (or any other large project or purchase), and an email will arrive from the builder saying they've changed their account details, could the purchaser please send future bank transfers to the new account. Of course the email is fraudulent and usually happens because…
Now that Brexit is near it doesn't matter anyway, but at least in Italy and Spain (but I presume the rest of EU) a more complex ID for accounts with checksum/validation, called IBAN, is used for both international and national transfers:
https://en.wikipedia.org/wiki/International_Bank_Account_Num...
that should avoid that kind of typo error.