Live data from Hacker News

Ozarks Technical Community College robbed of nearly $900k

bransontrilakesnews.com

11–20 of 88 posts

Re: Ozarks Technical Community College robbed of nearly $900k

#12
> The loss of the funds will not affect students, classes or operations, states the release.

Are organizations liable when they make statements like this? Suppose operations actually are affected and the college intentionally misrepresented the consequences of the fraud—are there grounds for legal recourse by students and future students?

Re: Ozarks Technical Community College robbed of nearly $900k

#13

This is probably the first time I am seeing this. The ads served on website are local to MO, probably where the college is based. Rather than being customized to my browsing/locality.

This used to be the case before "they" thought having personalized ads would drive up interest.

Re: Ozarks Technical Community College robbed of nearly $900k

#14

> The loss of the funds will not affect students, classes or operations, states the release. Are organizations liable when they make statements like this? Suppose operations actually are affected and the college intentionally misrepresented the consequences of the fraud—are there grounds for legal recourse by students and future students?

I would assume they can say this due to having insurance coverage.

Re: Ozarks Technical Community College robbed of nearly $900k

#15
post #6

Naive question, but why can't banks undo a fraudulent transaction? Is there no such framework in place?

EFTs are reversible but have much lower limits. To move this much money they probably used a bank wire. This can be reversible if you catch it in time. But wires happen so fast the thieves will surely transfer the money elsewhere before the originator even finds out.

Are the banks not liable, when they don't know there customer?

Re: Ozarks Technical Community College robbed of nearly $900k

#16
post #6

Earlier quoted context omitted.

EFTs are reversible but have much lower limits. To move this much money they probably used a bank wire. This can be reversible if you catch it in time. But wires happen so fast the thieves will surely transfer the money elsewhere before the originator even finds out.

Are the banks not liable, when they don't know there customer?

The thief’s can wire it to an account in an offshore country where US authorities would have no power.

Re: Ozarks Technical Community College robbed of nearly $900k

#17
I feel like spammers and cyber criminals are getting better. Stuff is starting to get through Google spam filter by mashing up with elements that seem very real and urgent. Like yesterday I got this spam in my Gmail primary inbox with a subject line like "RE: Department of Education Case #295720186".

It made me wonder if you could autogenerate filter-evading spam using GANs? Train a GAN to generate email that fools a spam filter, feed it your spam prompt, and the neural network camouflages your prompt in filter-evading cruft and misdirection.

Re: Ozarks Technical Community College robbed of nearly $900k

#19

> The loss of the funds will not affect students, classes or operations, states the release. Are organizations liable when they make statements like this? Suppose operations actually are affected and the college intentionally misrepresented the consequences of the fraud—are there grounds for legal recourse by students and future students?

I would assume they can say this due to having insurance coverage.

[deleted]

Re: Ozarks Technical Community College robbed of nearly $900k

#20
post #2

“We can’t provide all of the specifics at this time,” Higdon said, “but it appears the criminals succeeded in impersonating one of our vendors online and directed payments from the college into a fraudulent account.” - so they sent a fake invoice and the college paid it?

There are more and more reports of serious phishing attempts that do not rely on mere fake emails, but involve criminals breaking into a business' infrastructure, observing mail (and sometimes even call) flow for a while (this can take months!) and waiting for an opportune moment to strike. They'll use the real company's infrastructure to send an invoice or email in the middle of an existing project that goes unnoticed for long enough to hit several clients. By the time the client and the hacked company start arguing about who paid what bill when into what account, the criminals are already out and moving on to their next target.

Not many people are prepared for these attacks. All the standard checks for phishing scams (sender, subject, language used, information repeated, technical measures like SPF and DKIM) pass with flying colours. You need to be wary of every single email from legitimate contacts to protect yourself from such a threat.

Such hacks target businesses (because huge b2b transactions are common enough) but also wealthy individuals contracting companies. Anyone capable of wiring out a sum of money large enough to make months of work for the (probably third world) salaries of the people involved in the operation worth it can be a target.

There are plenty of people who will fall for your old "we're the IRS, pay us Google Play gift cards" scam and even a fake invoice from an unknown company sometimes gets paid by a billing department that doesn't care about their jobs, but not every scam victim fell for some comically obvious scam. In the real world, real companies don't stick to best practices ("hi we're your bank. No you can't call us back to verify") and as long as legitimate companies send weird bills or make weird payment requests, scammers will find ways to mislead people.

Post reply on HN