Live data from Hacker News

Hackers steal Western Michigan University professor's paycheck

mlive.com

21–30 of 42 posts

Re: Hackers steal Western Michigan University professor's paycheck

#21
post #2

The same thing happened recently at BU, but our school is covering all losses even though I think the users are at fault in our case: At BU it was people that responded to a fishing email that had their account info changed. http://www.bu.edu/today/2014/fighting-phishing-bu-moratorium...

That was my first guess for this story too - six people is a very small number if someone found a system exploit. Although it is still possible that's the case, and only specific passwords/accounts/etc were vulnerable.

Re: Hackers steal Western Michigan University professor's paycheck

#22
>>"Unfortunately, it's pervasive," Porter said of such theft by computer. If the criminals are willing to dedicate "time, brains and fortitude, it's hard to stop it all."

This article reads like it'll be difficult to catch the person who stole the money. I remember all the arguments about bitcoin being more (pseudo)anonymous than a Bank, but if authorities can't even get the person who got this Bank ACH Deposit then I must have a horrible understanding of the Banking process. What's the problem? I thought bank-fraud was the easiest crime to catch assuming the culprit isn't someone with connections in high-places.

Re: Hackers steal Western Michigan University professor's paycheck

#23

Has he argued with any Comp Sci students? (edited to avoid implying fault on his part)

This is not funny. Unpaid wages are never funny. Actually, the Catholic Church classes it as a "sin that cries to heaven", and groups it with murder, inhospitality and exploitation of those with no clout. What they all have in common is a disregard for the humanity of your fellow man, and you can't punish that enough.

Re: Hackers steal Western Michigan University professor's paycheck

#24
Employee handbook probably has a clause in "IT Policy" that says 'Employee is responsible for maintaining the security of his/her password' or some similar such nonsense that the Uni will try to hide behind. Typically the only way for employees to opt out of this (when this option is available at all) is to elect to receive a paper check.

My employer's system (which comes from a big name edu-prise sw vendor) takes a 6 digit password and my system username is public information (it is not advertised, as a username, but it is visible on public facing documents). Access to this system would allow a person to change my payroll & benefits info, mailing address, and other contact info, change student grades (for the current semester), access confidential student information, and in some cases, add/drop currently enrolled students from courses. The system default password and reset default are also public information. This is a disaster waiting to happen.

Re: Hackers steal Western Michigan University professor's paycheck

#25
This is an interesting case. If an employee is liable for the loss as a consequence of a data breach in a university system then does that mean it's acceptable for an employee to do their own penetration testing of university systems handling their money? This would help them better understand the weaknesses to protect themselves and push the university to fix their systems. Yes, this professor could have been phished and given up their credentials to a bad guy, but that shouldn't entirely offload the liability onto the employee as the university should have had strong measures in place for validating changes to routing numbers.

Re: Hackers steal Western Michigan University professor's paycheck

#27

UK resident: My wages are paid into my bank account using an electronic payments system that does not use the Internet at all. The accounts/HR people have computers that are on a separate VPN from the rest of us. The attack mode in this case revolved around the use of a client system to tell HR/Payroll where to pay the money. We don't do that, any change in bank account details is a visit to an office with paperwork.

I've lost a payment in a similar fashion before. The accounts team took the written paperwork and misinterpreted a 6 for a 0 (I didn't write the form) and it just happened to be a valid destination account number. It took me 2 weeks to get the payment back. Doesn't always come down to technology. In fact, when it comes to technology it's usually pretty good. Humans on the other hand always err on the side of incompet…

When I worked for a university in the UK as salaried Research Associate they "forgot" to pay me one month - didn't even apologize. They gave me a cheque that I cashed in the universities own branch and cycled to my own branch to deposit the money before my mortgage payment came out.

Re: Hackers steal Western Michigan University professor's paycheck

#28
post #22

>>"Unfortunately, it's pervasive," Porter said of such theft by computer. If the criminals are willing to dedicate "time, brains and fortitude, it's hard to stop it all." This article reads like it'll be difficult to catch the person who stole the money. I remember all the arguments about bitcoin being more (pseudo)anonymous than a Bank, but if authorities can't even get the person who got this Bank ACH Deposit then…

Or a fake ID... opening an untraceable bank account is one of the major use cases for identity theft. It's very likely that the money was moved into a bank account opening with a stolen or false identity, and the person will not be caught.

Re: Hackers steal Western Michigan University professor's paycheck

#29

Has he argued with any Comp Sci students? (edited to avoid implying fault on his part)

This is not funny. Unpaid wages are never funny. Actually, the Catholic Church classes it as a "sin that cries to heaven", and groups it with murder, inhospitality and exploitation of those with no clout. What they all have in common is a disregard for the humanity of your fellow man, and you can't punish that enough.

I'm not trying to be funny. People already known to the victim is the sane place to start any investigation.

edit - my edit earlier was going from 'pissed off' to 'argued with' as I realised that 'pissed off' can often imply intent to piss off.

Re: Hackers steal Western Michigan University professor's paycheck

#30
post #28
post #22

>>"Unfortunately, it's pervasive," Porter said of such theft by computer. If the criminals are willing to dedicate "time, brains and fortitude, it's hard to stop it all." This article reads like it'll be difficult to catch the person who stole the money. I remember all the arguments about bitcoin being more (pseudo)anonymous than a Bank, but if authorities can't even get the person who got this Bank ACH Deposit then…

Or a fake ID... opening an untraceable bank account is one of the major use cases for identity theft. It's very likely that the money was moved into a bank account opening with a stolen or false identity, and the person will not be caught.

mindblown.gif ...I had no idea a regular person could open & collect funds from a bank account that was fraudulently opened and actually get away with it.
Post reply on HN