Live data from Hacker News

Madison County, MS spends $2.7M to train comptroller about phishing, IT security

kingfish1935.blogspot.com

1–7 of 7 posts

Re: Madison County, MS spends $2.7M to train comptroller about phishing, IT security

#4
This... Has to be someone familiar with this process/situation I would think. Unless the county posts all of the information required to pull off such a scam online (to be transparent or something).

Still, how would they know when payment was due, amounts, that it hasn't already been paid, etc. I think someone is going to get caught.

Re: Madison County, MS spends $2.7M to train comptroller about phishing, IT security

#5

This... Has to be someone familiar with this process/situation I would think. Unless the county posts all of the information required to pull off such a scam online (to be transparent or something). Still, how would they know when payment was due, amounts, that it hasn't already been paid, etc. I think someone is going to get caught.

State and local government contracts are very often subject to sunshine laws and if they aren't publicly posted available via public records request, as are many internal documents of on-paper internal procedures as well as many documents from which in-reality procedures, to the extent they differ, can be inferred.

Re: Madison County, MS spends $2.7M to train comptroller about phishing, IT security

#7

There a should be an allowlist of bank accounts a public official is can to send money to.

They will lead with a spoofed email from utilities commissioner to comptroller: “We’re bringing Acme Co. on as contractor for the sewers project, their W9 and banking details are attached.”

Business email compromise scammers have improved and are no longer just spamming with obvious gift-card schemes in broken English.