23 ms·
Two major US technology firms 'tricked out of $100M'
- SteveNuts 10y agoThis happened to Ubiquiti a while back https://krebsonsecurity.com/2015/08/tech-firm-ubiquiti-suffers-46m-cyberheist/ https://krebsonsecurity.com/2015/08/tech-firm-ubiquiti-suffe...
- drzaiusapelord 10y ago>crooks spoof communications from executives at the victim firm in a bid to initiate unauthorized international wire transfers. In other words simple social engineering. These finance people are scared of their CEOs and VPs so they jump at their requests, often skipping the verficiation stage because "Bossman will get pissed if I ask him for his secondary auth. My manager told me I'd be fired if I pissed off bossman again." If anything, the companies that get hit by such simple scams deserve to be. They clearly don't have the corporate culture and accountability to stop a simple fake money request. Lets stop blaming the technology here and start blaming the real problem: executive entitlement and the incredibly classist structures at most companies where the bottom people can't even question the top people. This is why these scams work so well. The people in finance are petrified at questioning an executive. That shouldn't be the case, especially if they claim to be compliant with various financial and technical regulations and certification processes. A lot of good HIPPA is when everyone is too scared to tell a surgeon he can't send patient information that way or SOX if accountants are scared of their bosses.
- Someone1234 10y agoPeople would legitimately be surprised to learn how low tech ordering/invoicing/remittances remain in 2017 even for half billion dollar contracts. There's very little automation, even EDI is the exception rather than the rule (particularly for one off orders), most are either still paper, fax, or insecure email. Email remains pretty broken. You'll be lucky to get end to end encryption, and once it arrives it is hard to make assurances that the sender really sent it (or even the sender's domain). People have tried to fix email but nothing as ambitious as TLS/HTTPS has been. And getting people to use a more secure platform built on top of HTTPS is likely a non-starter... So what can be done? I legitimately don't know. Even snail mail can be "hacked" via sending a plausible sounding invoice to the right address at the right time.
- dahart 10y agoI'd be extremely surprised if half billion dollar contracts were automated in any way, that seems like a really bad idea.
- L_Rahman 10y agoAutomating the payment would be a really bad idea, but the workflow of receiving the contract/invoice, running it through internal systems, negotiation and legal could use some software help.
- dahart 10y agoAll my contract negotiation & signing over a few bucks has been done using cloud based encrypted services for years. Yes email is not encrypted, but I'm not sure what the problem is, or how this even relates to the article. This was a phishing scam over new deals. New deals can't generally be automated, shouldn't generally be automated, and the issue here involved human factors that are likely to always exist. The presumption that more computers and more encryption could fix what happened in this story seems misguided to me.
- javiramos 10y agoTotally agree.. This process is SO broken and frustrating.
- tyingq 10y agoI wonder how long a less greedy approach would have worked. I would guess a larger number of smaller invoices might have gone unnoticed for some time. This egregious approach lasted for 2 years.
- bitJericho 10y agoEmail uses tls. If both ends support it, it uses it. Most popular email providers support it. Also, dmarc signs emails the guaranteeing domains, and if you want email to be reliable, you must support dmarc.
- kirykl 10y agoI would think a simple 2nd factor check, by phone to the actual vendor would have prevented this. For such large amounts the time involved would be worth it
- anovikov 10y agoQuite likely people on the other side (employees of the victim companies) collaborated with him and got their share...
- kbart 10y agoTry to call international company with thousands of workers and get somebody who knows anything on phone. Also, most workers simply don't care for a tiny chance of scam, it's not their money after all.
- pythonaut_16 10y agoSeems like a reasonable requirement as part of any large deal like this. Even if each party pays someone 200k a year solely to sit in an office and make calls verifying large invoices you're still talking about a small amount compared to the size of these contracts.
- manquer 10y agoI would think that vendors with large enough contracts will be more than happy to jump through any hoops if required.
- vidarh 10y agoI've worked for companies in the past where no money would ever be paid out to anyone but government (tax bills etc.) without the party sending them the invoice having a valid purchase order number that referred to a pre-agreed supplier record that specified tha company name and address and the bank account to send it to. It was annoying at times, but it also meant their accounts department could match every single expense to a specific contract or pre-agreed authorisation, complete with who (on their end) had made the request and who had signed off the request. Even if you don't do that for everything, even just doing that for everything above a certain amount would make such fraud a lot harder.
- bvinc 10y agoWhy didn't he wire it to a Swiss or Cayman Islands bank account?
- ryanlol 10y agoBecause he didn't know anyone who could create him drop accounts in those countries?
- wyldfire 10y agoI saw speculation on Twitter that it was Google or Apple and Facebook. But to me, it seems like it could be any of dozens of companies based on "Internet-related services and products" and "multinational ... online social media/networking". See also: affidavit [1] [1] https://www.scribd.com/document/342639731/Rimasauskas-Affidavit https://www.scribd.com/document/342639731/Rimasauskas-Affida...
- tyingq 10y agoThey do say that the victims "regularly conducted multimillion-dollar transactions" with the computer hardware company that was being impersonated. That does narrow it down to companies in those spaces that run on their own metal, and significant amounts of it.
- ryanmarsh 10y agoMultimillion could be 2 or 10 and as far as running your own metal that's not really a big purchase relative to your average Fortune 100's IT budget.
- tyingq 10y agoThe space, though, is more narrow than that. Victim 2, for example, is specifically a social media company. Can't be that many social media companies, headquartered in the US, running their own metal, with more than one multi-million dollar invoice for it in a 2 year period. How many could that be? I can only think of 3 or 4 contenders.
- tyingq 10y agoMore detail here: https://www.justice.gov/usao-sdny/pr/lithuanian-man-arrested-theft-over-100-million-fraudulent-email-compromise-scheme https://www.justice.gov/usao-sdny/pr/lithuanian-man-arrested... There's a download link for the actual indictment as well. He registered a company with a name very similar to an existing, legitimate computer hardware manufacturer. Then targeted companies that already had a relationship and already regularly paid invoices to the company with the similar name. It mentions the victims were "multinational internet companies". The indictment goes farther, saying: "Victim-1 was a multinational technology company, specializing in Internet-related services and products, with headquarters in the United States" and "Victim-2 was a multinational corporation providing online social media and networking services, with headquarters in the United States" Edit: It mentions that both victims already regularly paid multi-million dollar invoices to the computer hardware company being impersonated. So, if you're trying to guess who the victims are, they are large enough that they run on their own purchased hardware, in fairly large quantities.
- binthere 10y agoThank you. I was really frustrated reading the article of this post as it was very vague about the actual scam.
- sna1l 10y agoThese clickbaity articles have become way more common on HN
- taftster 10y agoThese clickbaity articles have become way more common on the web. There's rarely anyone writing quality content for the sake of the content anymore. It's all just glorified hyperlink farming and ad impressions.
- eropple 10y agoWell...yeah. That's what pays. (And this is why I subscribe to media that does support long-form journalism and kit out journalists with the tools--and the paychecks--necessary to make it happen. Subscribe as in pay-money-to-on-a-monthly-basis. It's the only way it survives.)
- ccvannorman 10y agoStories like this are what give African Princes hope that someday they will find their Princess.
- mirimir 10y agoCould you unpack that a little?
- Strom 10y agoThe reference is to popular scams where a person contacts you and claims to be royalty in need of a bit of money. https://en.wikipedia.org/wiki/Advance-fee_scam https://en.wikipedia.org/wiki/Advance-fee_scam
- mirimir 10y agoDoh. Thanks :)
- justboxing 10y agoIt's more commonly known as the "Nigerian Prince Scam". The scam itself is decades old, Email and Internet scam artists have ushered it into the 21st Century :) Nigeria is associated with the scam and it was also known as 'Nigerian 419'. That's because the the first wave of these scams came from Nigeria. The '419' part of the name comes from the section of Nigeria's Criminal Code which outlaws the practice. These scams now come from anywhere in the world. Further Reading: http://www.bbb.org/new-york-city/get-consumer-help/articles/the-nigerian-prince-old-scam-new-twist/ http://www.bbb.org/new-york-city/get-consumer-help/articles/...
- astrodust 10y ago"I have $20M in US currency that needs to be moved out of the country as quickly as possible. If you have a US-based bank account that can do wire transfers I'll give you 4% in exchange for this transaction. The money came from my relative, a rich noble who unfortunately does not have any heirs in the US but decided to spend his later years in Florida and keep all of his money in a local bank so he could look after it personally." "I am currently working overseas in Nigeria and would greatly appreciate any help. This has been a big point of pain in our family."
- owly 10y agoSecurity is only as good as the weakest link, employees who do not question legitimacy and authority.
- tlrobinson 10y agoSimilar scams have targeted (medium-large, funded) startups as well. Typically the attacker starts by phishing an employee, then uses information discovered through that to trick someone else in the company to initiate a wire.
- mixedbit 10y agoSounds like a story for another "Catch Me If You Can" kind of movie.
- dboreham 10y agoEven more surprising when I consider my own experience getting large technology corporations to pay my companies money they legitimately owe us!
- 6stringmerc 10y agoThis aligns well with my 2017 Nicholl Fellowship screenplay entry called "Do Unto Others" where in Act III the protagonists use their insider knowledge of International Banking and Wire Transfers to clean out the hidden stash of illicit monies hidden by disgraced Enron executives[1]. To me, plausibility is important in fictional works that reach for meaning or defined structure, at least where possible. I mean, I love Hackers but of course groan at scenes inside "The Gibson" and whatnot. This guy actually made it work - I'm impressed. [1] https://www.scriptrevolution.com/scripts/do-unto-others https://www.scriptrevolution.com/scripts/do-unto-others
- 23443463453 10y agoSeems like a lesson in not knowing when to cut and run.
- wyc 10y agoThe funny thing is that these incidents are probably what it takes for those particular companies to beef up their security culture. Everyone else will likely keep their heads down: "How asinine of them! This dumb thing could never happen to us." The truth is that without the right security processes and culture in place, it could really happen to anyone dealing with substantial value and overworked mid-level managers, a form of the principal–agent problem[1]. Security incidents have a stark resemblance to emergency room visits. People are so hard to sell on prevention, and they end up paying big for an ER visit. [1] https://en.wikipedia.org/wiki/Principal%E2%80%93agent_problem https://en.wikipedia.org/wiki/Principal%E2%80%93agent_proble...
- dangerboysteve 10y agoI imagine these types of crimes are very much helped by mining data from Linked in and Facebook.
- perlgeek 10y agoTo me, the surprising thing is that they managed to get the bank transferred to the "correct" fraudulent accounts. If you send an existing customer another invoice, but with a changed bank account number, chances are that the money goes to the same bank account as they used previously. Even if you explicitly add a note about the changed account number, chances are still very high that they use the old one.
- analogmemory 10y agoI freelance and just moved, trying to get accounting departments to send checks to the correct address is worse than pulling teeth. Even after making large notes about the address changes and emailing them repeatibly. I should figure out how this guy managed to do it ;)
- sfifs 10y agoHonest question: Why would you use cheques instead of bank transfer? Isn't that cheaper all the way around? I live in India and practically haven't seen any company use cheques for payment in the last few years.
- DanBC 10y agoThe important bit of this for HN is that he got these companies to pay by using their sales order, invoice, payment process, and that process is common to most companies. If you have a small or an open source project you're going to struggle to get companies to pay unless you can fit their process. This means that it's probably worth while offering a "professional" licence. This grants no extra functionality, but allows the company to put in a sales order, and allows you to deliver something and allows you to issue an invoice.
- ryan-c 10y agoAnyone have a better guess than "Foxconn" as to who this guy was impersonating?
- settsu 10y agoThere is quite a bit that could be mined from this story, but just as a start: 1) The most zealous and persistent phishing awareness campaigns/training I've encountered has been at large corporations. I can imagine a series of articles, if not an entire career, that is based on exploring the psychology of employees in varying organization sizes being influenced by their perceptions of the stake they feel they hold in the performance of the organization (i.e., their "ownership") and how much their actions, positive and negative, might bear notable influence. Not confident I made my point clear, but the idea being I'm going to think differently about jumping up and down on a cruise ship vs. a row boat... 2) Putting aside the questionable application of it in this specific case, "cybercriminal" is an outmoded term that I believe actually undermines the mundane and routine nature of these crimes. Regardless of magnitude, it imbues the perpetrator and their activities with some 90s-era aura of mystery and preternatural skill—an exceptional event executed by exceptional individuals under exceptional circumstances.
- leonroy 10y agoIronic we nearly went under a few times during the early days because our customers (tier 1 telecoms and financial firms) would drag their heels for months and months over invoices many magnitudes less than this. Makes me wonder what's up with the process at these firms - wish we knew enough to say whether they're the exception or the rule.
- downrightmike 10y agoBy delaying any and all payments to vendors, you free up cashflow. It is in the company's best interest to hold off payment as long as they can.
- abraae 10y agoExcept that you create a toxic environment inside your accounts team, who have to constantly deal with incoming calls demanding money. And if you're the kind of organization that makes a process out of paying each vendor as late as possible (I mean beyond the agreed terms) - which some do - then you'e likely a shitty org in many other ways too.
- elchief 10y agoHow do you steal $100M and not get away with it? He had access to the money for years
- spoiledtechie 10y agoHe probably became verbose. You always think you would stop after the first 10m, but most folks want to see how far they can take it. I figure after the first 20m, he was like, I could do this forever! I would have stopped after the first 10m. They would have never missed the money and it could have turned into an accounting error.
- nandemo 10y ago> You always think you would stop after the first 10m There's No Desire To Retire If You Love Your Work, or something like that.
- dopamean 10y agoI have a friend who's father is very, very wealthy. He purchases a lot of art and often actually finalizes the sales by emailing someone who works for him something to the effect of "please transfer X dollars to Y party for Z piece of artwork." A few years ago someone got access to his gmail account in what appeared to be a mass phishing attack and saw several of these emails in his sent email folder. The intruder was able to have a few million dollars successfully transferred to himself. It was several months before it was noticed and the guy was never caught. My friend's father now uses two factor auth and has whoever receives those emails confirm via phone call the next day.
- randyrand 10y agoThat's pretty funny.
- tuxxy 10y agoWow, that's pretty awesome. What a wake up call lmao
- shazzy 10y agoThis actually happened to a law firm that I know of. One of their clients had their account hacked and in the client's mailbox they found emails from the law firm including some outstanding bills payable to the firm. The attacker then spoofed an email from the law firm to the client along the lines of "our bank details have changed to xxx please transfer your outstanding bill by [date]". The client didn't realise anything was wrong until the law firm chased him for the bill by which time the account the attacker had used was closed and the money moved offshore.
- markdown 10y agoAre you in the US? Don't 'know your customer' laws ensure that no bank account is owned by an anon?
- jeppebemad 10y agoLast week I received a similar e-mail from my co-founder, asking me if I could transfer some money to an account. I found it a little strange, but not enough to question that it actually had to be done. Since I was headed to the office anyway, I waited until I got in, and asked him what the money was for. "What money? What email?" Turns out the e-mail was sent from a fake gmail account with the name of my co-founder. Hadn't spotted that the email address was wrong, as it was hidden in my email client. I reported the email to Google and sent the scammer a sarcastic reply: "how many millions do you need?" The scammers' response? "You're fired" What a cheeky fraudster! That said, I'm sure he has pulled it off before.