3 ms·
Apologies if it was mentioned in the article, but I am curious as to how the original attacker acquired the information needed for spear phishing. I suppose bu
by sjroot 8y ago
Apologies if it was mentioned in the article, but I am curious as to how the original attacker acquired the information needed for spear phishing.
I suppose business dealings between the university and contractors is public to some extent, but it seems plausible that this attack came from within the university or the contractor.
- crescentfresh 8y agoThis was the real breach. Bank account numbers, company letterhead, the CFO's signature, these were all gathered before any attack took place!
- bt3 8y agoBank account numbers weren't leaked - the scammers simply requested the payments be rerouted to a different account. The letterhead could likely be easily reverse engineered, and I doubt the University rep knew what to look for, and the CFO's signature also doesn't carry any weight - any decent signature font could duplicate that signature (especially a digital one). I agree with the original comment - how did these scammers gain the knowledge that these transactions were ongoing, and know exactly who to target?
- scott_s 8y agoIf you know that a university is doing construction, then you know they're paying someone. It's not hard to know a university is doing construction because it will be reported on, they will have had to gain permission to do so, and you can just drive by and see the construction. Once you know that, then you just need to figure out the name of the companies involved. That should be simple: often construction companies will put up a sign, or you can just ask some people on site. That's assuming no prior knowledge, in which case it would be even easier.
- danso 8y agoThe university in question in a public institution. All of that info -- including copies of signed paperwork, names of officials, and ongoing contracts -- is likely available as public records.
- JamesCoyne 8y agoLook at the email image in the lower portion of the article. All the attacker needed to know was the accounts-payable email address for MacEwan, the true accounts-receivable address for the builder, a reasonably similar domain (.com -> .us) for spoofing, and a convincing email body. That is a frighteningly easy bar to clear, so it's reasonable to say this was human error more than a problem with information security.