10 ms·
Fresno lost $400k to a phishing scam in 2020 and never told the public
- deleted 5y ago[deleted]
- mdavis6890 5y agoGood job reporting on this. Now the question is whether the voters will care at the ballot box. We shouldn’t go after the person who fell for the scam - they’re just doing their job the best they can. Or even the person who should have disclosed. We have to all the way up to an elected official that needs to be held accountable, whether they knew about it or not.
- MrZander 5y agoWell, the previous mayor already lost the last election, and the new one disclosed it upon taking office.
- mdavis6890 5y agoWell there you go! :-)
- nelsondev 5y agoWhy shouldn’t there be accountability of the person who failed to disclose?
- thfuran 5y agoYou know, like how when an employee embezzles from a company you fire the CEO? It's just common sense. Punishing wrongdoing instead of ritually sacrificing a figurehead is just so barbaric.
- brnt 5y agoAs soon as you focus on the who and not the how, you incentivice people to cover their asses. Look up the root cause analysis culture in aviation for an effective method.
- nelsondev 5y agoYou can focus on both the “how” and the “who”. I work in an engineering organization where when something sufficiently complicated goes wrong, we do a proper root cause analysis, ask 5 Why’s, propose process improvements, etc. But sometimes, people just screw up, and preventing every unique screw up, would mean the creation of an absurd amount of process. For example, one time, excited by the performance results of a colleague, I tried to immediately apply his performance optimization in a different context serving production traffic; we had a team culture of don’t test in prod, etc; but my hubris/excitement meant I powered ahead, which ended up driving up latency, failing requests, and causing a small outage. The solution in this case isn’t to invent a new process to prevent my mistake, but rather to make sure the engineer knows they screwed up. A bit of shame/guilt leads to self improvement. If you focus solely on process, and avoid personal responsibility, you may end up missing opportunities for personal growth.
- thebigman433 5y ago> Or even the person who should have disclosed. We have to all the way up to an elected official that needs to be held accountable, whether they knew about it or not. How does this really make sense? The biggest wrong here is that it wasnt disclosed in my opinion. It sounds like it was the mayor's wrong there, but I dont see how you would "go all the way up to an elected official.. whether they knew about it or not". That part doesnt really make any sense to me
- tehwebguy 5y agoYeah the dollar amount is pretty much meaningless, it’s like the cost of employing 4 cops in a city that has 850. But the failure to disclose is a pretty big problem.
- 55555 5y agoThat’s not what phishing is.
- phire 5y agoIt's a type of phishing, known as spear phishing, where a specific individual or organisation is targeted with a highly customised scam. Emailing financial departments with fake invoices is a common type of spear phishing scam. https://en.wikipedia.org/wiki/Phishing#Spear_phishing https://en.wikipedia.org/wiki/Phishing#Spear_phishing
- benatkin 5y agoPhish Different. - Steve Jobs, 1997
- walrus01 5y agothe netsec/infosec industry term now is "whaling" or "spearphishing" where a specifically crafted fake email from a vendor to a payor is send to redirect the wire transfer to a another account, typically an ACH money mule or ignorant/clueles patsy that then forwards the bulk of the funds onwards to a location where it cannot be retrieved.
- IG_Semmelweiss 5y agoIm surprised that this attack on a govt entity was successful. In such entities, every vendor record is a database entry in some legacy custom CRUD system, which require 5 different people to approve X record update. Each of those people also have their own checklist of things to do prior to approval, one of which is literally pick up phone and confirm with vendor the X update. Govt has a reputation for not being agile - but maybe the scammers have identified a niche in city agencies? Now im wondering how many of these have never been reported on...
- atdrummond 5y agoI know of multiple municipalities (Illinois in this case) where there's a single point of failure for these kind of attacks. I am sure there are quite a few of these cases that never get reported to the public, especially after my experience with the quality of many of the audits that smaller and mid-size communities go through.
- csharpminor 5y agoAnd it’s especially easy to fake invoices since most local govs need to publicly post contracts and contract value. I wonder if there is some phishing going the vendor’s direction as well where the city requests to review the next invoice. It’s truly amazing to me that you can completely lose your money in an ACH transaction with little to no recourse.
- MattGaiser 5y agoI am an ex municipal employee. Procedures are often just blindly checked through. The paperwork for the procedure often exists and is filled out, but the procedure itself is often not conducted.
- fortran77 5y agoThe episode 111 of "Darknet Diaries" describes how Bullitt County, KY was hacked. 25 people were added to their payroll system and paid! They did it with a "man in the browser" attack so the transactions didn't raise red flags: https://darknetdiaries.com/transcript/111/ https://darknetdiaries.com/transcript/111/ Multiple people needed to sign off on these transactions, and the attackers were able to fake that once they had remote control of the browsers.
- csharpminor 5y agoI will say if you think this is bad, you ought to read about Washington State’s loss of $650M to organized cyber crime: https://www.seattletimes.com/seattle-news/auditor-state-unemployment-system-wholly-unprepared-for-fraud-one-agency-employee-under-criminal-investigation https://www.seattletimes.com/seattle-news/auditor-state-unem...
- walrus01 5y agoI had never heard of this, and I'm a WA state taxpayer... so admittedly having only read the article, I'm familiar with the theory that there's a number of fraud organizations out there that were in possession of the most vital personal data (name/DOB/SSN) that submitted false claims in 2020 during the earliest stages of the covid19 response, and got payments redirected to money mule ACH deposit accounts. this happened in more locations than just WA. one of the sketchiest things you can find on the internet, if you take time to research it, is the number of scammers posting "job openings" for things like a "accounts processing executive" for full WFH jobs. a certain percentage of gullible or entry level people who are too naive to know better fall for it. the general concept is to create a legit US domestic bank account that can receive ACH transfers and then forward the money onward somewhere else. usually ending up in some form of overseas account or cryptocurrency from which it cannot be retrieved.
- octoberfranklin 5y agoI was furious when I heard of this back in 2020, and I'm a WA state taxpayer. The ESD Commissioner job was handed out as a political patronage gift. The person who was running the show has "failed upward" and is now in Washington DC. One-party government sucks. "Yeah but the other party is worse" is irrelevant. https://www.seattletimes.com/seattle-news/politics/how-democratic-party-fundraiser-and-former-ambassador-suzi-levine-came-to-run-embattled-state-unemployment-system/ https://www.seattletimes.com/seattle-news/politics/how-democ...
- dmoy 5y agoMy own identity was stolen for this purpose, I had to submit a report to WA gov about the fraudulent claim submitted on my behalf
- Narkov 5y agoFor context, their total city revenue for FY22 is $1.8b. Not passing judgement either way, but at what point should this be reportable?
- zamadatix 5y agoReportable as in the city answering the public records request or reportable as in this news article? The former the amount shouldn't really matter, that's what public records are after all, the latter seems more subjective but I think the article is popular because of the denial of the records request and being found out not necessarily the amount being crazy high.
- et-al 5y agoThere are materiality guidelines. I don't know what they are for government, but general rule of thumb is 0.5 - 1% of gross revenue.
- walrus01 5y agoreminds me a little bit of when ubiquiti networks got phished to redirect a SWIFT wire transfer to a different location, and had to report it on their 10Q https://www.google.com/search?client=firefox-b-1-d&q=ubiquiti+wire+transfer+scam https://www.google.com/search?client=firefox-b-1-d&q=ubiquit... https://www.google.com/search?client=firefox-b-1-d&q=ubiquiti+networks+scammed+wire+transfer https://www.google.com/search?client=firefox-b-1-d&q=ubiquit... at least the SEC requirements for publicly traded companies requires them to disclose it. it's kind of funny that a for profit corporation has more transparency going on in its disclosure of getting scammed than a municipal government entity.
- rmbyrro 5y agoYou find it funny, but this is by design. Governments are not benevolent parties, gifts of the gods to society. Companies aren't either, but at least we can choose which companies we deal (not for everything, but still for many things) and companies can't use violence against us. We can't choose governments (if you live in a "democratic" state, you can choose a politician, which is another thing) and if you don't subscribe to what they impose, they have an excuse to use violence against you and your family. EDIT: private bodies in theory can use violence, but then we also can fight back in legitimate defense. This doesn't apply to governmental violence.
- astrange 5y agoYou can't choose to opt out of the city government of Fresno? I think it's pretty easy, I'm often not subjected to it.
- rmbyrro 5y agoYou'll just end up in another one just like it...
- lostlogin 5y agoThis is very circular. You prefer companies to the state, because we can chose which companies we deal with and companies can’t use violence. But it’s the state that says companies can’t use violence.
- bpodgursky 5y agoJust FYI the running total of CA's unemployment fraud during the pandemic is $20 billion: https://www.latimes.com/california/story/2021-10-25/californias-unemployment-fraud-20-billion https://www.latimes.com/california/story/2021-10-25/californ...
- DonHopkins 5y agoIf Frisco is short for San Francisco, does that mean Fresno is short for San Francesno?
- Raineer 5y agoErie, CO lost $1M to a phishing attack. It was very well timed and targeted toward a major project which had been in the works for a decade. https://www.denverpost.com/2019/12/30/erie-victim-financial-fraud-parkway-bridge/?returnUrl=https://www.denverpost.com/2019/12/30/erie-victim-financial-fraud-parkway-bridge/?clearUserState=true https://www.denverpost.com/2019/12/30/erie-victim-financial-...
- Illniyar 5y ago"The FBI asked city officials to keep the incident under wraps, so their investigation wasn’t compromised, Dyer said." Could this be a valid reason not to disclose it?
- benatkin 5y agoA valid reason not to disclose it at first, perhaps. By the time that the Fresno Bee formally requested it, that probably wasn't a valid reason not to disclose it anymore.
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- DannyBee 5y ago"Dyer said the emails were privileged information since the city attorney was included". This is not how privilege works, and all the people involved certainly know it. (This used to be a game oil and other companies would play, and courts do not look kindly on it anymore)
- throwaway0a5e 5y ago>and courts do not look kindly on it anymore As anyone who's ever spent more than a few nanoseconds caring about things like civil liberties or government accountability knows, the courts tend to give people who are on the "same team" a lot more leeway.
- DannyBee 5y agoThis is definitely true, but there are limits.
- throwaway0a5e 5y agoIf you make the courts look inept the courts come after you. If you do something politically tone deaf the politicians come after you. If you make the politicians look inept that's just Tuesday.
- dancemethis 5y agoFresno is just a brazilian emo band.
- TommyDANGerous 5y agoWow!