8 ms·
Ozarks Technical Community College robbed of nearly $900k
- Fargoan 4y ago“We can’t provide all of the specifics at this time,” Higdon said, “but it appears the criminals succeeded in impersonating one of our vendors online and directed payments from the college into a fraudulent account.” - so they sent a fake invoice and the college paid it?
- bluejekyll 4y agoI read that more as someone called the school and said something like: “hi, I’m calling from vendor X you usually pay into our bank account ABC, but due to some reason, we’ve needed to close that account. Can you please update that account to DEF and make all future payments there?”
- jeroenhd 4y agoThere are more and more reports of serious phishing attempts that do not rely on mere fake emails, but involve criminals breaking into a business' infrastructure, observing mail (and sometimes even call) flow for a while (this can take months!) and waiting for an opportune moment to strike. They'll use the real company's infrastructure to send an invoice or email in the middle of an existing project that goes unnoticed for long enough to hit several clients. By the time the client and the hacked company start arguing about who paid what bill when into what account, the criminals are already out and moving on to their next target. Not many people are prepared for these attacks. All the standard checks for phishing scams (sender, subject, language used, information repeated, technical measures like SPF and DKIM) pass with flying colours. You need to be wary of every single email from legitimate contacts to protect yourself from such a threat. Such hacks target businesses (because huge b2b transactions are common enough) but also wealthy individuals contracting companies. Anyone capable of wiring out a sum of money large enough to make months of work for the (probably third world) salaries of the people involved in the operation worth it can be a target. There are plenty of people who will fall for your old "we're the IRS, pay us Google Play gift cards" scam and even a fake invoice from an unknown company sometimes gets paid by a billing department that doesn't care about their jobs, but not every scam victim fell for some comically obvious scam. In the real world, real companies don't stick to best practices ("hi we're your bank. No you can't call us back to verify") and as long as legitimate companies send weird bills or make weird payment requests, scammers will find ways to mislead people.
- cookie_monsta 4y agoHere's another such example. The red flags are there, in hindsight: https://ia.acs.org.au/article/2020/ice-rink-loses--77k-in-email-scam.html https://ia.acs.org.au/article/2020/ice-rink-loses--77k-in-em...
- formerkrogemp 4y agoThey pretended to be the vendor and probably got the college to "update" vendor payment info to the fraudster's controlled account's details.
- sva_ 4y ago(Geoblocked in EU) https://archive.ph/YtPLb https://archive.ph/YtPLb
- formerkrogemp 4y agoThanks for the link.
- threatofrain 4y agoNaive question, but why can't banks undo a fraudulent transaction? Is there no such framework in place?
- yardie 4y agoEFTs are reversible but have much lower limits. To move this much money they probably used a bank wire. This can be reversible if you catch it in time. But wires happen so fast the thieves will surely transfer the money elsewhere before the originator even finds out.
- _trampeltier 4y agoAre the banks not liable, when they don't know there customer?
- tonmoy 4y agoThe thief’s can wire it to an account in an offshore country where US authorities would have no power.
- thatfunkymunki 4y agoI still don't quite get this. I always imagined a bank wire as a data transfer, and that an actual settlement of hard currency happens sometime thereafter. How is it irreversible, in this regard?
- duxup 4y agoDo the banks in this case provide some assurance / can they be sure who is on the other end of the transfer?
- formerkrogemp 4y agoIf it's a transfer using your authentication details they might put the transaction on hold or call you, but, no, they generally aren't liable with the processes they have in place unless there's significant negligence. The college might have been the one authorizing the transfer here to the wrong party. Banks can't or don't typically verify all of your vendors and clients and transactions. They provide the money pipes.
- yardie 4y agoJust so we are all aware, crypto does not solve fraud. The result would have been the same if they paid in Bitcoin.
- usrn 4y agoRight but usually people argue banks prevent this sort of thing and that's one of the main downsides to crypto. It turns out banks don't.
- formerkrogemp 4y agoBanks and even western union at the gas station or grocery store do often catch fraud preying upon old people to send money. It just isn't foolproof.
- fortran77 4y agoFake invoice scams have been around for a long time.
- formerkrogemp 4y agoThey have been getting more sophisticated over time as well. GPT and GAN generated or hand tailored phishing will do in even trained professionals at times.
- gruez 4y agookay? I'm not aware of anyone who thought crypto solved fraud in the first place.
- formerkrogemp 4y ago
- downrightmike 4y agoOof, if a $900,000 invoice doesn't trigger review from their accounting dept, kind of their fault for not having a process of the common sense to question that bill.
- formerkrogemp 4y agoI hate to say it but a lot of "accounting depts" these days are someone with no formal training who just took on the role as another hat on top of other hats as the more experienced folks retired or moved on to greener pastures. There's a shortage of accounting folks in general as well.
- MrLeap 4y agoAmusing anecdote. My girlfriend has an accounting degree in the Ozarks and has had trouble getting work related to it.
- formerkrogemp 4y agoThere are many job postings for folks with 3+ years of experience. Very little is being offered for people who don't want to work in Big 4 or haven't completed a few internships. Most traditional entry level work is being or has been automated. Accounts receivable and payable are being rolled up along with payroll into the job duties of outsourced accounting and the like.
- deleted 4y ago[deleted]
- CPLX 4y agoGoing to go out on a limb and guess it wasn’t one invoice.
- tyingq 4y agoGoogle and Facebook got bilked out of $100M, and you would guess they had lots of processes and technology in place. https://www.npr.org/2019/03/25/706715377/man-pleads-guilty-to-phishing-scheme-that-fleeced-facebook-google-of-100-million https://www.npr.org/2019/03/25/706715377/man-pleads-guilty-t...
- redtriumph 4y agoThis is probably the first time I am seeing this. The ads served on website are local to MO, probably where the college is based. Rather than being customized to my browsing/locality.
- Fiahil 4y agoThis used to be the case before "they" thought having personalized ads would drive up interest.
- formerkrogemp 4y agoI can confirm that, based upon google research, the "Ozark Technical Community College" is in the Ozark Mountains of Missouri and Arkansas. More or less.
- solenoidalslide 4y ago> The loss of the funds will not affect students, classes or operations, states the release. Are organizations liable when they make statements like this? Suppose operations actually are affected and the college intentionally misrepresented the consequences of the fraud—are there grounds for legal recourse by students and future students?
- ceejayoz 4y agoI would assume they can say this due to having insurance coverage.
- deleted 4y ago[deleted]
- formerkrogemp 4y agoIt might just be a phrase to reassure stakeholders not to panic and rethink potential or existing relationships with the college of fears of incompetence.
- duxup 4y agoIs there some reason to think that these things will be effected? I read that as "yeah keep coming to class, everyone will get paid, the lights will be on". I don't see why that wouldn't be true.
- leephillips 4y agoIf you have been harmed by the statement of the college, the legal recourse would be to sue them and bring evidence of the actual harm.
- civilized 4y agoI feel like spammers and cyber criminals are getting better. Stuff is starting to get through Google spam filter by mashing up with elements that seem very real and urgent. Like yesterday I got this spam in my Gmail primary inbox with a subject line like "RE: Department of Education Case #295720186". It made me wonder if you could autogenerate filter-evading spam using GANs? Train a GAN to generate email that fools a spam filter, feed it your spam prompt, and the neural network camouflages your prompt in filter-evading cruft and misdirection.
- Swizec 4y agoOn the other hand, I’m seeing more and more legitimate stuff land in Gmail’s spam filter. Like virtually of San Francisco Marathon’s newsletters. Sure they’re pushy and really really want you to sign up for more races and I definitely need to unsubscribe … but I did subscribe and that means it isn’t spam.
- ghaff 4y agoOne of the things that I assume happens is that, even when people have explicitly signed up for something or at least not opted out of receiving updates etc., they'll just "report spam" rather than unsubscribe and when enough people do this it gets put in everyone's spam folder unless enough people reclassify it. There's not much stuff that ends up in my spam folder that I really care about and a fair bit I don't know how I got on some list. But relatively little of it is spam in the usual meaning of the term.
- everforward 4y ago> at least not opted out of receiving updates etc I still consider that spam; successfully hiding the checkbox from me doesn't mean that I want the emails. I report them as spam in the hopes that it will force them to switch to an opt-in system.
- qiskit 4y ago> they'll just "report spam" rather than unsubscribe I'm guessing this is a major part of it. But then again, if a legitimate service is so spammy that people will just "report as spam" rather than unsubscribing, maybe they should change their behavior.
- propter_hoc 4y ago> "Although the blame for this incident rests squarely on the criminals who committed this act“ Hm, and the inadequate financial controls structure of the college.
- vmception 4y agoRight but when there is a victim its because someone did an illegal or victim creating action. We don't blame the victim for the success rate of the perpetrator, because it was still up to the perpetrator to do the action to create the victim. I’m curious about the details here, like if they swapped out wire details in the system or made a whole bank account in the vendors name etc
- latchkey 4y agoWe just got a spear phishing email to one of our finance department people. It appeared "From" the CEO. Must have pulled the names from LinkedIn. Had some legitimate company in the email. Turns out that company even has a fraud page on their website since so many people seem to get these emails. It must work enough that the scammers keep trying. https://www.nortonrosefulbright.com/en/global-statement/fraud-alerts https://www.nortonrosefulbright.com/en/global-statement/frau...
- cookiengineer 4y ago> 451: Unavailable due to legal reasons > We recognize you are attempting to access this website from a country belonging to the European Economic Area (EEA) including the EU which enforces the General Data Protection Regulation (GDPR) and therefore access cannot be granted at this time. For any issues, contact internet@bransontrilakesnews.com or call 417-334-3161. lol. Archive link for other Europeans: https://archive.ph/YtPLb https://archive.ph/YtPLb
- mamouri 4y agohttps://archive.ph/YtPLb https://archive.ph/YtPLb The site is not available for European visiotrs due to legal reasons: >>> We recognize you are attempting to access this website from a country belonging to the European Economic Area (EEA) including the EU which enforces the General Data Protection Regulation (GDPR) and therefore access cannot be granted at this time.
- Kerrick 4y agoFor websites with specifically-American audiences, it can often be easier to only allow people from their intended readership access than to correctly understand and implement compliance to a foreign law. In this case, it's a local news website.
- ricardobeat 4y agoIt’s not that complicated. Just don’t collect any private/profiling information and you’re good. They’d probably rather stay with a more limited audience that keeps their ad CTRs up, than dilute the numbers with unmonetized visitors.
- ahtihn 4y agoWhy would a local news site care about GDPR compliance? It's not like enforcement is even feasible.
- kovalevski 4y agois it not just promotion for new season of Netflix's Ozark?
- adamgordonbell 4y agoWon't load for me. Here is a text archive: https://earthly-tools.com/text-mode?url=https://www.bransontrilakesnews.com/news/local/article_0a6f60d4-c25a-11ec-9270-1b30a93475bc.html https://earthly-tools.com/text-mode?url=https://www.bransont...