3 ms·
“We can’t provide all of the specifics at this time,” Higdon said, “but it appears the criminals succeeded in impersonating one of our vendors online and direct
by Fargoan 4y ago
“We can’t provide all of the specifics at this time,” Higdon said, “but it appears the criminals succeeded in impersonating one of our vendors online and directed payments from the college into a fraudulent account.”
- so they sent a fake invoice and the college paid it?
- bluejekyll 4y agoI read that more as someone called the school and said something like: “hi, I’m calling from vendor X you usually pay into our bank account ABC, but due to some reason, we’ve needed to close that account. Can you please update that account to DEF and make all future payments there?”
- jeroenhd 4y agoThere are more and more reports of serious phishing attempts that do not rely on mere fake emails, but involve criminals breaking into a business' infrastructure, observing mail (and sometimes even call) flow for a while (this can take months!) and waiting for an opportune moment to strike. They'll use the real company's infrastructure to send an invoice or email in the middle of an existing project that goes unnoticed for long enough to hit several clients. By the time the client and the hacked company start arguing about who paid what bill when into what account, the criminals are already out and moving on to their next target. Not many people are prepared for these attacks. All the standard checks for phishing scams (sender, subject, language used, information repeated, technical measures like SPF and DKIM) pass with flying colours. You need to be wary of every single email from legitimate contacts to protect yourself from such a threat. Such hacks target businesses (because huge b2b transactions are common enough) but also wealthy individuals contracting companies. Anyone capable of wiring out a sum of money large enough to make months of work for the (probably third world) salaries of the people involved in the operation worth it can be a target. There are plenty of people who will fall for your old "we're the IRS, pay us Google Play gift cards" scam and even a fake invoice from an unknown company sometimes gets paid by a billing department that doesn't care about their jobs, but not every scam victim fell for some comically obvious scam. In the real world, real companies don't stick to best practices ("hi we're your bank. No you can't call us back to verify") and as long as legitimate companies send weird bills or make weird payment requests, scammers will find ways to mislead people.
- cookie_monsta 4y agoHere's another such example. The red flags are there, in hindsight: https://ia.acs.org.au/article/2020/ice-rink-loses--77k-in-email-scam.html https://ia.acs.org.au/article/2020/ice-rink-loses--77k-in-em...
- formerkrogemp 4y agoThey pretended to be the vendor and probably got the college to "update" vendor payment info to the fraudster's controlled account's details.