Email Payment Scam, Who is responsible?
Discussion
To add to my want to get out of the stresses of self employed another bomb dropped its self off today.....
Basically I emailed over a £2K invoice to a regular customer, who replied a few days later with " no problems, have send this over to your new account"
Transpires, they had an email either from me or looking like from me asking for the invoice to be paid to a new bank account.
And they paid it straight to this account without contacting me!! my bank details are clearly at the bottom of the invoice.
Clearly one of our email accounts has been hacked, I cannot see any evidence it came from my account.
Really pissed of that you would just send £2K without confirming. I thought these scams were fairly known about?
But I guess the question is who is responsible for this? does it depend on who's email was hacked?
Basically I emailed over a £2K invoice to a regular customer, who replied a few days later with " no problems, have send this over to your new account"
Transpires, they had an email either from me or looking like from me asking for the invoice to be paid to a new bank account.
And they paid it straight to this account without contacting me!! my bank details are clearly at the bottom of the invoice.
Clearly one of our email accounts has been hacked, I cannot see any evidence it came from my account.
Really pissed of that you would just send £2K without confirming. I thought these scams were fairly known about?
But I guess the question is who is responsible for this? does it depend on who's email was hacked?
Watching a recent episode of 'The Sheriffs are Coming' a few weeks ago a very identical story was covered, ended up with the person being owed the money taking the debtor to court and winning, debtor didn't pay so the CCJ was given to the sheriffs to obtain payment, debtor was (obviously) pee'd off as he had now paid the same invoice twice!
Contract Killer said:
Clearly one of our email accounts has been hacked, I cannot see any evidence it came from my account.
It could have been either account. In most types of email account if you have access to the account you can create fake emails directly in the Inbox appearing to have come from the recipient, this will bypass fraud/spoofing checks etc. If it was your account, they could have sent the emails from the account and deleted them from the Sent folder, simultaneously with you accessing it as normal.In case it was yours, first thing is to change your password immediately and enable 2-factor authentication if not already done. There may be logs of sessions open available, check these and terminate any you don't recognise (although changing the password should do this).
Contract Killer said:
To add to my want to get out of the stresses of self employed another bomb dropped its self off today.....
Basically I emailed over a £2K invoice to a regular customer, who replied a few days later with " no problems, have send this over to your new account"
Transpires, they had an email either from me or looking like from me asking for the invoice to be paid to a new bank account.
And they paid it straight to this account without contacting me!! my bank details are clearly at the bottom of the invoice.
Clearly one of our email accounts has been hacked, I cannot see any evidence it came from my account.
Really pissed of that you would just send £2K without confirming. I thought these scams were fairly known about?
But I guess the question is who is responsible for this? does it depend on who's email was hacked?
Obviously you will want to ensure that you haven't been hacked - however, that doesn't take away from the fact that the person sending you money should have confirmed the bank details and more so if informed of a change.Basically I emailed over a £2K invoice to a regular customer, who replied a few days later with " no problems, have send this over to your new account"
Transpires, they had an email either from me or looking like from me asking for the invoice to be paid to a new bank account.
And they paid it straight to this account without contacting me!! my bank details are clearly at the bottom of the invoice.
Clearly one of our email accounts has been hacked, I cannot see any evidence it came from my account.
Really pissed of that you would just send £2K without confirming. I thought these scams were fairly known about?
But I guess the question is who is responsible for this? does it depend on who's email was hacked?
I won't name names, however a relative of mine works for a large charity and they were hit with email claiming to be a company who completes research for the charity and informing them that bank details had changed.
Initially this was processed without any kind of checking at all and the charity transferred £20k to a completely unknown bank account (Cyber securities, banks etc managed to claw back £10k of this).
Thankfully the same didn't happen on a much larger account with around £200k involved.
I don't know about you - however if somebody is asking me to pay via a bank transfer I like to confirm and double-check those bank details and I would never accept a "change of bank details" any other way than face-to-face or via me calling said company and checking the details.
otolith said:
Unlikely that you have been hacked, it's trivially easy to make an email look like it comes from someone else.
But the scammer would have to know some particulars, and have some contact list to know there was a relationship between the entities. Doesn't necessarily mean the OP was hacked, could just as easily be an intermediary (e.g. webmail portal) or the person sending the money.CzechItOut said:
How easy would it be to sit in the middle of email traffic looking for mails with the subject containing "invoice" and an attachment?
The email is then intercepted, attachment edited and then forwarded on. Completely seamless to the recipient and no need to "hack" email accounts?
How do you propose to sit in the middle?The email is then intercepted, attachment edited and then forwarded on. Completely seamless to the recipient and no need to "hack" email accounts?
It's much easier to get a naive user to click on a spoofed email and install malware... or a spoofed web page and handover the password.
The hacker doesn't change it, just logs in and looks at sent mail.
Hacking is (relatively) easy through social engineering, malware, spoofed emails.
Vaud said:
How do you propose to sit in the middle?
It's much easier to get a naive user to click on a spoofed email and install malware... or a spoofed web page and handover the password.
The hacker doesn't change it, just logs in and looks at sent mail.
Hacking is (relatively) easy through social engineering, malware, spoofed emails.
No idea.It's much easier to get a naive user to click on a spoofed email and install malware... or a spoofed web page and handover the password.
The hacker doesn't change it, just logs in and looks at sent mail.
Hacking is (relatively) easy through social engineering, malware, spoofed emails.
It just seems a remarkable coincidence that the email account of someone who either sends large invoices or receives large invoices just happens to be vulnerable at the time a request for payment is made/received.
CzechItOut said:
How easy would it be to sit in the middle of email traffic looking for mails with the subject containing "invoice" and an attachment?
The email is then intercepted, attachment edited and then forwarded on. Completely seamless to the recipient and no need to "hack" email accounts?
In the case of unencrypted email (e.g. systems not using TLS between SMTP servers for example) it is technically possible to view / intercept* the email in transit, but not possible to stop it reaching the intended recipient.The email is then intercepted, attachment edited and then forwarded on. Completely seamless to the recipient and no need to "hack" email accounts?
A lot of systems use TLS encryption between SMTP servers these days, and in that case the email will be encrypted and hence impossible to view / intercept.
A few years back, a company I worked for monitored all internet traffic, and anything that wasn't encrypted was fair game (we used an app called SessionWall).
This crap is scarily common. We have to confirm all new bank details now by phone. Some are easy to spot though, I think I could spot any potentially odd ones, but we have to do the phone confirmation anyway to tick the box.
There's also one I get from time to time pretending to be my director asking me to urgently send payment to X. It must catch out some. Luckily for me, I know I would never get such an email.
Banks are getting wiser to it. When I change the account details for one of our suppliers I now get warning messages. Or even when I just add a new supplier or pay to a one off account. The bank is quick to tell me I'm liable if it's a scam.
Regardless though, it's not you that has been scammed, it's your customer.
There's also one I get from time to time pretending to be my director asking me to urgently send payment to X. It must catch out some. Luckily for me, I know I would never get such an email.
Banks are getting wiser to it. When I change the account details for one of our suppliers I now get warning messages. Or even when I just add a new supplier or pay to a one off account. The bank is quick to tell me I'm liable if it's a scam.
Regardless though, it's not you that has been scammed, it's your customer.
I cannot believe that people still rely on emails with bank account details on as this scam has been going on for years.
I heard a story that someone from Antigua lost over a million dollars so he hired some private detectives they traced the money back to the UK but was then told not to pursue the matter any further as it could affect his health.
When we changed our businessbank account 5 years ago it was a nightmare getting some of thecompanies to change the bank details.
I heard a story that someone from Antigua lost over a million dollars so he hired some private detectives they traced the money back to the UK but was then told not to pursue the matter any further as it could affect his health.
When we changed our businessbank account 5 years ago it was a nightmare getting some of thecompanies to change the bank details.
If more of your customers pop up and say they've paid you, but you've not received the cash then you have been hacked and they've conned your customers based on information they've got from your system.
Is the work you or your customer do particularly publicised? I mean they could have been hacked, and they've picked you as their biggest supplier to fake bank change... but equally possible its a speculative attack if a deal between your companies has been publicised... i.e they know that you supply that company from press.
Anyway; if your company does end up being the one hacked then you're not responsible for the lost cash, but you may want to consider how pissed off all your customers will be if they're out of pocket because you got hacked.
If its just the one, then they need to employ a better finance bod and chalk this up to experience... and pay you what they owe.
Is the work you or your customer do particularly publicised? I mean they could have been hacked, and they've picked you as their biggest supplier to fake bank change... but equally possible its a speculative attack if a deal between your companies has been publicised... i.e they know that you supply that company from press.
Anyway; if your company does end up being the one hacked then you're not responsible for the lost cash, but you may want to consider how pissed off all your customers will be if they're out of pocket because you got hacked.
If its just the one, then they need to employ a better finance bod and chalk this up to experience... and pay you what they owe.
Old Merc said:
Your customer is the one who has fallen for a scam and been conned out of the money. Your bill has not been paid yet,so your out of pocket as well.
I suspect your quite entitled to get your customer to pay your invoice.
Occasionally for work, I have to complete recognised (by the FCA) mandatory regulatory training for a lots of related subjects. A recent one was around data protection and phishing/AML.I suspect your quite entitled to get your customer to pay your invoice.
They actually used what happened to the OP's customer as an example case, and scored you on the answered to some key questions about it.
In in nutshell it was noted that it was THEIR mistake for not checking the details and they would now be out of pocket as they had to compensate the supplier.
'THEIR' mistake due to their lack of controls.
Gassing Station | Speed, Plod & the Law | Top of Page | What's New | My Stuff



tting you to buy more time before paying.