Scammed
Author
Discussion

MAVROS

Original Poster:

116 posts

193 months

Sunday 17th September 2017
quotequote all
The wife sent a large sum of money to one of our suppliers after an email request from them. Turns out their account was hacked and the money was sent to an account abroad. The receiving bank have said they intercepted the transaction but can't say whether any money was drawn out or how much. It's going to take up to six weeks for it to be sorted out. In the meantime we're largely left in limbo awaiting the banks action.
We've contacted Actionfraud, the police, trading standards, the hacked company, our own bank and taken advice from our solicitors. A detective constable friend says this smacks of an inside job from the receiving company due to the number of emails sent prior to the fraud taking place. I'd like any advice on what else I can do whilst I wait for the bank to sort this mess out. Should I commission my own computer expert to compile a report on what happened maybe even check my suppliers computers if they'd allow it? Can anybody recommend any experts in this field who can help?

Behemoth

2,105 posts

161 months

Sunday 17th September 2017
quotequote all
You could explore the email trail by investigating the full email headers closely to see if you can find the source of the phish (presuming that's what happened). There are a number of good guides on the web for this if you search "full email header detect phishing" or sthg similar. Somewhere, you should spot a rogue domain or IP address.

red_slr

20,780 posts

219 months

Sunday 17th September 2017
quotequote all
We have had a very similar issue but no money exchanged hands. We are a small company so I make all orders and knew I had not placed the order. It was totally different from orders we placed in the past and that supplier invoices us at the end of the month rather than ad hoc.

That said, it was scary, very well executed and probably easily catch loads out. They had clearly intercepted emails in the past. This was about 2 months ago. I am fairly confident it was our email server that was the weakness, although our IT provider suggested they "just got lucky".. A few weeks later we were black listed several times with spamhaus.

I plan to upgrade our email at some point before the end of the year but irks me because we now have to spend £££ a year on upgraded email platform. Hmm.

Anyway, good luck hope you get the money back.


randlemarcus

13,646 posts

261 months

Sunday 17th September 2017
quotequote all
red_slr said:
We have had a very similar issue but no money exchanged hands. We are a small company so I make all orders and knew I had not placed the order. It was totally different from orders we placed in the past and that supplier invoices us at the end of the month rather than ad hoc.

That said, it was scary, very well executed and probably easily catch loads out. They had clearly intercepted emails in the past. This was about 2 months ago. I am fairly confident it was our email server that was the weakness, although our IT provider suggested they "just got lucky".. A few weeks later we were black listed several times with spamhaus.

I plan to upgrade our email at some point before the end of the year but irks me because we now have to spend £££ a year on upgraded email platform. Hmm.

Anyway, good luck hope you get the money back.
Look at biting that bullet and moving to something like GSuite or 365, rather than just paying more for a server of your own....

nyt

1,939 posts

180 months

Sunday 17th September 2017
quotequote all
You should have your network looked at.
It's possible that the perpetrators included malevolent software in the emails that you activated by opening Word/PDF/other files.

red_slr

20,780 posts

219 months

Sunday 17th September 2017
quotequote all
It was opened on a secure machine by IT.

red_slr

20,780 posts

219 months

Sunday 17th September 2017
quotequote all
randlemarcus said:
red_slr said:
We have had a very similar issue but no money exchanged hands. We are a small company so I make all orders and knew I had not placed the order. It was totally different from orders we placed in the past and that supplier invoices us at the end of the month rather than ad hoc.

That said, it was scary, very well executed and probably easily catch loads out. They had clearly intercepted emails in the past. This was about 2 months ago. I am fairly confident it was our email server that was the weakness, although our IT provider suggested they "just got lucky".. A few weeks later we were black listed several times with spamhaus.

I plan to upgrade our email at some point before the end of the year but irks me because we now have to spend £££ a year on upgraded email platform. Hmm.

Anyway, good luck hope you get the money back.
Look at biting that bullet and moving to something like GSuite or 365, rather than just paying more for a server of your own....
Yes I agree! I think we are going to go with a web based platform.

hunton69

674 posts

167 months

Sunday 17th September 2017
quotequote all
Do you ever watch the news the scam is so common.
These scammers have systems in place that pick up certain words which refer to money transfers and then intercept the email trail. Simple phone call to the client to confirm bank details prevents.
Whats app is secure but I would also confirm by phone

hunton69

674 posts

167 months

Sunday 17th September 2017
quotequote all
A very very rich chap in the carribean lost 1.5 million dollars this why so got a dozen private detectives on the case he got very close to discovering where the money went but was then advised to back off.
The gang involved were in the UK

Paddymcc

1,305 posts

221 months

Sunday 17th September 2017
quotequote all
Happened a close friend the other week whom has finished building his house.

Received an email from the kitchen installers looking the balance paid and an invoice included in the email. The wife paid it using their credit card luckily.

Few weeks later the kitchen installers rang looking payment and the scam was duly uncovered.

nyt

1,939 posts

180 months

Sunday 17th September 2017
quotequote all
red_slr said:
It was opened on a secure machine by IT.
The original email was opened securely by IT?

But you have an IT department so they'll be on top of any malware. No need to be concerned on that front.

yajeed

5,057 posts

284 months

Sunday 17th September 2017
quotequote all
MAVROS said:
The wife sent a large sum of money to one of our suppliers after an email request from them. Turns out their account was hacked and the money was sent to an account abroad. The receiving bank have said they intercepted the transaction but can't say whether any money was drawn out or how much. It's going to take up to six weeks for it to be sorted out. In the meantime we're largely left in limbo awaiting the banks action.
We've contacted Actionfraud, the police, trading standards, the hacked company, our own bank and taken advice from our solicitors. A detective constable friend says this smacks of an inside job from the receiving company due to the number of emails sent prior to the fraud taking place. I'd like any advice on what else I can do whilst I wait for the bank to sort this mess out. Should I commission my own computer expert to compile a report on what happened maybe even check my suppliers computers if they'd allow it? Can anybody recommend any experts in this field who can help?
If you want someone to give the email a once over, then PM me and I'll take a look/ask someone to, depending on how sophisticated it is. If it's simply a plain old phishing email rather than a malicious file that could do further damage, it'll give you at least some assurance of what to/not to do next.

I don't pretend to be the NSA, however, I can give you an indication of my team's background if it'd make you feel more comfortable disclosing the information.

Reading that back, this isn't a bid for work, just a favour for a fellow petrolhead.

SantaBarbara

3,244 posts

138 months

Sunday 17th September 2017
quotequote all
You need to have a controlled Authorised Payee file and rigorously. Control amendment. To it

bitchstewie

67,807 posts

240 months

Sunday 17th September 2017
quotequote all
The best thing you can do is invest in training and awareness and put in place measure so this kind of thing can't happen again.

You shouldn't be changing bank/supplier details just off the back of an email - it's too easy to spoof.

yajeed

5,057 posts

284 months

Sunday 17th September 2017
quotequote all
nyt said:
The original email was opened securely by IT?

But you have an IT department so they'll be on top of any malware. No need to be concerned on that front.
I couldn't work out whether that was tongue in cheek or not. IT departments generally have little clue about malware or the analysis thereof, other than how to install an AV client.

That said, some (typically larger corporations) have the necessary skillset. If you work for one of them, you'll be getting a knock on your office door when they discover you've disclosed this publicly ;-)

red_slr

20,780 posts

219 months

Sunday 17th September 2017
quotequote all
nyt said:
red_slr said:
It was opened on a secure machine by IT.
The original email was opened securely by IT?

But you have an IT department so they'll be on top of any malware. No need to be concerned on that front.
IT is outsourced.

It was identified as being sus. IT then opened it securely to see what the actual content was. (it was a pdf).

nyt

1,939 posts

180 months

Sunday 17th September 2017
quotequote all
yajeed said:
nyt said:
The original email was opened securely by IT?

But you have an IT department so they'll be on top of any malware. No need to be concerned on that front.
I couldn't work out whether that was tongue in cheek or not. IT departments generally have little clue about malware or the analysis thereof, other than how to install an AV client.

That said, some (typically larger corporations) have the necessary skillset. If you work for one of them, you'll be getting a knock on your office door when they discover you've disclosed this publicly ;-)
Not tongue in cheek at all - but I see how you could have interpreted it like that. My bad.

Had the OP been a small company with no IT at all, there was a risk that there might have been an additional, unwelcome payload included with the original emails that was activated when he opened attachments and was undetected.
The fact that he has an IT department and they subsequently opened the emails on an isolated machine suggested that they were on top of the situation.

Apologies for being unclear and best of luck to the OP

yajeed

5,057 posts

284 months

Sunday 17th September 2017
quotequote all
red_slr said:
IT is outsourced.

It was identified as being sus. IT then opened it securely to see what the actual content was. (it was a pdf).
OK. Was the PDF malicious? It'll be one of two things:

1) In PDF format to make it look legitimate and hide the contents from a rudimentary keyword scanner
2) To take advantage of a vulnerability in the software you use to read the PDF, and install some more malicious software.

If it's 1) then your potential loss is the sum you transferred
If it's 2) then your loss could be potentially larger, and needs to be further investigated.

Clearly your wife opened the PDF before IT did, so whether they did it safely or not is relatively unimportant.

edited to add: Unless I've misunderstood and the PDF was stripped from the email, but the email not blocked, so your wife just acted on the text in the body of the message that was delivered to her.


Edited by yajeed on Sunday 17th September 13:38

yajeed

5,057 posts

284 months

Sunday 17th September 2017
quotequote all
nyt said:
The fact that he has an IT department and they subsequently opened the emails on an isolated machine suggested that they were on top of the situation.
If I had a penny for everytime I'd heard that and it turned out not to be the case, I'd have several more pennies ;-)

I wonder if Sony Entertainment had an IT department?

nyt

1,939 posts

180 months

Sunday 17th September 2017
quotequote all
yajeed said:
nyt said:
The fact that he has an IT department and they subsequently opened the emails on an isolated machine suggested that they were on top of the situation.
If I had a penny for everytime I'd heard that and it turned out not to be the case, I'd have several more pennies ;-)

I wonder if Sony Entertainment had an IT department?
Reading the original post, it looked like the OP might have been a husband and wife business. In fact there's an IT department who can look into for the OP, so further warnings seemed necessary.

We've made the OP aware that there might be a risk.
He has an IT department to talk to.
He already enough on his plate.
That's should be enough.