Email Payment Scam, Who is responsible?
Email Payment Scam, Who is responsible?
Author
Discussion

Contract Killer

Original Poster:

4,508 posts

212 months

Wednesday 1st May 2019
quotequote all
To add to my want to get out of the stresses of self employed another bomb dropped its self off today.....


Basically I emailed over a £2K invoice to a regular customer, who replied a few days later with " no problems, have send this over to your new account"


Transpires, they had an email either from me or looking like from me asking for the invoice to be paid to a new bank account.

And they paid it straight to this account without contacting me!! my bank details are clearly at the bottom of the invoice.


Clearly one of our email accounts has been hacked, I cannot see any evidence it came from my account.

Really pissed of that you would just send £2K without confirming. I thought these scams were fairly known about?


But I guess the question is who is responsible for this? does it depend on who's email was hacked?


Brads67

3,199 posts

127 months

Wednesday 1st May 2019
quotequote all
You're brave putting that on here. PH will just assume you are vunerable and therefore stupid.

Saleen836

12,503 posts

238 months

Wednesday 1st May 2019
quotequote all
Watching a recent episode of 'The Sheriffs are Coming' a few weeks ago a very identical story was covered, ended up with the person being owed the money taking the debtor to court and winning, debtor didn't pay so the CCJ was given to the sheriffs to obtain payment, debtor was (obviously) pee'd off as he had now paid the same invoice twice!

Gareth79

9,044 posts

275 months

Thursday 2nd May 2019
quotequote all
Contract Killer said:
Clearly one of our email accounts has been hacked, I cannot see any evidence it came from my account.
It could have been either account. In most types of email account if you have access to the account you can create fake emails directly in the Inbox appearing to have come from the recipient, this will bypass fraud/spoofing checks etc. If it was your account, they could have sent the emails from the account and deleted them from the Sent folder, simultaneously with you accessing it as normal.

In case it was yours, first thing is to change your password immediately and enable 2-factor authentication if not already done. There may be logs of sessions open available, check these and terminate any you don't recognise (although changing the password should do this).




otolith

68,901 posts

233 months

Thursday 2nd May 2019
quotequote all
Unlikely that you have been hacked, it's trivially easy to make an email look like it comes from someone else.

Stoofa

959 posts

197 months

Thursday 2nd May 2019
quotequote all
Contract Killer said:
To add to my want to get out of the stresses of self employed another bomb dropped its self off today.....


Basically I emailed over a £2K invoice to a regular customer, who replied a few days later with " no problems, have send this over to your new account"


Transpires, they had an email either from me or looking like from me asking for the invoice to be paid to a new bank account.

And they paid it straight to this account without contacting me!! my bank details are clearly at the bottom of the invoice.


Clearly one of our email accounts has been hacked, I cannot see any evidence it came from my account.

Really pissed of that you would just send £2K without confirming. I thought these scams were fairly known about?


But I guess the question is who is responsible for this? does it depend on who's email was hacked?
Obviously you will want to ensure that you haven't been hacked - however, that doesn't take away from the fact that the person sending you money should have confirmed the bank details and more so if informed of a change.

I won't name names, however a relative of mine works for a large charity and they were hit with email claiming to be a company who completes research for the charity and informing them that bank details had changed.
Initially this was processed without any kind of checking at all and the charity transferred £20k to a completely unknown bank account (Cyber securities, banks etc managed to claw back £10k of this).
Thankfully the same didn't happen on a much larger account with around £200k involved.

I don't know about you - however if somebody is asking me to pay via a bank transfer I like to confirm and double-check those bank details and I would never accept a "change of bank details" any other way than face-to-face or via me calling said company and checking the details.

Durzel

12,999 posts

197 months

Thursday 2nd May 2019
quotequote all
otolith said:
Unlikely that you have been hacked, it's trivially easy to make an email look like it comes from someone else.
But the scammer would have to know some particulars, and have some contact list to know there was a relationship between the entities. Doesn't necessarily mean the OP was hacked, could just as easily be an intermediary (e.g. webmail portal) or the person sending the money.

Vaud

59,510 posts

184 months

Thursday 2nd May 2019
quotequote all
It's more likely that they have been hacked and that the scammer has found details in their emails to then fake a believable email.

Old Merc

3,819 posts

196 months

Thursday 2nd May 2019
quotequote all
Your customer is the one who has fallen for a scam and been conned out of the money. Your bill has not been paid yet,so your out of pocket as well.
I suspect your quite entitled to get your customer to pay your invoice.

CzechItOut

2,156 posts

220 months

Thursday 2nd May 2019
quotequote all
How easy would it be to sit in the middle of email traffic looking for mails with the subject containing "invoice" and an attachment?

The email is then intercepted, attachment edited and then forwarded on. Completely seamless to the recipient and no need to "hack" email accounts?

Vaud

59,510 posts

184 months

Thursday 2nd May 2019
quotequote all
CzechItOut said:
How easy would it be to sit in the middle of email traffic looking for mails with the subject containing "invoice" and an attachment?

The email is then intercepted, attachment edited and then forwarded on. Completely seamless to the recipient and no need to "hack" email accounts?
How do you propose to sit in the middle?

It's much easier to get a naive user to click on a spoofed email and install malware... or a spoofed web page and handover the password.

The hacker doesn't change it, just logs in and looks at sent mail.

Hacking is (relatively) easy through social engineering, malware, spoofed emails.

Fulmentaljack3t

111 posts

135 months

Thursday 2nd May 2019
quotequote all
Could a business partner/employee/family member have sent the invoice? Maybe desperate for money/have a grudge against you?...

CzechItOut

2,156 posts

220 months

Thursday 2nd May 2019
quotequote all
Vaud said:
How do you propose to sit in the middle?

It's much easier to get a naive user to click on a spoofed email and install malware... or a spoofed web page and handover the password.

The hacker doesn't change it, just logs in and looks at sent mail.

Hacking is (relatively) easy through social engineering, malware, spoofed emails.
No idea.

It just seems a remarkable coincidence that the email account of someone who either sends large invoices or receives large invoices just happens to be vulnerable at the time a request for payment is made/received.

TonyRPH

13,539 posts

197 months

Thursday 2nd May 2019
quotequote all
CzechItOut said:
How easy would it be to sit in the middle of email traffic looking for mails with the subject containing "invoice" and an attachment?

The email is then intercepted, attachment edited and then forwarded on. Completely seamless to the recipient and no need to "hack" email accounts?
In the case of unencrypted email (e.g. systems not using TLS between SMTP servers for example) it is technically possible to view / intercept* the email in transit, but not possible to stop it reaching the intended recipient.

A lot of systems use TLS encryption between SMTP servers these days, and in that case the email will be encrypted and hence impossible to view / intercept.

A few years back, a company I worked for monitored all internet traffic, and anything that wasn't encrypted was fair game (we used an app called SessionWall).




Drew106

1,652 posts

174 months

Thursday 2nd May 2019
quotequote all
This crap is scarily common. We have to confirm all new bank details now by phone. Some are easy to spot though, I think I could spot any potentially odd ones, but we have to do the phone confirmation anyway to tick the box.

There's also one I get from time to time pretending to be my director asking me to urgently send payment to X. It must catch out some. Luckily for me, I know I would never get such an email.

Banks are getting wiser to it. When I change the account details for one of our suppliers I now get warning messages. Or even when I just add a new supplier or pay to a one off account. The bank is quick to tell me I'm liable if it's a scam.

Regardless though, it's not you that has been scammed, it's your customer.

hunton69

674 posts

166 months

Thursday 2nd May 2019
quotequote all
I cannot believe that people still rely on emails with bank account details on as this scam has been going on for years.
I heard a story that someone from Antigua lost over a million dollars so he hired some private detectives they traced the money back to the UK but was then told not to pursue the matter any further as it could affect his health.
When we changed our businessbank account 5 years ago it was a nightmare getting some of thecompanies to change the bank details.

Rivenink

4,292 posts

135 months

Thursday 2nd May 2019
quotequote all
If more of your customers pop up and say they've paid you, but you've not received the cash then you have been hacked and they've conned your customers based on information they've got from your system.

Is the work you or your customer do particularly publicised? I mean they could have been hacked, and they've picked you as their biggest supplier to fake bank change... but equally possible its a speculative attack if a deal between your companies has been publicised... i.e they know that you supply that company from press.


Anyway; if your company does end up being the one hacked then you're not responsible for the lost cash, but you may want to consider how pissed off all your customers will be if they're out of pocket because you got hacked.

If its just the one, then they need to employ a better finance bod and chalk this up to experience... and pay you what they owe.


Oakey

27,982 posts

245 months

Thursday 2nd May 2019
quotequote all
Option C. He's bullstting you to buy more time before paying.

Mandalore

5,457 posts

142 months

Thursday 2nd May 2019
quotequote all
Brads67 said:
You're brave putting that on here. PH will just assume you are vunerable and therefore stupid.
Not everyone is like you.

Or, was that the point??

Mandalore

5,457 posts

142 months

Thursday 2nd May 2019
quotequote all
Old Merc said:
Your customer is the one who has fallen for a scam and been conned out of the money. Your bill has not been paid yet,so your out of pocket as well.
I suspect your quite entitled to get your customer to pay your invoice.
Occasionally for work, I have to complete recognised (by the FCA) mandatory regulatory training for a lots of related subjects. A recent one was around data protection and phishing/AML.

They actually used what happened to the OP's customer as an example case, and scored you on the answered to some key questions about it.

In in nutshell it was noted that it was THEIR mistake for not checking the details and they would now be out of pocket as they had to compensate the supplier.

'THEIR' mistake due to their lack of controls.