The 'bogus boss' email scam costing firms millions
bbc.com
bbc.com
The final email will be sent from a very similar email domain: the scammers register a domain with a simple letter/number substitution that is VERY difficult to visually detect if you aren't looking. Many were registered with VistaPrint, who offer free registration of domains on a trial plan, or something. You can see a list of their recently-registered domains here http://vistaprinta.tk/, if you scan through it you'll see some misspellings and l/1 switcheroos. (I spoke with someone at Vistaprint who indicated that they are actively working on this problem, and they have taken quick action when requested).
When my clients ask me to take a technology approach on these matters, I encourage them to treat it as a process issue instead. Having adequate controls for issues like this (phone call required, second approver for large wire transfers, etc) is better than any futile spam-blocking action we could take.
In 1998 I was able to use SMTP to send an email "from Bill Gates" (only sent it to myself for my own personal amusement), but the trick stopped working later.
When verification is easy, people do more of it.
I did this just by opening a telnet session to the SMTP port at apple.com and manually typing in SMTP commands and associated text.
Apple's SMTP server happily delivered a fake email from agrove@intel.com from a system at ucdavis.edu.
Lol, those were the days....
* thompsonenteprises.com
* uberpromo.info
* kinneyconstructiion.com
* blackbeartactical.com (real domain: blackbeardtactical.com)
Yes, in the general case PKI is a broken and web-of-trust is hard to bootstrap, but protection against scams like this don't need to solve the general case. Distributing keys internally isn't hard. Even some communication external to the organization should be easily authenticated with pubkey crypto - it's not more difficult than the business contracts everybody already uses regularly.
Why is everybody trying to solve this with email headers or fallible human judgment?
The only thing that should even be relevant re: usability is the need to occasionally enter a password. This is even minimized with gpg-agent (or similar), which we can assume is something that would be setup by IT anyway along with everything else related to email.
> C suite
Then educate them about the need. Even better, educate the lawyers about why authorizing large purchases (i.e. the type of scam currently being discussed) without proper authentication is an unacceptable risk.
> it can't help to prevent things like this
While you cannot fix a stupid CxO, the problem of deciding if a particular email claiming to to be from that CxO authorizing a purchase order is actually from that CxO is easy.
Remember, we only need to solve the internal case, where it is easy to setup PKI. I believe there are even several solutions already available[1] for directory services and key management. Run some sort of local directory service and a local CA and a decent email client should make authentically completely transparent for internal emails.
Nothing is trivial with mutt, especially not GPG related issues. If it seems easy to you then you're a very skilled outlier.
Sincerely,
A Mutt user for three or four years
Configuring it to use pgp (way before gpg existed) was a bit of a challenge years ago. I certainly wouldn't recommend it to most people today. At the time, most email programs required some technical knowledge to setup, so the difficulty is relative.
My point is that these solutions have existed for a long time, even in what many would now call the "earlier" years of email. Even decades ago it was common to have the setup within and organization handled by IT.
// mutt still wins over more "modern" email software in a lot of ways
We need to fix this problem for the accountants, not the IT guys.
I think you're getting downvoted in this thread because while you're trying to make a distinction between difficulty of setup and difficulty of use, the waters have already been poisoned by so many people that (wrongly) say "FOSS tools like mutt are easy to set up" that people are lumping you in with that group, even though that's not what you're saying.
The MUA should find (and verify) the key in the directory service and automatically handle the signing/signature-verification.
You might need UI to use signatures with external email, but that is a separate problem.
Good for you, but these things are not trivial.
I'm not even recommending it mutt (or any other specific MUA) as a solution today. These are simply examples that demonstrate how simple authentication can be.
If you want me to believe that internal pubkey authentication (probably based on a directory service provided by the IT department), then you are going to have to explain how most orginizations are able to handle stuff like internal addresses books, which are also provided by directory services (LDAP, Active Directory, etc). An address book requires far more UI than authentication, yet it is a common feature.
We have that where I work, wouldn't that help? That way an email with the CEO's email but with a slightly off email address would show external, where every other email within the company has no such flag.
Argh! Sorry this got flagged as external. Stupid IT guys. Anyway, we're about to close a major deal that will make us all rich, please wire blah blah blah.
The recipients who fall for it don't think about that. They think "oh crap, the big boss needs this done". Critical thinking about and questioning of decisions from higher up is strongly -- one might even say violently -- discouraged in many large organizations.
Which is exactly how these scams work in the first place, so it would probably work just fine.
I'm not saying that this doesn't require a lapse in critical thinking ability; just that kind of lapse required is a pretty common everyday one, which non-technical people make all the time.
So what this guy did, was name an object after someone, wait for them to be away from keyboard, and then say: "Hah! Guys, check this out! I made my text green lol. Anyway, [offensive remarks...]"
Everyone seems so interested in a technical way to stop this, but you can't code your way out of stupid accountants.
What's stupid is the business processes that allow an accountant that much power over wire transfers without some kind of secondary approval. That's just vulnerable to all kinds of things, like an accountant wiring the money to the Cayman islands and leaving for a country with no extradition treaty.
I agree it's not just a stupid accountant, but they need to be responsible when the weight of the job is on their shoulders.
Accountants are paid to be extremely detail-oriented. If your accountant can't tell between a 1 and the letter "l", how can you trust him/her to not miss that the amounts he/she is keeping track of and paying don't have extra (or missing) zeroes in them?
edit: not sure why this is controversial. Then again I do have high standards when it comes to hiring people into positions that require paying attention to details.
The reality is people are not robots and tend to focus on only one thing at a time. That won't change.
You don't win this battle by trying to block all the possible ways in. Instead you create one approved process for handling $BIGDOLLAR transactions.
Common sense should be the first line of defense. Even by email, managers should not approve a transaction they know nothing about. And if one approves somethings after having only talked to complete strangers, it's hard to fight raw stupidity. The first think I would have done in this story is fire the accountant.
> "My accountant was called on Friday morning," she tells the BBC. "Someone said: 'You're going to get an email from the president, and she's going to give you instructions to conduct a very confidential transaction and you're going to have to respond to whatever instructions she gives you'."
This should have thrown up so many red flags for anyone. Crazy.
A phone call from a stranger and an email from an account that has her name in it... it was probably CEO@imstealingyourmoney.ru
This is a serious question just as a FYI.
ETA: I think some slight variations on the domain name could also be filtered out completely, but I'd guess it would be hard to catch all of those that it is difficult to visually detect without also filtering legitimate mail.
I've seen an email like this aimed at the company I work for and it was something like ceo@yourrcompany.com (just one letter was doubled from the real domain).
Conpany vs Company
Which just demonstrates how easy it is to get this past people.
PS: That or you where just assuming that was an error on my part ops. I did briefly correct it before realizing it was a better example.
What I would do, though, is get my lawyer involved to write up a new contract that would make them liable for every last penny should this happen again.
No accountant would work for you with that stipulation, the risk/reward calculation doesn't make sense.
On the other hand, sometimes people fall for scams because they are extremely gullible and they never learn. e.g. http://www.neogaf.com/forum/showpost.php?p=36572169
You can easily set up your online banking to require one individual to intiate a wire transfer, and a separate individual to approve the transaction. This is a very basic financial control.
My guess is the companies falling victim to this don't have any formal controls in place.
The business that lost 30m+ I don't understand... It must have been multiple wires over a period of time. They found some vulnerable accountant with the power and just milked them over time.
And any company that has so many six figure cash disbursement transactions that approving them is an administrative burden is the type of company that most needs this kind of control in the first place.
In a corporation at least you can require an electronic signature, which requires you to provide your network credentials. Of course you have to have implemented this.
I have to electronically sign my PTO requests, for example.
I was considering it [PGP] last year for company emails but the largest sums I deal with is £100s, if I was controlling £1000s plus based on email transactions I'd think signed emails (in both directions) would be absolutely required.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Very few people verify signatures. Most implementations are impossible for most people. Including a signature may increase risk by leading to false sense of security. -----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.8
iQA/AWuBP8e2M4NxG4rj7+GnEQKyPQCfaOxVJCSfv1Ej0W1Leo/FNC+zBSsAoNrC
vkPIrX6tsLdCT/uG0zGN06fP
=vqQX
-----END PGP SIGNATURE-----Yes, I understand how you meant it. By I really can't understand ordinary people can even come to "your" conclusion. How can people be so stupid (sorry for my harsh wording) not to be able to understand that a digital signature just means that there exists a possibility to check whether the message is authentic (and this has to be done if necessary) instead of being authentic?
It's the same reason why email accounts have 2,000 unread inbox messages or 30 notifications at the top of their phone. You get so used to seeing the notification that you begin to ignore it. In this case, you see a string of non-readable text that makes up some weird "signature" at the bottom. The conclusion? "Oh. The signature is there. It's been authentic every other time I checked. Why wouldn't it be authentic on the 101st check?"
Humans are the hardest vector to defend in an attack. Never underestimate the laziness of people - even when a simple solution exists to combat the problem at hand.
> this seems like it should be a standard and basic part of all email programs now
I can't speak with authority on this, but it feels like this would be adding overhead to something that doesn't necessarily need it. Email is supposed(!) to be relatively simple. I can think of many cases where you would definitely want to have PKI integrated into your emails, but I can think of just as many cases where it's unnecessary overhead in email clients as a standard. However, I admit that I could be wrong.
https://news.ycombinator.com/item?id=10796950
http://henrikwarne.com/2015/12/27/social-engineering-from-ke...
I made a lot of free money on runescape doing this back in elementary school. "Jagex Modz 1"
Why should that be unauthorized? Unless it's written in the T&C that you must not use a pseudonym which impersonates a company official, he had used the system in a legitimate way and did not exploit bugs or bypassed access controls.
OT:
>"Her firm, which which employs 50 people" //
Surely the BBC's story editing software has a spell-checker that looks for errant word duplication?
'"Which which is which?" he said'
... but I'd still want a human editor to focus on that. Surely with such a massive text output a news organisation doesn't rely solely on human focus to maintain good grammar and such? Am I really expecting too much?
with thanks to s/o
How often is "the the" or "which which" actually intended, less than 1% of occurrences?
Buffalo.
I'm certainly not the best writer (quite appalling actually), but the following reads better while still carrying the same intent:
You'd think that would be easy to detect with no false positives.
However I'd be interested to read any corrections if I'm wrong as I'm always looking to improve my English writing skills.
You'd think that that...
is equal to
You'd think that...
And 'you'd think that' won't risk distracting any of your readers.
The problem comes when I'm actually writing. I tend to read my writing out loud to myself before I post it, and when I actually say things out loud, the double that sounds better.
I have two conclusions:
- My editing is all about hypocrisy.
- It's hard to get out of the habit of writing how you speak.
However, clearly this was written with an ear to humour so the extra "that" is essential - which is why you have your editing interface flag the double but not auto-correct it.
You know the part that makes me laugh is if these people put their ingenuity into doing something useful for society, they wouldn't need to be stealing from everyone all the bloody time.
I'm more surprised that the convicted fraudster is living in an Ashdod mansion off the beach, and evidently the current Israeli government isn't interested in repatriating him to France to serve his time. I mean, I know there's no bilateral extradition treaty in place, but the son of a bitch brags about what he did -- he doesn't even pretend to deny it!
And because the growth is organic rather than the artificial growth of a massive VC cash injection, most companies don't know what they don't know.
Subject: Transfer
Hi John,
Hope your day is going on well, I need you to process a Transfer payment swiftly,let me know what details would be needed, to get it done as soon as possible
Kind Regards,
Jane Doe
Very weird, not sure if a bot puts these together or if there's human involvement.
It'd be easy enough to source a list of company names and owners of the companies then generate possible domains and possible email addresses for the owners but you ultimately need to know who should receive the email. This probably involves a human digging around on LinkedIn. I have no idea what's it like to scrape LinkedIn but presumably they make it difficult. The difference between using the correct email address for the CFO but incorrect one for the owner suggests it's a bit of both.
As for tracking them, it's not as simple as you probably believe. Opening a business checking account or personal checking account anonymously is a lot easier than you believe. Withdrawing 10-50k is also not as difficult as you might believe. Moving hundreds of thousands to millions might be present an issue. You might be able to get some money back if it's that high dollar, but if you sent it to a shady country you're screwed.
That would also help immensely with accidental leaks of internal discussions, which is something I have to constantly watch out for with gmail (google apps).
Settings > Mail > Mark Addresses
Alternatively, the window could be made smaller if the accountant's 2FA client kept a short history of valid codes and timestamps.
Then again, without a systematic lockout (i.e. putting this restriction into the bank account itself) then the 2FA system could probably be socially engineered away just like any other safeguard.
So not using well-known best pratices (email signatures created with private key) is simply stupidity and these firms get what they deserve.
A SaaS solution which simplifies / streamlines companies’ internal (and potentially external) approval processes.. I am no expert in this area but a quick google search shows only solutions which look cumbersome and overly complex (or come as part of large and probably fairly inflexible CRMs).
I would probably target SMEs first, ie the sort of companies mentioned in the article.
Anyway, if anyone thinks there may be an opportunity here and wants to talk about this a bit more, drop me an email (address in my profile).