Facebook and Google were conned out of $100M in phishing scheme
theguardian.com
theguardian.com
Blockchain?
Vendors had to be pre-approved and their bank details managed, who were explicitly matched to POs, explicitly matched to invoices, and finally... invoices had to be matched to inventory receipts before any sort of payment was triggered. POs had to be approved by someone internally with specific approval levels as well.
Not sure if we were insanely overboard but... no idea how this happened.
Given this story I would bet there is a fair bit of undiscovered internal fraud at google and fb
But it is amazing how bad some private companies accounts are. We ended up effectively advising them on their accounts receivable.
The thing about this particular scam is the size; no-one goes hunting for POs and invoices for $100m. (or everyone assumes someone else has). It's the success of the big lie.
There was some more to it, about using it to participate on a competition representing the company, but it was absolutely ridiculous.
Instead of the email getting filtered out right away, the story goes that it rolled downhill through several layers of management, and apparently, people were asking each other "who is this guy? do we need to buy him a plane?"
Better to check internally (and chew out your employee for overpromising if needed) than to accidentally jeopardize a large account by calling the guy a fraud or ignoring him and it turning out to be true.
Laundering the money and not getting caught => 90% of the work.
The dude made a big fraud and got caught in 5 minutes. That's amateur hour.
If they'd done $1M nobody would have heard about it, nobody would bother investigating too thoroughly, and they'd just shrug and move on.
The "pro" thing to do is to take your $1M and walk away even though you know there's more money at that tap.
There's a lot of casino cheats that talk about their craft. The good ones work extra hard to give the constant illusion of losing money which helps them win a little bit more without drawing too much attention. There's a whole art to knowing where the line is and not crossing it, flying completely under the radar.
That's what professionals do.
A common variation on the them is where they actually ship some low value item, wait just long enough for UCC return rights to expire and then send a ridiculous invoice. If ignored, a threatening follow-up comes that includes the proof of delivery of the item and late penalty threats. The item was usually shipped signature-required, so the proof more intimidating. (If you're wondering, the law is generally still on your side but you shouldn't just ignore the letters and keep the item even though they will likely give up anyway.)
To get it back to you in large amounts as clean money, you would need to have another corporation that contracts with the casino or other service provider, and it is paid with money that is clean for all intents and purposes.
but the problem here is the name on the bank accounts even if you wanted to get to cryptocurrency, you would really want a nominee director on the corporate bank account, but then you have to trust they don't take the money (there are plenty of reputable ones though).
if you had that much in cash already then you could buy mining hardware. set up a solar powered mining farm and get cryptocurrency over the next 6-12 months, then you have the liquidity. if you are interested in national currency and bigger material things, then you will still need to contract w/ a crypto-service so that you could report income, but the crypto-service's funding source would be a deadend for auditors.
There are many reasons to mine at a loss.
I'm sure there are any number of bankers in various countries who would gladly help you out for a 30-50% cut.
If I was in the con game and knew a loophole to get my hands on $100m, I doubt I'd wait around too long to figure out all the details and risk the loophole being closed.
Also, side note, you have to wonder if the conman had some detailed insider knowledge of existing legitimate PO #s, like from the actual vendor's insecure systems. Hack a vendor, get PO #s and beat them to sending the invoice. Hope you get the money and can disappear faster than the vendor sends his invoice and alarm bells go off.
https://en.m.wikipedia.org/wiki/Bangladesh_Bank_heist
$81m was sent to a bank in the Philippines and less than 25% was recovered. Other banks had success is recovering all the funds sent through them as part of the same heist.
Admins, please change the link.
I hear about a kind of phishing at my company. It is as primitive as pretending to be our CEO, who is trying to reoncile an invoice for a supplier.
The argument was that the person who needed to verify the key wouldn't be bothered to actually verify. The key would be so commonplace that as long as a nonsensical string of characters appeared, the verifier would check the box using the it's-good-enough mentality. The crux is still the same: fool the human, get the goods.
There are numerous problems to solve to make this kind of attack unviable. The key thing to understand is that whilst the software industry has done a good job of automating and improving intra-business work, through things like office and enterprise software, it's had relatively little impact on inter-business work, which is still mostly paper based. Even when workflows are theoretically digitised, it's often simply by sending scans of paper forms or Word/PDF files via email. There are exceptions in the travel and financial industries (with SABRE and SWIFT respectively), but those are relatively restricted networks - for instance I doubt Google or its suppliers are directly connected to SWIFT.
There's some low hanging fruit. Email has DKIM and DMARC. Deploying these widely would make the From header reliable, at least assuming unhacked machines. It isn't intuitive that the From header can't be trusted and office workers typically assume that it is ... after all, it's normally correct and why would something as critical as email allow anyone to impersonate anyone else? But by default, it does.
Unfortunately DMARC is a fairly recent standard and the email space is quite stagnant, so many organisations don't use it, making email-based phishing trivial. It also hits the problem that lots of organisations have developed insecure mail practices over time in which impersonation is common, like marketing firms that send email on another organisations behalf, so deploying DMARC isn't as simple as just switching it on. It can often take months to track down and fix all the mail being sent with a "From: someone@foo.org" header but which actually wasn't sent by foo.org servers. That means it's a project that needs a budget, and that in turn means it often doesn't get proposed or worked on. Especially because the victims of email phishing are typically other companies, not the company being impersonated.
But because DKIM and DMARC are fundamentally based on digital signatures, and because the workflows being attacked are so often email based, setting up DKIM/DMARC is one of the best practical ways to secure modern business.
Now ... longer term, email with Word documents attached is not a solid base on which to link businesses together, DKIM/DMARC or not. It's hard to automate. It's very susceptible to human error. It suffers strange limitations, like tiny attachment sizes. Organisations often mutilate it, like with mandatory headers/footer legal disclaimers that are larger than the messages itself, or with vacation responders that don't understand mailing lists. And as nobody really coordinates or is responsible for the email network, nobody is incentivised to improve it. When improvements happen, they happen slowly and mostly because Google or Yahoo employees made it happen through sheer force of will.
Corda is an open source project that is trying to build a new inter-business network, focused (for now) on finance. So things like invoicing and bill paying is very much in scope. It uses digital signatures and encryption pervasively from the start. It takes a lot of inspiration from Bitcoin and the block chain space, although it does not use chains of blocks or proof of work itself. Some of what it does is focused on building a kind of shared global database, albeit one with rather different properties to a normal database, but part of what it does is make it easy to build structured workflows between firms using straight-line blocking code that resembles a written English description of the process. So there's plans to support human interaction in these workflows, but ultimately, the goal is to try and get them off email and paper based processes and onto something more secure and more structured. There's a paper here that goes into some of the details:
https://docs.corda.net/_static/corda-technical-whitepaper.pd...