How Cybercriminals Profit by Tapping Your Email
easydns.com
easydns.com
Being owed a sizable wire from a corporate entity, I requested payment to an account via my personal email (<name>@<name>.co). As they were validating/processing that, I opened up a new bank account that can receive wires with no fees. I then sent them an email with the new information, and a couple weeks later received the funds in my new bank account without any friction. What no one brought up was the fact that the email with the new information was from <name>@<name>.com, as I had transitioned from .co to .com in the meantime. The attack vector highlighted in this article is definitely under-guarded.
It won’t help if the attacker spoofs the first invoice but hopefully will raise alarms if future invoices are spoofed and contain different bank details. I guess it could also give me a legal argument that I’ve explicitly made them aware of this risk and that they should’ve known better and that they still owe me money and should pay again (as the first time they haven’t actually paid me but the attacker).
I think perhaps in the signature line of our email, we need to implore that last minute or unexpected changes to the original plan- especially involving wire transfers - be verified over the phone.
Eventually SIM swap attacks may get more common and a third channel (or two better channels than email + phone system) may be necessary.
In cases other than fraud and bank error, the timeline and process depends. Basically ask your bank really nicely, they'll ask the receiving bank really nicely, and if everyone agrees with your reasons (and the money is still there) you'll most likely get it back.
There has to be a way to reverse wires, otherwise if the teller fat-fingers an extra zero onto the end of your requested amount you'd be SOL.
[0] https://www.cbc.ca/news/canada/calgary/wire-fraud-email-cond...
I’m convinced that a lot of the money is in fact reversed.
That's not the obvious technical solution and would not be very effective. The most obvious technical solution would be to insist their customers sign any emails that involve the movement of large sums of money.
Why you have to accept "the document can do everything what it want", if you like to print a PDF from Adobe Acrobat Reader or do Fullscreen mode?
I mean just VBA is not a problem, just if you start to do things outside of the document.
I think it wouldn't be even hard to implement it.
My friend wasn't compromised but the person she was dealing with was. evidently they were reading the other guys mail and when mention of invoicing came up they made a fake email address that was almost the same as his (swapped a l for a 1) and sent through a new banking detail.
the woman at this end didn't realize the email didn't come from who she thought it did and sent a 10k payment directly into the thieves bank account.
She was mortified afterwards.
Isn't banking system supposed to protect from this kind of stuff? I mean, is not responsability of banks to ensure that the recipient of the transfer is indeed the one specified by the sender? Or one should consider a (wrong) placed banking transfer simply gone? The (non-)reversibility of transfers is one of the main arguments against crypto-currencies, and yet this kind of events seems to be happening with banks anyway.
My family runs a small-medium business and a couple of years back we were victim of something very similar. I'm a professional penetration tester myself (not to brag but I'm pretty sure my family company is pretty secure), anyway as we were the victim here (the one that were not paid in the process), there was no way for us (me) to detect the issue (at the technical level) up until it was too late. What happened is that one of our customer got their email compromised, and attackers were literally man-in-the-middleing all of their emails. When they detected some bills and payments requests from us, they simply forwarded them back to our customers using a fresh registered domain name that looked a lot like ours. In the process they did alter the attachment, to change indeed the IBAN.
To keep it short, when we realized that something was wrong it was too late, and banks even refused to pay our customer back.
We did report the event to the authorities, however to this day we did not hear anything back :)
TL;DR Attackers compromised some customers' emails, altering the IBAN in the attachments in the process. Customer did pay attackers instead of the legitimate company, and bank could not undo things. Is sending money to a wrong IBAN the same as sending it to a wrong wallet address for crypto-currencies? Not a big fan myself, but if there are no guarantees we might as well do the switch.
Only a rant