Fresno lost $400k to a phishing scam in 2020 and never told the public
fresnobee.com
fresnobee.com
so admittedly having only read the article, I'm familiar with the theory that there's a number of fraud organizations out there that were in possession of the most vital personal data (name/DOB/SSN) that submitted false claims in 2020 during the earliest stages of the covid19 response, and got payments redirected to money mule ACH deposit accounts.
this happened in more locations than just WA.
one of the sketchiest things you can find on the internet, if you take time to research it, is the number of scammers posting "job openings" for things like a "accounts processing executive" for full WFH jobs. a certain percentage of gullible or entry level people who are too naive to know better fall for it. the general concept is to create a legit US domestic bank account that can receive ACH transfers and then forward the money onward somewhere else. usually ending up in some form of overseas account or cryptocurrency from which it cannot be retrieved.
The ESD Commissioner job was handed out as a political patronage gift. The person who was running the show has "failed upward" and is now in Washington DC.
One-party government sucks. "Yeah but the other party is worse" is irrelevant.
https://www.seattletimes.com/seattle-news/politics/how-democ...
0: https://www.npr.org/2019/12/20/790192972/washington-legislat...
I'm always a little suspicious of claims of benefit fraud that aren't backed up by court cases. They're very easy to inflate. Someone loses their job, fills in a form incorrectly, gets paid, the error is discovered a year later: was there really fraudulent intent, or is it just the combination of means-testing and the difficulty of discovering someone's true circumstances?
The number is mostly so large because it's 10% of an even bigger number, the amount CA pays in unemployment claims, which is not in dispute.
It is not at all comparable to Finland, and it is completely comparable to Finland
Finland via Nokia is quite high-tech in places; many people are poor; Finland unemployment system is not at all like California EDD; high-tech is available to the unemployment benefits people to implement payments, but do they use it?
Personally I care a lot about the Scandinavian lands even though I live in California. It is really interesting to me to hear comparisons of California to Finland. Both systems of government are complex and unique, so superficial comparisons certainly have a lot of hidden detail. People on YNews are uniquely capable with high tech so real inquiry here might lead to something interesting.
The US doesn’t (although by choice) and trying to prevent fraud without identity infrastructure seems hard.
The police officer handling fraud I talked to said he was getting a lot of a calls about this kind of fraud.
The state sent out a letter pretty quick, and I filed to stop this within a few weeks. I have no idea how much was stolen with my name, or how much was recovered later
At the time, I would prefer the state to err on the side of paying quickly for those suddenly out of work in a pandemic, but if the state paid almost $50m for a system to stop fraud that just didn’t work right, then perhaps a refund and legal recourse is in order.
But I think a lot of the US, myself included, opposes central identity.
Therefore we are in our own self made hole.
There will be a few edge cases (disabled), though after a few prosecutions the fraud will mostly stop.
Accounting for population size, Washington State's loss is still more than a hundred times as big.
> All told, the imposter and fraud claims represented $646.8 million in misappropriated benefits. (Not all the imposter claims were paid; many were stopped by ESD before funds went out.) Of that, the state has recovered $370 million, the audit stated.
https://www.google.com/search?client=firefox-b-1-d&q=ubiquit...
https://www.google.com/search?client=firefox-b-1-d&q=ubiquit...
at least the SEC requirements for publicly traded companies requires them to disclose it. it's kind of funny that a for profit corporation has more transparency going on in its disclosure of getting scammed than a municipal government entity.
Companies aren't either, but at least we can choose which companies we deal (not for everything, but still for many things) and companies can't use violence against us. We can't choose governments (if you live in a "democratic" state, you can choose a politician, which is another thing) and if you don't subscribe to what they impose, they have an excuse to use violence against you and your family.
EDIT: private bodies in theory can use violence, but then we also can fight back in legitimate defense. This doesn't apply to governmental violence.
This is not how privilege works, and all the people involved certainly know it.
(This used to be a game oil and other companies would play, and courts do not look kindly on it anymore)
As anyone who's ever spent more than a few nanoseconds caring about things like civil liberties or government accountability knows, the courts tend to give people who are on the "same team" a lot more leeway.
If you do something politically tone deaf the politicians come after you.
If you make the politicians look inept that's just Tuesday.
https://www.denverpost.com/2019/12/30/erie-victim-financial-...
Could this be a valid reason not to disclose it?
Each of those people also have their own checklist of things to do prior to approval, one of which is literally pick up phone and confirm with vendor the X update.
Govt has a reputation for not being agile - but maybe the scammers have identified a niche in city agencies?
Now im wondering how many of these have never been reported on...
I wonder if there is some phishing going the vendor’s direction as well where the city requests to review the next invoice.
It’s truly amazing to me that you can completely lose your money in an ACH transaction with little to no recourse.
https://darknetdiaries.com/transcript/111/
Multiple people needed to sign off on these transactions, and the attackers were able to fake that once they had remote control of the browsers.
Getting comically insane stuff (like a 400k transfer to a scammer) to actually happen is way easier when everyone exists in "I just stamp the form if all the fields are filled out, checking what's in the fields is the next guy's job" type silos.
We shouldn’t go after the person who fell for the scam - they’re just doing their job the best they can. Or even the person who should have disclosed. We have to all the way up to an elected official that needs to be held accountable, whether they knew about it or not.
Look up the root cause analysis culture in aviation for an effective method.
But sometimes, people just screw up, and preventing every unique screw up, would mean the creation of an absurd amount of process.
For example, one time, excited by the performance results of a colleague, I tried to immediately apply his performance optimization in a different context serving production traffic; we had a team culture of don’t test in prod, etc; but my hubris/excitement meant I powered ahead, which ended up driving up latency, failing requests, and causing a small outage.
The solution in this case isn’t to invent a new process to prevent my mistake, but rather to make sure the engineer knows they screwed up. A bit of shame/guilt leads to self improvement.
If you focus solely on process, and avoid personal responsibility, you may end up missing opportunities for personal growth.
How does this really make sense? The biggest wrong here is that it wasnt disclosed in my opinion. It sounds like it was the mayor's wrong there, but I dont see how you would "go all the way up to an elected official.. whether they knew about it or not". That part doesnt really make any sense to me
Emailing financial departments with fake invoices is a common type of spear phishing scam.