Canadian University Hit For $12m Phishing Scam

MacEwan University said its IT systems are secure after the institution was defrauded of nearly $12 million in a phishing scam compounded by human error.

The university learned it was the victim of an attack last Wednesday, Aug. 23 after a series of fraudulent emails “convinced university staff to change electronic banking information for one of the university’s major vendors.”

The fraud led university staff members to transfer $11.8 million to a bank account they believed belonged to the vendor, the university said.

MacEwan University spokesperson David Beharry said three relatively low-level staff members were involved in the transfer. He said there was no process in place which required staff members to phone the vendor to confirm the request to change banking information, but that will change.

“We are looking at the levels of staffing it must go through for authorisation before somebody changes that,” he said. “There is going to be a secondary and tertiary level of approval before this goes on.

Beharry said three separate payments, ranging from $22,000 to $9.9 million, were made to the vendor between Aug. 10 and Aug. 19. He said he has not been given permission to release the vendor’s name, but said the company is local.

“What we were able to find out is, there were approximately 14 construction firms in the Edmonton area that were targeted,” Beharry said.

“The fraudsters produced these fake domains about these 14 organizations. The organisations would not have any knowledge that somebody is phishing.”

Beharry said all personal and financial information, and all transactions made with the university, are secure.

More than $11.4 million of the money has been traced to accounts in Canada and Hong Kong. The university said the funds have been frozen while it works with lawyers in an attempt to recover the money.

Beharry said the university is confident it will get the money back.

The rest of the money is still missing. Beharry admitted this “shouldn’t have happened in the first place.”

“I think twice about this, too, and I go, ‘How?'” And that’s why we need to fully investigate, because we need to get to the bottom of this to make sure it doesn’t happen again,” he said.

“I think it’s safe to say that there was a lot of disappointment and frustration. Because this came down to human error.”

The president of Kick Point, an Edmonton digital marketing and web design agency, said she was “flabbergasted” when she heard about what happened at MacEwan.

“I’m really shocked that an institution this large could be taken by a scam like this and in such a large amount,” Dana DiTomaso said.

She said there’s a perception that phishing scams mainly target personal information, like credit card and password information, but they also affect businesses.

“I think it’s more common than people let on because it doesn’t necessarily get the same kind of attention,” she said. “If a business loses a bunch of money, they’re either a private business and they don’t want to talk about it because it’s embarrassing, or they’re a public business and they have to talk about it but they don’t really want to.

“You don’t hear about the volume of issues that come up on a day-to-day basis.”

The most important advice she can give to anyone in a situation like this is to think twice.

“Think twice before you transfer a bunch of money to somebody else. If it seems iffy, if someone is asking you to do something different than what you would normally do, which is the case here or what seems to be the case here, then check in with somebody else, check in with a bunch of people.”

After the fraud was discovered, MacEwan conducted an audit of university business processes. Officials said “controls were put in place” to prevent similar incidents from happening.

Beharry said the university provides information to its staff, students and faculty about these types of scams and other cyber-security related issues. He said it’s important that the university reinforce its messaging.

External experts have been brought in to help the university in its investigation. The university said preliminary investigations reveal that controls in place around the process of changing vendor banking information were inadequate, and that a number of opportunities to identify the fraud were missed.

MacEwan University said final results of the review are expected within a few weeks.

The minister of advanced education and the officer of the auditor general have been made aware of the situation.

Advanced Education Minister Marlin Schmidt said he’s “very disappointed” the university fell victim to the crime, adding he’s instructed all university board chairs to review their financial controls.

“This is unacceptable and I’ve asked the board chair to report back to me by Sept. 15 with details on how this occurred,” Schmidt said in a statement.

“While I’m told that MacEwan has put improved internal financial controls to help prevent it from happening again, I expect post-secondary institutions to do better to protect public dollars against fraud.”

Beharry said it’s too early to say whether the staff members will be disciplined.

Global News:

You Might Also Read: 

The Insider Threat:

Employees That Cause Data Breaches:

 

« WikiLeaks: The Biter Bit
Wearable Sensor Tech For Beat Police Officers »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

Tufin

Tufin

Tufin enables organizations to automate their security policy visibility, risk management, provisioning and compliance across their multi-vendor, hybrid environment.

Lynx Software Technologies

Lynx Software Technologies

Lynx provide secure software and operating systems for use in mission critical applications such as aerospace, medical, transportation and IoT.

FedRAMP

FedRAMP

FedRAMP, is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services.

Ceerus

Ceerus

Ceerus was created to simplify the process of deploying and managing security across all the channels in an organisation.

Wotan Monitoring

Wotan Monitoring

Wotan Monitoring is the software solution for fully automatic process monitoring, infrastructure monitoring and end-to-end monitoring.

redGuardian

redGuardian

redGuardian is a DDoS mitigation solution available both as a BGP-based service and as an on-premise platform.

SBD Automotive

SBD Automotive

SBD Automotive are specialists in automotive technology providing independent research and consultancy to help create smarter, more secure, better connected, and increasingly autonomous cars.

Datplan

Datplan

Datplan offers a software solution that gives an overview of 8 key cyber risk areas, their threats, and risk management steps.

Jerusalem Venture Partners (JVP)

Jerusalem Venture Partners (JVP)

JVP’s Center of Excellence in Be’er Sheva aims to identify, nurture and build the next wave of cyber security and big data companies to emerge out of Israel.

Inpher

Inpher

Inpher has pioneered cryptographic Secret Computing® that enables advanced analytics and machine learning while keeping data private, secure, and distributed.

AdaCore

AdaCore

AdaCore is focused on helping developers build safe, secure and reliable software.

Valency Networks

Valency Networks

Valency Networks provide cutting edge results in the areas of Vulnerability Assessment and Penetration Testing services for webapps, cloud apps, mobile apps and IT networks.

Securance Consulting

Securance Consulting

Since 2002, Securance has empowered enterprises to assume proactive security, compliance, and risk management strategies.

Cyber Octet

Cyber Octet

Cyber Octet is an IT Solution, Security, Training and Services company. We provide training and services from Web Application Security to ISO 27001 implementation.

SUCCESS Computer Consulting

SUCCESS Computer Consulting

SUCCESS Computer Consulting is a leader in managed IT and security services for small and medium-sized businesses in Minneapolis, St. Paul, and the surrounding Twin Cities Metro area.

Taktika

Taktika

Taktika stands at the forefront of cybersecurity defense, offering cutting-edge integration and managed Security Operations Center (SOC) services.