Started By
Message
locked post

Law Baws: BigLaw Associate Loses $2.5 Mill to Scamster

Posted on 1/25/19 at 8:03 am
Posted by JudgeHolden
Gila River
Member since Jan 2008
18566 posts
Posted on 1/25/19 at 8:03 am
LINK

Dude was closing a deal and sent out funds to a bank account based on emails sent from his client’s email server. The emails appeared to be from his client. They were from scamsters.

quote:

the fraudsters had obtained details about the underlying transaction in a breach of a third party’s computer system.


Let’s be careful out there. It’s a dangerous world.

Posted by VABuckeye
NOVA
Member since Dec 2007
38283 posts
Posted on 1/25/19 at 8:07 am to
This is a huge issue with real estate settlements and wiring instructions.
Posted by MMauler
Primary This RINO Traitor
Member since Jun 2013
24745 posts
Posted on 1/25/19 at 8:09 am to
Correction --

FORMER BigLaw Associate Loses $2.5 Mill to Scamster
Posted by SlowFlowPro
With populists, expect populism
Member since Jan 2004
481186 posts
Posted on 1/25/19 at 8:10 am to
lol i got one of those "lawsuits against a business partner" emails yesterday
Posted by JudgeHolden
Gila River
Member since Jan 2008
18566 posts
Posted on 1/25/19 at 8:13 am to
I jacked around with one of those guys for a while to see how they would play it. They were better than I thought, but still pretty easy to see through. They play hard to the notion that you will make a quick few.
Posted by MikeBRLA
Baton Rouge
Member since Jun 2005
17242 posts
Posted on 1/25/19 at 8:14 am to
quote:

This is a huge issue with real estate settlements and wiring instructions.


Yep. I know of a few in Baton Rouge that got scammed recently. Wired money to the wrong account based on fraudulent emails they believed to contain valid wiring instructions.

By the time they figured out what was going on, the money had been wired all over the world and was long gone.
Posted by JudgeHolden
Gila River
Member since Jan 2008
18566 posts
Posted on 1/25/19 at 8:23 am to
quote:

MikeBRLA


Ouch. Then you gotta make that call to Mr Plattsmeier.
Posted by pcolatiger28
Pensacola, Fl
Member since Apr 2009
1284 posts
Posted on 1/25/19 at 8:23 am to
I work for an email security company, in particular a very large O365 reseller. This is extremely common through highly targeted phishing attacks and impersonation attempts, especially to O365 email subscribers. You business owners out there need third party email security running in front of O365, web filtering, and employee training. I get calls weekly regarding people or their clients getting scammed out of a lot of money.
Posted by mikelbr
Baton Rouge
Member since Apr 2008
49099 posts
Posted on 1/25/19 at 8:33 am to
quote:

I work for an email security company, in particular a very large O365 reseller. This is extremely common through highly targeted phishing attacks and impersonation attempts, especially to O365 email subscribers. You business owners out there need third party email security running in front of O365, web filtering, and employee training. I get calls weekly regarding people or their clients getting scammed out of a lot of money.



No doubt. A real world example of this in Louisiana last year was a phishing attempt at a plant. With the company domain name and list of employees, they sent out a mass email to everyone urging them to go to the ADP system(for payroll and benefits) and change their passwords. They were redirected to a bogus ADP site, current passwords stolen. Then the bad guys logged into their ADP accounts, redirected their direct deposit, changed the EMAIL associated with the account, then changed the password.
You figure if they hit up a few facilities with 500+ employees and get even 5 goobers' bi-weekly paychecks rerouted, that's some serious cash for not even doing any real 'hacking'.

They are some bad bad people.
This post was edited on 1/25/19 at 8:34 am
Posted by GeeOH
Louisiana
Member since Dec 2013
13376 posts
Posted on 1/25/19 at 8:43 am to
Thisbis where the blockchain stuff will take hold in the matket. Crypto shite would have avoided this...plain and simple
Posted by JudgeHolden
Gila River
Member since Jan 2008
18566 posts
Posted on 1/25/19 at 9:00 am to
Edumicate me.

How would crypto avoid the scam?
Posted by AlxTgr
Kyre Banorg
Member since Oct 2003
87960 posts
Posted on 1/25/19 at 9:04 am to
Some law firm in La. got stung by a much more basic scam. There's a reported decision on it because they sued their bank and won at the trial court. On appeal, it was held that the lawyers were sophisticated users and had they checked online they would have seen that the money was no longer there to transfer. Working from memory-could be a little different.
Posted by Tigeralum2008
Yankees Fan
Member since Apr 2012
17751 posts
Posted on 1/25/19 at 9:09 am to
quote:

I work for an email security company, in particular a very large O365 reseller. This is extremely common through highly targeted phishing attacks and impersonation attempts, especially to O365 email subscribers. You business owners out there need third party email security running in front of O365, web filtering, and employee training. I get calls weekly regarding people or their clients getting scammed out of a lot of money.


We use a 3rd party email security app called "PhishMe"

It's great. You can build a button into every client's outlook that allows them to highlight a suspicious message and easily report it as phishing. Once confirmed by our security group, the message is cleansed from our server and all client inboxes.

You can even create fake phishing attempts to find vulnerable users and train them before they fall prey to a real attempt.

Highly recommend
Posted by Centinel
Idaho
Member since Sep 2016
46661 posts
Posted on 1/25/19 at 9:20 am to
quote:

You business owners out there need third party email security running in front of O365, web filtering, and employee training.


This man is speaking the truth. On top of this, if you're not using MFA (multi-factor authentication) on ANY application you use that is internet-based, you are wrong.

My firm gets hit by an average of 250+ or more phishing emails. A day. And those are just the ones that get through our email firewall.
Posted by Jim Rockford
Member since May 2011
106013 posts
Posted on 1/25/19 at 9:23 am to
We still use paper checks and snail mail for this reason. We will communicate via email only when absolutely necessary and never wire money
Posted by LSUFanHouston
NOLA
Member since Jul 2009
41600 posts
Posted on 1/25/19 at 9:25 am to
About six months ago, I had a client call me (the client was an attorney) and ask me to e-mail him a copy of his latest bill from us, so he could pay us.

I had our receptionist send him one, I called him back, he said he got it, and would get us a check.

About three weeks passed, no check. So I called him to ask him when we might expect payment. He tells me he wired the money to us a couple of days after he got the invoice via e-mail, "per your receptionist's instructions".

I told him we don't do wires.

Somebody hacked into his law firm's e-mail accounts. They saw the e-mail from the receptionist to him with the invoice attached. They then spoofed an e-mails from our receptionist to him, basically telling him that due to the past due status of the bill we would like him to wire us the payment. Then they provided wiring instructions to him. The attorney then responded saying he would take care of it (but the e-mail never came to us, instead it went to the scammers).

We talked to the banks involved and it turned out the wiring instructions had the money sent to a bank in New Jersey, that belonged to a 90 year old disabled man. The scammers had hacked into his bank accounts, and when the wire arrived, the scammers then sent the money overseas. The man has never used online banking, never really checks statements, and had no idea this was happening.

We were not at fault and he was able to get some of his money back from the bank. But, we now only send out invoices and account statements via our secure e-mail system, not over regular e-mail.
Posted by Centinel
Idaho
Member since Sep 2016
46661 posts
Posted on 1/25/19 at 9:33 am to
quote:

Somebody hacked into his law firm's e-mail accounts. They saw the e-mail from the receptionist to him with the invoice attached. They then spoofed an e-mails from our receptionist to him, basically telling him that due to the past due status of the bill we would like him to wire us the payment. Then they provided wiring instructions to him. The attorney then responded saying he would take care of it (but the e-mail never came to us, instead it went to the scammers).


We've had this happen a few times with our clients. By the way, he didn't get "hacked". He got a phishing email, probably looking like an O365 login page, and he entered his credentials. Happens allll the time, and is why I said earlier if you're using internet-based applications, ESPECIALLY O365, you better have a MFA platform in place. Otherwise your employees WILL have their credentials stolen and used.
Posted by Broke
AKA Buttercup
Member since Sep 2006
65493 posts
Posted on 1/25/19 at 9:48 am to
I make every client call me before I send out any funds. I want to hear their voice telling me to wire money.
Posted by GWfool
Member since Aug 2010
2419 posts
Posted on 1/25/19 at 10:14 am to
quote:

We still use paper checks and snail mail for this reason. We will communicate via email only when absolutely necessary and never wire money


What type of work do you do? That is not practical for some of us when doing large level finance deals across multiple locations, wiring money is essential. But, obviously so is security as this shows.
Posted by Jim Rockford
Member since May 2011
106013 posts
Posted on 1/25/19 at 10:14 am to
Agribusiness type stuff.
first pageprev pagePage 1 of 2Next pagelast page

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on X, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookXInstagram