- My Forums
- Tiger Rant
- LSU Recruiting
- SEC Rant
- Saints Talk
- Pelicans Talk
- More Sports Board
- Fantasy Sports
- Golf Board
- Soccer Board
- O-T Lounge
- Tech Board
- Home/Garden Board
- Outdoor Board
- Health/Fitness Board
- Movie/TV Board
- Book Board
- Music Board
- Political Talk
- Money Talk
- Fark Board
- Gaming Board
- Travel Board
- Food/Drink Board
- Ticket Exchange
- TD Help Board
Customize My Forums- View All Forums
- Show Left Links
- Topic Sort Options
- Trending Topics
- Recent Topics
- Active Topics
Started By
Message

Law Baws: BigLaw Associate Loses $2.5 Mill to Scamster
Posted on 1/25/19 at 8:03 am
Posted on 1/25/19 at 8:03 am
LINK
Dude was closing a deal and sent out funds to a bank account based on emails sent from his client’s email server. The emails appeared to be from his client. They were from scamsters.
Let’s be careful out there. It’s a dangerous world.
Dude was closing a deal and sent out funds to a bank account based on emails sent from his client’s email server. The emails appeared to be from his client. They were from scamsters.
quote:
the fraudsters had obtained details about the underlying transaction in a breach of a third party’s computer system.
Let’s be careful out there. It’s a dangerous world.
Posted on 1/25/19 at 8:07 am to JudgeHolden
This is a huge issue with real estate settlements and wiring instructions.
Posted on 1/25/19 at 8:09 am to JudgeHolden
Correction --
FORMER BigLaw Associate Loses $2.5 Mill to Scamster
FORMER BigLaw Associate Loses $2.5 Mill to Scamster
Posted on 1/25/19 at 8:10 am to JudgeHolden
lol i got one of those "lawsuits against a business partner" emails yesterday
Posted on 1/25/19 at 8:13 am to SlowFlowPro
I jacked around with one of those guys for a while to see how they would play it. They were better than I thought, but still pretty easy to see through. They play hard to the notion that you will make a quick few.
Posted on 1/25/19 at 8:14 am to VABuckeye
quote:
This is a huge issue with real estate settlements and wiring instructions.
Yep. I know of a few in Baton Rouge that got scammed recently. Wired money to the wrong account based on fraudulent emails they believed to contain valid wiring instructions.
By the time they figured out what was going on, the money had been wired all over the world and was long gone.
Posted on 1/25/19 at 8:23 am to MikeBRLA
quote:
MikeBRLA
Ouch. Then you gotta make that call to Mr Plattsmeier.
Posted on 1/25/19 at 8:23 am to JudgeHolden
I work for an email security company, in particular a very large O365 reseller. This is extremely common through highly targeted phishing attacks and impersonation attempts, especially to O365 email subscribers. You business owners out there need third party email security running in front of O365, web filtering, and employee training. I get calls weekly regarding people or their clients getting scammed out of a lot of money.
Posted on 1/25/19 at 8:33 am to pcolatiger28
quote:
I work for an email security company, in particular a very large O365 reseller. This is extremely common through highly targeted phishing attacks and impersonation attempts, especially to O365 email subscribers. You business owners out there need third party email security running in front of O365, web filtering, and employee training. I get calls weekly regarding people or their clients getting scammed out of a lot of money.
No doubt. A real world example of this in Louisiana last year was a phishing attempt at a plant. With the company domain name and list of employees, they sent out a mass email to everyone urging them to go to the ADP system(for payroll and benefits) and change their passwords. They were redirected to a bogus ADP site, current passwords stolen. Then the bad guys logged into their ADP accounts, redirected their direct deposit, changed the EMAIL associated with the account, then changed the password.
You figure if they hit up a few facilities with 500+ employees and get even 5 goobers' bi-weekly paychecks rerouted, that's some serious cash for not even doing any real 'hacking'.
They are some bad bad people.
This post was edited on 1/25/19 at 8:34 am
Posted on 1/25/19 at 8:43 am to VABuckeye
Thisbis where the blockchain stuff will take hold in the matket. Crypto shite would have avoided this...plain and simple
Posted on 1/25/19 at 9:00 am to GeeOH
Edumicate me.
How would crypto avoid the scam?
How would crypto avoid the scam?
Posted on 1/25/19 at 9:04 am to JudgeHolden
Some law firm in La. got stung by a much more basic scam. There's a reported decision on it because they sued their bank and won at the trial court. On appeal, it was held that the lawyers were sophisticated users and had they checked online they would have seen that the money was no longer there to transfer. Working from memory-could be a little different.
Posted on 1/25/19 at 9:09 am to pcolatiger28
quote:
I work for an email security company, in particular a very large O365 reseller. This is extremely common through highly targeted phishing attacks and impersonation attempts, especially to O365 email subscribers. You business owners out there need third party email security running in front of O365, web filtering, and employee training. I get calls weekly regarding people or their clients getting scammed out of a lot of money.
We use a 3rd party email security app called "PhishMe"
It's great. You can build a button into every client's outlook that allows them to highlight a suspicious message and easily report it as phishing. Once confirmed by our security group, the message is cleansed from our server and all client inboxes.
You can even create fake phishing attempts to find vulnerable users and train them before they fall prey to a real attempt.
Highly recommend
Posted on 1/25/19 at 9:20 am to pcolatiger28
quote:
You business owners out there need third party email security running in front of O365, web filtering, and employee training.
This man is speaking the truth. On top of this, if you're not using MFA (multi-factor authentication) on ANY application you use that is internet-based, you are wrong.
My firm gets hit by an average of 250+ or more phishing emails. A day. And those are just the ones that get through our email firewall.
Posted on 1/25/19 at 9:23 am to JudgeHolden
We still use paper checks and snail mail for this reason. We will communicate via email only when absolutely necessary and never wire money
Posted on 1/25/19 at 9:25 am to JudgeHolden
About six months ago, I had a client call me (the client was an attorney) and ask me to e-mail him a copy of his latest bill from us, so he could pay us.
I had our receptionist send him one, I called him back, he said he got it, and would get us a check.
About three weeks passed, no check. So I called him to ask him when we might expect payment. He tells me he wired the money to us a couple of days after he got the invoice via e-mail, "per your receptionist's instructions".
I told him we don't do wires.
Somebody hacked into his law firm's e-mail accounts. They saw the e-mail from the receptionist to him with the invoice attached. They then spoofed an e-mails from our receptionist to him, basically telling him that due to the past due status of the bill we would like him to wire us the payment. Then they provided wiring instructions to him. The attorney then responded saying he would take care of it (but the e-mail never came to us, instead it went to the scammers).
We talked to the banks involved and it turned out the wiring instructions had the money sent to a bank in New Jersey, that belonged to a 90 year old disabled man. The scammers had hacked into his bank accounts, and when the wire arrived, the scammers then sent the money overseas. The man has never used online banking, never really checks statements, and had no idea this was happening.
We were not at fault and he was able to get some of his money back from the bank. But, we now only send out invoices and account statements via our secure e-mail system, not over regular e-mail.
I had our receptionist send him one, I called him back, he said he got it, and would get us a check.
About three weeks passed, no check. So I called him to ask him when we might expect payment. He tells me he wired the money to us a couple of days after he got the invoice via e-mail, "per your receptionist's instructions".
I told him we don't do wires.
Somebody hacked into his law firm's e-mail accounts. They saw the e-mail from the receptionist to him with the invoice attached. They then spoofed an e-mails from our receptionist to him, basically telling him that due to the past due status of the bill we would like him to wire us the payment. Then they provided wiring instructions to him. The attorney then responded saying he would take care of it (but the e-mail never came to us, instead it went to the scammers).
We talked to the banks involved and it turned out the wiring instructions had the money sent to a bank in New Jersey, that belonged to a 90 year old disabled man. The scammers had hacked into his bank accounts, and when the wire arrived, the scammers then sent the money overseas. The man has never used online banking, never really checks statements, and had no idea this was happening.
We were not at fault and he was able to get some of his money back from the bank. But, we now only send out invoices and account statements via our secure e-mail system, not over regular e-mail.
Posted on 1/25/19 at 9:33 am to LSUFanHouston
quote:
Somebody hacked into his law firm's e-mail accounts. They saw the e-mail from the receptionist to him with the invoice attached. They then spoofed an e-mails from our receptionist to him, basically telling him that due to the past due status of the bill we would like him to wire us the payment. Then they provided wiring instructions to him. The attorney then responded saying he would take care of it (but the e-mail never came to us, instead it went to the scammers).
We've had this happen a few times with our clients. By the way, he didn't get "hacked". He got a phishing email, probably looking like an O365 login page, and he entered his credentials. Happens allll the time, and is why I said earlier if you're using internet-based applications, ESPECIALLY O365, you better have a MFA platform in place. Otherwise your employees WILL have their credentials stolen and used.
Posted on 1/25/19 at 9:48 am to JudgeHolden
I make every client call me before I send out any funds. I want to hear their voice telling me to wire money.
Posted on 1/25/19 at 10:14 am to Jim Rockford
quote:
We still use paper checks and snail mail for this reason. We will communicate via email only when absolutely necessary and never wire money
What type of work do you do? That is not practical for some of us when doing large level finance deals across multiple locations, wiring money is essential. But, obviously so is security as this shows.
Popular
Back to top

12









