{"id":199,"date":"2020-07-09T09:17:14","date_gmt":"2020-07-09T16:17:14","guid":{"rendered":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/?p=199"},"modified":"2020-07-09T09:23:41","modified_gmt":"2020-07-09T16:23:41","slug":"invoice-payment-redirection","status":"publish","type":"post","link":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/2020\/07\/09\/invoice-payment-redirection\/","title":{"rendered":"Invoice Payment Redirection"},"content":{"rendered":"<p>An email account at one of UVic&#8217;s suppliers was compromised.\u00a0 The attacker accessed the email account at the supplier and attempted to have staff at UVic send payment to a bank account owned by the attacker via wire transfer.<\/p>\n<p>While the staff person in this particular department did not immediately suspect a fraud attempt, they eventually called the supplier contact and confirmed with the supplier that they did not send those emails.\u00a0 No payment was sent.<\/p>\n<p>Below are redacted screenshots of emails sent by the attacker.\u00a0 If you receive similar emails, contact your supplier using a phone number you already have on file, inform UVic Accounting, and contact the Information Security Office.<\/p>\n<p>This is the initial contact from the attacker:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-200\" src=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2020\/07\/Canary0-300x133.png\" alt=\"\" width=\"1096\" height=\"486\" srcset=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2020\/07\/Canary0-300x133.png 300w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2020\/07\/Canary0.png 749w\" sizes=\"auto, (max-width: 1096px) 100vw, 1096px\" \/><\/p>\n<p>The attacker starts to get demanding here:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-201\" src=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2020\/07\/Canary1-300x101.png\" alt=\"\" width=\"1069\" height=\"360\" srcset=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2020\/07\/Canary1-300x101.png 300w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2020\/07\/Canary1.png 723w\" sizes=\"auto, (max-width: 1069px) 100vw, 1069px\" \/><\/p>\n<p>And finally, the attacker forgets that improper spelling and grammar is a strong indicator that something is wrong:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-202\" src=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2020\/07\/Canary2-300x98.png\" alt=\"\" width=\"1280\" height=\"418\" srcset=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2020\/07\/Canary2-300x98.png 300w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2020\/07\/Canary2.png 747w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An email account at one of UVic&#8217;s suppliers was compromised.\u00a0 The attacker accessed the email account at the supplier and attempted to have staff at UVic send payment to a bank account owned by the attacker via wire transfer. While the staff person in this particular department did not immediately suspect a fraud attempt, they &hellip; <a href=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/2020\/07\/09\/invoice-payment-redirection\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Invoice Payment Redirection<\/span><\/a><\/p>\n","protected":false},"author":701,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"image","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-199","post","type-post","status-publish","format-image","hentry","category-uncategorized","post_format-post-format-image"],"_links":{"self":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts\/199","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/users\/701"}],"replies":[{"embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/comments?post=199"}],"version-history":[{"count":3,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts\/199\/revisions"}],"predecessor-version":[{"id":205,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts\/199\/revisions\/205"}],"wp:attachment":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/media?parent=199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/categories?post=199"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/tags?post=199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}