Recovering €1.2 Million That Was Stolen From a Client
Recovering €1.2 Million That Was Stolen From a Client
When you enter your office on a friday morning around 8, and you already missed 34 calls, it will be a day like no other. A few moments later again I my phone rang, I picked up the phone, and got bombarded with disstress from the person on the line. A client of us and his company were the target of hackers and they managed to steal just over €1.2 million euros from their bank accounts. “Can you help us to get it back” he asked.
“Of course we can. If we can prove that the amount was stolen, transferred without approval, than we will make sure that you will receive back every last cent of it. Ethical or not.” was my response.
How our client got hacked
Our client in this matter trades in different kinds of fertilizer. Mainly importing fertilizers from abroad for wholesale purposes in the Netherlands. They closed a deal to buy tons of fertilizer from a company in Italy with the whole trading process already in the final stadium, invoicing and delivery. Both parties agreed that the payment for the whole load would be done in 3 split payments where the last payment was going to be done after the delivery of the fertilizer. That is the point where everything went wrong for them.
For several weeks hackers already managed to get and maintain access to the mail servers of this company, checking every email that was going in and out. These hackers have followed the communications between this company and their fertilizer supplier in Italy and the concept contracts that where being sent back and forward. The hackers just needed to sit back and wait for the right time to work their magic.
When the deal finally was closed and contracts were signed the billing department of the Italian company created the invoices stating the amounts and payment dates for our client. While this was happening, the hackers created and spoofing email address which was almost identical to the email address of the billing department of the Italian company and they even referred the (fake) domain name that they used to the original site of the supplier in Italy. When you don’t pay attention to the details, it was hard to separate the fake company from the real company.
One business day after the Italian company emailed the invoices to our client, the hackers started to do their work. They intercepted the original invoices, recreating them and changing the bank details that were mentioned to where the Dutch company had to transfer the three payments. The hackers emailed the fake invoice, in the name of the billing department of the Italian company, to our client saying that they made an mistake with the first invoice and it’s mentioned details and that the attached file is the ‘correct’ invoice (with the false bank details). Without questioning anything, the billing department of our client assumed this new email and invoice to be legit, with a few checks everything seemed to be accurate for them, and they planned the payments to be paid to the wrong bank account. The hackers received two payments with a total worth of €1.203.036,99.
Damage & Shame
This theft could have been easily prevented. We offered our client multiple (one-time) security checks and upgrades but the famous response of “Nah, that will never happen to us” was the reason why they didn’t. Now they had to make extra expenses to 1. Solve the problem and retrieve the money 2. make sure this never happens again 3. repair the relationship with their supplier. Again, because they didn’t want to spend money on their own safety of their systems. We can’t repeat this enough because the damage that hackers cause always exceeds the amount that they manage to steal.
The (un?)ethical)Fix
We can’t go in this matter to deep but ethical hackers can also leave out the ethical part, and still act ethical. Since this was legitimate money of our Dutch client, we traced the payments after our client made the transaction. We managed to hack back the full amount even though the banks are not very happy with what we did, but we got zero cooperation from anyone which is very rude considering the situation. The two payments first went to Deutsche Bank and from there the payments where split to 3 BunQ accounts and Banka Sparkassa in Slovenia. It took us a total of 7 weeks to hack into all these banks at once and transfer money back to our client. Even the money that the hackers already had spent is back, these accounts are in an negative overdraft but that is the problem of the account holder.
We advised our client to go to the police with our reports, since it contains names and bank accounts of the people who are involved (after the hack) in the part where the money got stolen. Probably this are just money mules. The Dutch police did not really bother to investigate, which is not a huge shock to us, but it is still very strange considering that they received complete information from us and they did not even bother to invite anyone over for questioning.
So, since apparently you can’t really rely on our authorities anymore, we will always do more than our very best to go the extra mile for our clients. Even if they screw up. But the biggest lesson is that trying to prevent always is much better than to cure. This case should have never occurred if our client took our advise at heart and let us implement precautions in their systems. In that case no hacker would have had acces to their mailservers. An expensive lesson learned.
