7 ms·
Fresno lost $400k to a phishing scam in 2020 and never told the public
- DannyBee 5y ago"Dyer said the emails were privileged information since the city attorney was included". This is not how privilege works, and all the people involved certainly know it. (This used to be a game oil and other companies would play, and courts do not look kindly on it anymore)
- throwaway0a5e 5y ago>and courts do not look kindly on it anymore As anyone who's ever spent more than a few nanoseconds caring about things like civil liberties or government accountability knows, the courts tend to give people who are on the "same team" a lot more leeway.
- DannyBee 5y agoThis is definitely true, but there are limits.
- throwaway0a5e 5y agoIf you make the courts look inept the courts come after you. If you do something politically tone deaf the politicians come after you. If you make the politicians look inept that's just Tuesday.
- dancemethis 5y agoFresno is just a brazilian emo band.
- mdavis6890 5y agoGood job reporting on this. Now the question is whether the voters will care at the ballot box. We shouldn’t go after the person who fell for the scam - they’re just doing their job the best they can. Or even the person who should have disclosed. We have to all the way up to an elected official that needs to be held accountable, whether they knew about it or not.
- tehwebguy 5y agoYeah the dollar amount is pretty much meaningless, it’s like the cost of employing 4 cops in a city that has 850. But the failure to disclose is a pretty big problem.
- MrZander 5y agoWell, the previous mayor already lost the last election, and the new one disclosed it upon taking office.
- mdavis6890 5y agoWell there you go! :-)
- nelsondev 5y agoWhy shouldn’t there be accountability of the person who failed to disclose?
- thfuran 5y agoYou know, like how when an employee embezzles from a company you fire the CEO? It's just common sense. Punishing wrongdoing instead of ritually sacrificing a figurehead is just so barbaric.
- brnt 5y agoAs soon as you focus on the who and not the how, you incentivice people to cover their asses. Look up the root cause analysis culture in aviation for an effective method.
- nelsondev 5y agoYou can focus on both the “how” and the “who”. I work in an engineering organization where when something sufficiently complicated goes wrong, we do a proper root cause analysis, ask 5 Why’s, propose process improvements, etc. But sometimes, people just screw up, and preventing every unique screw up, would mean the creation of an absurd amount of process. For example, one time, excited by the performance results of a colleague, I tried to immediately apply his performance optimization in a different context serving production traffic; we had a team culture of don’t test in prod, etc; but my hubris/excitement meant I powered ahead, which ended up driving up latency, failing requests, and causing a small outage. The solution in this case isn’t to invent a new process to prevent my mistake, but rather to make sure the engineer knows they screwed up. A bit of shame/guilt leads to self improvement. If you focus solely on process, and avoid personal responsibility, you may end up missing opportunities for personal growth.
- 55555 5y agoThat’s not what phishing is.
- walrus01 5y agothe netsec/infosec industry term now is "whaling" or "spearphishing" where a specifically crafted fake email from a vendor to a payor is send to redirect the wire transfer to a another account, typically an ACH money mule or ignorant/clueles patsy that then forwards the bulk of the funds onwards to a location where it cannot be retrieved.
- phire 5y agoIt's a type of phishing, known as spear phishing, where a specific individual or organisation is targeted with a highly customised scam. Emailing financial departments with fake invoices is a common type of spear phishing scam. https://en.wikipedia.org/wiki/Phishing#Spear_phishing https://en.wikipedia.org/wiki/Phishing#Spear_phishing
- benatkin 5y agoPhish Different. - Steve Jobs, 1997
- IG_Semmelweiss 5y agoIm surprised that this attack on a govt entity was successful. In such entities, every vendor record is a database entry in some legacy custom CRUD system, which require 5 different people to approve X record update. Each of those people also have their own checklist of things to do prior to approval, one of which is literally pick up phone and confirm with vendor the X update. Govt has a reputation for not being agile - but maybe the scammers have identified a niche in city agencies? Now im wondering how many of these have never been reported on...
- MattGaiser 5y agoI am an ex municipal employee. Procedures are often just blindly checked through. The paperwork for the procedure often exists and is filled out, but the procedure itself is often not conducted.
- throwaway0a5e 5y agoThose 5 different people don't understand the big picture and even if they do they likely don't care (and probably have been burned from caring in the past). Getting comically insane stuff (like a 400k transfer to a scammer) to actually happen is way easier when everyone exists in "I just stamp the form if all the fields are filled out, checking what's in the fields is the next guy's job" type silos.
- wccrawford 5y agoAnd there's a good chance that many of them think "Oh, the other 4 will catch it if I don't, so it's not a big deal." Adding a committee to something doesn't make it automatically smarter.
- atdrummond 5y agoI know of multiple municipalities (Illinois in this case) where there's a single point of failure for these kind of attacks. I am sure there are quite a few of these cases that never get reported to the public, especially after my experience with the quality of many of the audits that smaller and mid-size communities go through.
- deleted 5y ago[deleted]
- csharpminor 5y agoI will say if you think this is bad, you ought to read about Washington State’s loss of $650M to organized cyber crime: https://www.seattletimes.com/seattle-news/auditor-state-unemployment-system-wholly-unprepared-for-fraud-one-agency-employee-under-criminal-investigation https://www.seattletimes.com/seattle-news/auditor-state-unem...
- flippyhead 5y agoThe statement above left leaves out some important details when level-setting the just how bad it was in WA state: > All told, the imposter and fraud claims represented $646.8 million in misappropriated benefits. (Not all the imposter claims were paid; many were stopped by ESD before funds went out.) Of that, the state has recovered $370 million, the audit stated.
- walrus01 5y agoI had never heard of this, and I'm a WA state taxpayer... so admittedly having only read the article, I'm familiar with the theory that there's a number of fraud organizations out there that were in possession of the most vital personal data (name/DOB/SSN) that submitted false claims in 2020 during the earliest stages of the covid19 response, and got payments redirected to money mule ACH deposit accounts. this happened in more locations than just WA. one of the sketchiest things you can find on the internet, if you take time to research it, is the number of scammers posting "job openings" for things like a "accounts processing executive" for full WFH jobs. a certain percentage of gullible or entry level people who are too naive to know better fall for it. the general concept is to create a legit US domestic bank account that can receive ACH transfers and then forward the money onward somewhere else. usually ending up in some form of overseas account or cryptocurrency from which it cannot be retrieved.
- octoberfranklin 5y agoI was furious when I heard of this back in 2020, and I'm a WA state taxpayer. The ESD Commissioner job was handed out as a political patronage gift. The person who was running the show has "failed upward" and is now in Washington DC. One-party government sucks. "Yeah but the other party is worse" is irrelevant. https://www.seattletimes.com/seattle-news/politics/how-democratic-party-fundraiser-and-former-ambassador-suzi-levine-came-to-run-embattled-state-unemployment-system/ https://www.seattletimes.com/seattle-news/politics/how-democ...
- Narkov 5y agoFor context, their total city revenue for FY22 is $1.8b. Not passing judgement either way, but at what point should this be reportable?
- zamadatix 5y agoReportable as in the city answering the public records request or reportable as in this news article? The former the amount shouldn't really matter, that's what public records are after all, the latter seems more subjective but I think the article is popular because of the denial of the records request and being found out not necessarily the amount being crazy high.
- et-al 5y agoThere are materiality guidelines. I don't know what they are for government, but general rule of thumb is 0.5 - 1% of gross revenue.
- walrus01 5y agoreminds me a little bit of when ubiquiti networks got phished to redirect a SWIFT wire transfer to a different location, and had to report it on their 10Q https://www.google.com/search?client=firefox-b-1-d&q=ubiquiti+wire+transfer+scam https://www.google.com/search?client=firefox-b-1-d&q=ubiquit... https://www.google.com/search?client=firefox-b-1-d&q=ubiquiti+networks+scammed+wire+transfer https://www.google.com/search?client=firefox-b-1-d&q=ubiquit... at least the SEC requirements for publicly traded companies requires them to disclose it. it's kind of funny that a for profit corporation has more transparency going on in its disclosure of getting scammed than a municipal government entity.
- rmbyrro 5y agoYou find it funny, but this is by design. Governments are not benevolent parties, gifts of the gods to society. Companies aren't either, but at least we can choose which companies we deal (not for everything, but still for many things) and companies can't use violence against us. We can't choose governments (if you live in a "democratic" state, you can choose a politician, which is another thing) and if you don't subscribe to what they impose, they have an excuse to use violence against you and your family. EDIT: private bodies in theory can use violence, but then we also can fight back in legitimate defense. This doesn't apply to governmental violence.
- lostlogin 5y agoThis is very circular. You prefer companies to the state, because we can chose which companies we deal with and companies can’t use violence. But it’s the state that says companies can’t use violence.
- rmbyrro 5y agoI don't prefer companies, just don't like the idea that other people can use violence against me and it's illegal for me to defend myself.
- NoSorryCannot 5y agoA monopoly on violence is a necessary condition for being a state. It is something that is true for states but not other things, and it isn't circular to say they are potentially more dangerous for having that attribute.
- bpodgursky 5y agoJust FYI the running total of CA's unemployment fraud during the pandemic is $20 billion: https://www.latimes.com/california/story/2021-10-25/californias-unemployment-fraud-20-billion https://www.latimes.com/california/story/2021-10-25/californ...
- DonHopkins 5y agoIf Frisco is short for San Francisco, does that mean Fresno is short for San Francesno?
- Raineer 5y agoErie, CO lost $1M to a phishing attack. It was very well timed and targeted toward a major project which had been in the works for a decade. https://www.denverpost.com/2019/12/30/erie-victim-financial-fraud-parkway-bridge/?returnUrl=https://www.denverpost.com/2019/12/30/erie-victim-financial-fraud-parkway-bridge/?clearUserState=true https://www.denverpost.com/2019/12/30/erie-victim-financial-...
- Illniyar 5y ago"The FBI asked city officials to keep the incident under wraps, so their investigation wasn’t compromised, Dyer said." Could this be a valid reason not to disclose it?
- benatkin 5y agoA valid reason not to disclose it at first, perhaps. By the time that the Fresno Bee formally requested it, that probably wasn't a valid reason not to disclose it anymore.
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- TommyDANGerous 5y agoWow!