$1.04M Lost in Business Email Compromise Scam
Exploit: Business Email Compromise, Data Breach
Company: City of Saskatoon
Industry: Government, Municipal
Location: Saskatoon, SK
Source: https://www.itworldcanada.com/article/saskatoon-stung-by-1m-scam-job/420950
The city of Saskatoon has become the latest victim of cybercrime as $1.04 million has been stolen in a Business Email Compromise Scam. The municipality held an urgent press conference announcing that a bad actor, posing as a Chief Financial Officer from a prominent construction company, tricked city staff members into changing the receiving bank of a large payment.
City Manager Jeff Jorgenson told reports that despite city policies, “clearly, the control that was used wasn’t strong enough to prevent (the fraud).” He continued, “What I would say is internal and external staff who are experts in this area are reviewing all financial processes and controls in this area.”
While further details of the fraud are not available, what we do know is that the bad actor either spoofed or hacked the email of the construction company in order to trick the city staff into thinking they were dealing with the actual CFO.
Do you need help protecting your staff with Microsoft 365 security?
Microsoft office products are widely used across most business making Microsoft 365 the most targeted platform. With concerning trends of exploiting businesses through email fraud and other hidden vulnerabilities in their Microsoft Office apps, it is important to know how you can protect your staff and your business to any potential threats for Microsoft 365.
Read more about Microsoft 365 Security Today