Business
Foundation defrauded
"It was unfortunate that a foundation was targeted but a fraud and cyber attack is what it is, and difficult to prevent normally even with best controls,” said Ronnie Screwvala, founder of Swades Foundation and former head of the UTV media conglomerate. He stated to Parsiana that prompt action "as (soon as) we detected it was critical to ensure recovery within 24 hours.”
The foundation for rural empowerment started and run by Screwvala and his wife Zarina was a victim of an email spoofing attack that resulted in the siphoning off of Rs 34 lakhs from its account, reported the Mumbai Mirror (MM) on July 20, 2016. According to Tech Target network (www.techtarget.com) email spoofing is the "forgery of an e-mail header so that the message appears to have originated from someone or somewhere other than the actual source.”
The report reveals that on July 5, a senior finance official of the Swades Foundation received an email from an ID bearing
Screwvala’s name, inquiring about funds in its bank account. Believing that the email was from Screwvala, the official replied. On the same day, she received another email from the same ID asking her to immediately transfer Rs 20.20 lakh to a bank account, giving the account number and other details. The official followed the instructions. A similar mail was received a few days later, again from the ID bearing Screwvala’s name, seeking a transfer of Rs 14.16 lakhs to a different account number. This time too, the official "followed the instructions and transferred the money.”
When on July 11, the same official received yet another email from the same account seeking details of funds available with the Foundation, she decided to cross check with Screwvala who "was quick to point out that the IDs from which the three emails were received were not his.” Based on a complaint by Swades with the Cyber Crime police station, investigations were carried out and three arrests made. The police were able to recover Rs 22 lakhs. Screwvala was quoted as stating that he was "hopeful they will recover the balance too.”
The US Federal Bureau of Investigation (FBI), in an advisory on its website in April this year, warned about a dramatic increase in so-called "CEO fraud,” e-mail scams in which the attacker spoofs a message from the boss and tricks someone at the organization into wiring funds to the fraudsters. The FBI estimates these scams have cost organizations more than $2.3 billion (over Rs 15,300 crores) in losses over the past three years.
One of the significant preventive actions that companies and businesses can take is widespread education of employees on the various risks involved in cyber security, stated Porus Doctor, senior partner at Deloitte Haskins & Sells, and the Asia Pacific Region - Internal Audit Leader, speaking to Parsiana over the telephone.
"E-learnings and in-person training are the best way to do this, if the organization is large enough to warrant the investment involved in doing this,” he said. In any case, he suggests that those responsible for risk management need to periodically put out advisories in the form of newsletters or announcements to staff handling responsible portfolios in finance, information technology (IT) and accounts regarding best practices to be followed to tackle cyber risks. Spoofing cannot be eliminated, states the seasoned internal auditor; but "it is very important for all businesses to formulate policies for management of these risks and educate employees,” he stresses.
The foundation for rural empowerment started and run by Screwvala and his wife Zarina was a victim of an email spoofing attack that resulted in the siphoning off of Rs 34 lakhs from its account, reported the Mumbai Mirror (MM) on July 20, 2016. According to Tech Target network (www.techtarget.com) email spoofing is the "forgery of an e-mail header so that the message appears to have originated from someone or somewhere other than the actual source.”
The report reveals that on July 5, a senior finance official of the Swades Foundation received an email from an ID bearing
Screwvala’s name, inquiring about funds in its bank account. Believing that the email was from Screwvala, the official replied. On the same day, she received another email from the same ID asking her to immediately transfer Rs 20.20 lakh to a bank account, giving the account number and other details. The official followed the instructions. A similar mail was received a few days later, again from the ID bearing Screwvala’s name, seeking a transfer of Rs 14.16 lakhs to a different account number. This time too, the official "followed the instructions and transferred the money.”When on July 11, the same official received yet another email from the same account seeking details of funds available with the Foundation, she decided to cross check with Screwvala who "was quick to point out that the IDs from which the three emails were received were not his.” Based on a complaint by Swades with the Cyber Crime police station, investigations were carried out and three arrests made. The police were able to recover Rs 22 lakhs. Screwvala was quoted as stating that he was "hopeful they will recover the balance too.”
The US Federal Bureau of Investigation (FBI), in an advisory on its website in April this year, warned about a dramatic increase in so-called "CEO fraud,” e-mail scams in which the attacker spoofs a message from the boss and tricks someone at the organization into wiring funds to the fraudsters. The FBI estimates these scams have cost organizations more than $2.3 billion (over Rs 15,300 crores) in losses over the past three years.
One of the significant preventive actions that companies and businesses can take is widespread education of employees on the various risks involved in cyber security, stated Porus Doctor, senior partner at Deloitte Haskins & Sells, and the Asia Pacific Region - Internal Audit Leader, speaking to Parsiana over the telephone.
"E-learnings and in-person training are the best way to do this, if the organization is large enough to warrant the investment involved in doing this,” he said. In any case, he suggests that those responsible for risk management need to periodically put out advisories in the form of newsletters or announcements to staff handling responsible portfolios in finance, information technology (IT) and accounts regarding best practices to be followed to tackle cyber risks. Spoofing cannot be eliminated, states the seasoned internal auditor; but "it is very important for all businesses to formulate policies for management of these risks and educate employees,” he stresses.
◆ ◆ ◆
From the archive
