City Of El Paso Victim Of 3 Million Dollar Phishing Scam

Stu Sjouwerman | Nov 5, 2016

cityofelpaso.pngDuring a news conference Wednesday afternoon, city officials revealed that cybercriminals pretending to be a vendor scammed the city's Accounts Receivable Department out of about $3 million for the streetcar project  by using a phishing scam.

Dr. Mark Sutter, the city's chief financial officer, said the first ACH payment to the phony vendor was for about $300,000 and a second payment was for about $2.9 million.

Professor Luc Longpre with UTEP's Computer Science program has been teaching courses on cyber security for more than 20 years now. "As soon as you have some amount of money is some account, and you have a process to be able to spend that money somewhere and somebody cracked your system, then they'll take advantage of that process and take the money, it depends on how much money was in the account," he said.

Sutter said the city has recovered about half of that money. That means the rest is basically lost as it was cashed out by the bad guys and not recoverable.

Sutter also stated they don't think their systems were compromised at all, and added changing their system isn't necessary because the system wasn't hacked.

Right. A human was hacked with social engineering.

This could have been prevented with new-school security awareness training.

 

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.