Spear Phishing in the Royal Canadian Mint


The Royal Canadian Mint, which produces Canada’s coins, nearly sent an employee’s paycheck to an attacker following a spear phishing attack, CBC News reports. The attacker sent an email to the Mint’s HR department while posing as an employee and requested that the department change the employee’s bank account details. The HR worker who received the email was convinced, and they changed the employee’s direct deposit information.

Fortunately, the bank rejected the payment before it was sent to the scammer, so the employee didn’t lose their paycheck. The scammer did receive the employee’s pay stub, however, which contained some sensitive personal and financial information. The employee later fell victim to identity theft and was affected by fraudulent credit card purchases, although the Mint says there’s no evidence that those incidents are a result of the data that was lost during the payroll spoofing attempt.

While the bank caught the fraudulent payment in this case, Jeff Thomson, a senior RCMP intelligence analyst with the Canadian Anti-Fraud Centre, told CBC News that payroll spoofing scams are increasing.

“Oftentimes it can result in significant losses,” Thomson said. “It typically falls in our top two in terms of dollar loss in the amount of money that the victims can lose.”

Thomson continued, saying it’s tough to hold the scammers accountable because they’re often located in another country.

“So the tactics the fraudsters employ certainly make it more difficult to track them down,” he said. “And it’s challenging in investigating when you're crossing jurisdictions.”

These types of attacks depend on ignorance to succeed. If the HR worker had been trained to be on the lookout for payroll diversion attempts, they might have been more careful. The employee was lucky not to lose their paycheck, but they still lost sensitive information through no fault of their own. New-school security awareness training can teach your employees about the tactics used by scammers so they can recognize these techniques when they encounter them.

CBC News has the story: https://www.cbc.ca/news/politics/mint-spear-phishing-scam-1.5392036

Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:


Subscribe To Our Blog

Ransomware Hostage Rescue Manual

Get the latest about social engineering

Subscribe to CyberheistNews