World's Largest Sovereign Wealth Fund Falls For $10m Social Engineering Attack

Stu Sjouwerman | May 14, 2020

iStock-1171977818The Norwegian Investment Fund has been swindled out of 10 million dollars by fraudsters who pulled off a social engineering attack that the Norfund called "an advanced data breach" but what is commonly known as a Business Email Compromise, aka CEO Fraud.

Norfund is the world's largest sovereign wealth fund—created from saved North Sea Oil revenues and currently worth over a trillion dollars— admitted  that a hacker was able to manipulate the organization into routing a loan intended for a Cambodian microfinance organization into an account controlled by cyber criminals.

As a result, in March, 100m Kroner was lost. The investment fund says the money appears to have been diverted from the organization in Cambodia to Mexico. Local and international police have been brought in to investigate the matter. There are not yet a lot of details about this attack, which may have been a simple compromised email account, perhaps several pwned workstations fully under control of the bad guys, or a fully compromised network.

"The defrauders manipulated and falsified information exchange between Norfund and the borrowing institution over time in a way that was realistic in structure, content and use of language," Norfund said on Wednesday of the heist. "Documents and payment details were falsified."

The Register commented: "Again, this may be a generous way of saying someone got tricked into sending money into the wrong account with some forged invoices, or bogus emails, and poor invoice control." 

Norfund CEO Tellef Thorleifsson is promising swift action to prevent the organization from getting conned again: "This is a grave incident. The fraud clearly shows that we, as an international investor and development organisation, through active use of digital channels are vulnerable," he said.

"The fact that this has happened shows that our systems and routines are not good enough. We have [to] take immediate and serious action to correct this."

In addition to getting law enforcement involved, Norfund said it is working with the Norwegian Ministry of Foreign Affairs and its bank, DNB, to track down the thief and get the money back. PwC is also being called in to do an evaluation for the IT security setup at the fund.

"Norfund hopes that by being open about this incident we can contribute to reducing the risk of others being victims of similar fraudulent activities," the investment firm said.

Excellent course of action to take. We strongly suggest you step all employees through new-school security awareness training, which to a very high degree simply prevents disasters like this from happening in the first place. Source: The Register

Will your users respond to phishing emails?

KnowBe4's Phishing Reply Test (PRT) is a complimentary IT security tool that makes it easy for you to check to see if key users in your organization will reply to a highly targeted phishing attack without clicking on a link. PRT will give you quick insights into how many users will take the bait so you can take action to train your users and better protect your organization from these fraudulent attacks!

PRT-imageHere's how it works:

  • Immediately start your test with your choice of three phishing email reply scenarios
  • Spoof a Sender’s name and email address your users know and trust
  • Phishes for user replies and returns the results to you within minutes
  • Get a PDF emailed to you within 24 hours with the percentage of users that replied

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-reply-test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.