Ronald Deabler, a business owner and a Certified Public Accountant, was recently sentenced to four years in prison for his involvement in a scheme to launder $5.3 million fraudulently obtained from Children's Healthcare of Atlanta, Inc. (CHOA).
In June 2023, a commercial furniture vendor CHOA used was hacked. The hacker gained access to the vendor's email system. The hacker impersonated one of the vendor's employees and contacted CHOA. Then, the hacker requested that the vendor's bank account information be updated for ACH payments.
The new bank account information provided by the attacker was Deabler's bank account. Deabler agreed to distribute money stolen from the CHOA for a commission.
The attacker directed CHOA to wire $5.3 million into the vendor's "new" bank account. Shortly after, Deabler opened a second bank account into which he attempted to move the $5.3 million. The bank prevented this action, so Deabler transferred more than $1 million to the secondary account and converted roughly $3.5 million into cashier's checks, which he mailed to individuals and entities at the attacker's direction.
CHOA and the furniture vendor discovered the fraud, and CHOA notified its bank. The bank traced the stolen funds to Deabler's bank account. Approximately $4 million of the stolen money was recovered from Deabler's accounts and from the accounts that received Deabler's cashier's checks.
Source: https://www.justice.gov/usao-ndga/pr/former-cpa-sentenced-federal-prison-laundering-funds-stolen-childrens-healthcare
Commentary
A compromised vendor email account and poor ACH payment alteration controls combined to create a $5.3 million loss.
In the case above, the attacker did not need to breach the system of the targeted organization. It was enough to gain access to a vendor's email system, impersonate the vendor, and extract money from the target. Once a trusted vendor's bank account is under the control of a cyber criminal, requests to change banking information may look completely ordinary.
Such emails would appear to be from the correct domain, from the correct contact, and contain all proper vendor branding/identification.
Without proper ACH alteration controls, such emails may trick employees and lead to losses.
To reduce exposure to fraudulent vendor emails and strengthen ACH controls, consider these steps:
· Require secondary communication with the vendor to verify the bank account change. This communication should be verbal, using a known phone number on file, not a number listed in the change request email.
· Always require dual approval on all vendor changes. The employee who approves the change should not be the same employee that initiated the change or received the first communication.
· Recertify payment details with each vendor periodically and require recent evidence of ownership for any account change.
· Train all accounting staff regarding the dangers of vendor email compromise, including the urgency, secrecy, and bypassing of internal controls tactics designed to make them transfer money or make account changes quickly.
· Utilize a mandatory hold period before funds are released when making the first payments to a recently changed vendor account.
The final takeaway is that email alone should not be the trusted method by which ACH payment information is changed. To combat fraud, organizations must have strong cybersecurity training in place on the realities of vendor email compromise as well as on strong internal ACH payment controls. Utilizing both may help avoid the risks.