Educause Security Discussion mailing list archives

Re: Fake Direct Deposit Forms


From: "Barton, Robert W." <bartonrt () LEWISU EDU>
Date: Tue, 10 Sep 2019 16:25:47 +0000

We've been seeing this for a while now.  We moved to a) confirming with the requestor in an email that is not a 'reply 
to' and b) requiring additional documentation.  When we do find a request for forms that is fraudulent, I've responded 
with a fake form; it has a [Image result for emoji tongue out] emoji on it (for those not receiving the pic...tongue 
out face).  We've seen less attempts lately.

Executive Director of Information Security and Policy
Lewis University
One University Parkway
Romeoville, IL  60446-2200
815-836-5663

From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of 
Stevenson,Katherine Talia
Sent: Tuesday, September 10, 2019 11:02 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Fake Direct Deposit Forms

We received a warning about this sort of scam from Kentucky Homeland Security just this morning. The attack seems to be 
targeting government and edu sectors.


--

Katherine Talia Stevenson

(she/her/hers) (what's this?<https://www.glsen.org/article/pronouns-resource-educators>)

Executive Director - Enterprise Technology Services
Member - Commission on the Status of Women

University of Louisville - Information Technology Services

Phone: +1 (502) 852-2767

________________________________
From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV 
EDUCAUSE EDU>> on behalf of King, Ronald A. <raking () NSU EDU<mailto:raking () NSU EDU>>
Sent: Tuesday, September 10, 2019 11:14
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> <SECURITY () LISTSERV EDUCAUSE 
EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>>
Subject: [SECURITY] Fake Direct Deposit Forms


CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you 
recognize the sender and know the content is safe.

As an FYI, I have had three reports of fake Direct Deposit requests. Two of them included completed forms. The forms 
included the victims correct address and social. Both would have redirected full paychecks to American Express National 
Bank in Salt Lake City. Attached is an image of the electronic check. Given the size of the Equifax breach and the loss 
of the pertinent info, we cannot be the only institution seeing this.



Ron



Ronald King

Chief Information Security Officer



Office of Information Technology

(757) 823-2916 (Office)

raking () nsu edu<mailto:raking () nsu edu>

www.nsu.edu<https://urldefense.proofpoint.com/v2/url?u=http-3A__www.nsu.edu_&d=DwMFAg&c=OAG1LQNACBDguGvBeNj18Swhr9TMTjS-x4O_KuapPgY&r=UIHCRdveYdNkGYqs6orGB0fUHNEtsbB2WxrUlA1OViWePznXjbTl5iT3G1fau4Kg&m=jOAebUmI8m9mTBrPJUutfRIXXHa0YZknqN8eOPORM3Y&s=oaCVfIRmSScohVwOIkCsmezEn3b8HWPyG2WkHUdmmyg&e=>

@NSUCISO (Twitter)

[NSU_logo_horiz_tag_4c - Smaller]



**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.educause.edu_community&d=DwMFAg&c=OAG1LQNACBDguGvBeNj18Swhr9TMTjS-x4O_KuapPgY&r=UIHCRdveYdNkGYqs6orGB0fUHNEtsbB2WxrUlA1OViWePznXjbTl5iT3G1fau4Kg&m=jOAebUmI8m9mTBrPJUutfRIXXHa0YZknqN8eOPORM3Y&s=Q0akRg5syNQ5WS_Ci1XqnZn9XkLgckz-LDgDIzeE4s0&e=>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

This message (including any attachments) is intended only for
the use of the individual or entity to which it is addressed and
may contain information that is non-public, proprietary,
privileged, confidential, and exempt from disclosure under
applicable law or may constitute as attorney work product.
If you are not the intended recipient, you are hereby notified
that any use, dissemination, distribution, or copying of this
communication is strictly prohibited. If you have received this
communication in error, notify us immediately by telephone at (815)-836-5950 and
(i) destroy this message if a facsimile or (ii) delete this message
immediately if this is an electronic communication.

Thank you.

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


Current thread: