The recent hacking and defrauding of Gazelles “The Scaling Up Guys” of $400,000 is yet another case that points up the need to have the maximum amount of cybersecurity (and cyber safety awareness) in relation to your computer networking vectors as possible. It all began on the morning of October 11 when Verne Harnish, the syndicated “Growth Guy” of Gazelles was on an unsecured public network prior to giving the day’s closing keynote speech at the Atlas business Forum in Moscow. Harnish believes that’s when his account was hacked, as he had just given instructions to his assistant to wire a substantial amount of funds to an account in Spain, prompting the hackers’ algorithm to scan for vulnerabilities and opportunity to steal the funds. It wasn’t until that Thursday (2 days later), though, that the actual theft of the $400K was detected.
How It Happened
Apparently the hackers – likely based in China, as they had the money wired to Hong Kong – sent an email to Harnish’s assistant imitating his communicative style, subject line, and signature, asking her to wire funds to 3 different locations. It didn’t seem strange to the assistant because Harnish was then involved with funding several real estate and investment ventures. The assistant responded back in the affirmative, and the hackers posing as Harnish replied in kind, effectively defrauding him (in a couple of moves) of $400,000.
Bank Alerts Deleted
The hackers also deleted Harnish’s daily bank alerts which he didn’t notice since, as he says, “I was busy with meetings in Moscow and/or travelling. Anyway, my assistant calls in the wire transfers because our bank had suggested that calling in was less costly in terms of exchange rates and fees when wiring internationally – but much less safe than using our CEO Portal which requires two people with dongles to approve (penny wise, pound foolish).” With the call-in, the assistant’s voice was verified, and then they called her back to confirm. “Dumb process,” said Harnish. “My fault and the bank’s for thinking that this is a sufficient ‘dual’ response.”
The Day “Almost Saved”
To the bank’s credit they did flag one of the three transactions to Hong Kong and suggested to Harnish’s assistant that she call him to verify them. She emailed Harnish asking when they could talk while he was on the road. Unfortunately, the cybercriminals intercepted this email and replied, again in Harnish’s style, that he was busy travelling, “that the transfer was good, and to get the bank to send,” in Harnish’s words. The emails were subsequently deleted (they were, however, able to recover all the deleted emails on the server to confirm they had been sent and received, and that the bank alerts were erased).
A Pricey Lesson Learned
Although the likelihood that Harnish will ever see his funds again are close to zero, there is a valuable lesson in his cyber-fraud debacle: He will now think twice and once again about the verifications and confirmations on such big wire transfers; he’ll also no longer operate with the thinking, “It can’t happen to me”; and when on the road away from HQ, he’ll never use unsecured public networks to do big business again. Harnish (and anyone familiar with his story) has gained extreme clarity on how and when to do big financial transactions (certainly not while on unsecured Wi-Fi networks, and especially not without in-person meetings with assistants, confirmations, etc.!).
Need Help with Your Cybersecurity Strategy?
If you need assistance in optimizing your cybersecurity strategies, you should speak to a cybersecurity specialist at Centerpoint IT, which is a proven leader in providing IT consulting in Roswell. Contact one of our helpful IT experts at (404) 781-0200 or send us an email at info@centerpointit.com today, and we can help you with any of your questions or needs.
Call our business managed IT services department directly at (404) 777-0147 or simply fill out this form and we will get in touch with you to set up a getting-to-know-you introductory phone call.
Fill in our quick form
We'll schedule an introductory phone call
We'll take the time to listen and plan the next steps
11285 Elkins Rd Suite E1, Roswell, GA 30076
© Copyright 2024 Centerpoint IT. All Rights Reserved. Website in partnership with Tech Pro Marketing. | Privacy Policy
Get Immediate Help For All Your Technology Issues (404) 777-0147
If you want our team at Centerpoint IT to help you with all or any part of your business IT, cybersecurity, or telephone services, just book a call.
Fill in your information below to get started today.
"*" indicates required fields
Fill in your information below to schedule now.
"*" indicates required fields
Before your organization commits to 1, 2, 3 or even longer managed IT services contract, understand what you’re getting. Centerpoint IT gives you the facts in our Managed IT Services Buyer’s Guide.
Enter your information below and we’ll send it over.
"*" indicates required fields
We are turning 15 and want to celebrate this milestone with you because without you this would not have been possible. Throughout this year look for special promotions on services and tools aimed at Making IT Simple for You so you can focus on your business.
We are turning 15 and want to celebrate this milestone with you because without you this would not have been possible. Throughout this year look for special promotions on services and tools aimed at Making IT Simple for You so you can focus on your business.
https://calendly.com/centerpoint-it/discovery-call