Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Reducing Risks of Insider Attacks | Main | More Anti-Spyware Authority to the Federal Trade Commission »

Companies Get Phished, Too

ComputerWorld is reporting that Supervalu Inc., a U.S. grocery chain, is a victim of corporate phishing. It seems the phishers posed as partner businesses and requested that payments for their products be sent to new bank accounts. I'm not sure what their normal practice is to verify such a change but it didn't work in this case.


On Feb. 26 and 28, he said, the company received two fraudulent e-mails — one purporting to be from an employee at American Greetings Corp., and a second supposedly from an employee at Pepsi­Co Inc.’s Frito-Lay Inc. unit. Both of those firms are approved Supervalu supplier.

Between Feb. 28 and March3, Kilgroff’s filing said, Supervalu deposited more than $6.5million via multiple wire transfers to an HSBC Holdings PLC account listed in the fake American Greetings message.

And on March 2, Supervalu said it made eight separate wire transfers totaling $3.6 million to First Security Bank in Rogers, Ark., as requested in the second e-mail.

It's easy to take pot shots at this company, a la The Register which headlines their article on the scam with "World's most gullible supermarket chain falls victim to online scam." More important though is seeing the limits of email for business transactions. We simply can't trust it. If the topic of an email involves the exchange of money then the message can't be trusted. Maybe a few incidents like this will be enough to generate serious interest in digitally signed messaging. There is a lot of entrenched infrastructure to update and difficult questions about getting the process going but it will happen eventually.

Email is broken and we need to fix it.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/499

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net