55th Largest Private Company In America Sent Millions To China Because An Email Told Them To
from the you've-got-mail dept
You've all heard of this kind of scam before. Some nefarious person or group gets a hold of someone's email or computer screen, pretends to be someone in some official capacity, and demands a whatever sum of money they can get away with. Some of the time these scammers pretend to be the IRS, or a utility company, or even law enforcement. What these scams tend to mostly have in common is that they go after private citizens en masse, in the hope to entice whatever percentage of the more gullible amongst us to pay up. What you don't expect to hear about is one of the largest corporations in the United States essentially falling for the same thing.
The Scoular Co., an employee-owned commodities trader founded 120 years ago, has been taken for $17.2 million in an international email swindle, according to federal court documents. An executive with the 800-employee company wired the money in installments last summer to a bank in China after receiving emails ordering him to do so, says an FBI statement filed last month in U.S. District Court in Omaha.Sort of takes your breath away, doesn't it. One would like to think that it takes more for any company to move millions of dollars around internationally than a simple email string. Whatever else, this seems to indicate a complete failure of process, with the lack of checks against fraud and mistakes occurring on stunning levels. In attempts to explain how this happened, Scoular CEO Chuck Elsea wove a tail of compromised identities (including his) and coincidences that caused all of this to happen. The tale, however, leaves the reader certain that there was still some serious stupid going on here.
The gambit involved emails sent to a Scoular executive that purported to be from Elsea and the company’s outside auditing firm. The emails directed the wire transfer of millions of dollars to a Chinese bank. But court documents say the emails were really from impostors using email addresses set up in Germany, France and Israel and computer servers in Moscow. The three wire transfers, the FBI says, happened in June 2014. They were prompted by emails sent to Scoular’s corporate controller, identified in the FBI statement as McMurtry. The emails purported to be from Scoular CEO Elsea, but were sent from an email address that wasn’t his normal company one.Which is precisely where this scam should have died on its scammy vine, wilting under the dry heat of "haha, the boss got his personal email hacked." The idea that millions of dollars can be ordered transferred from an email address not associated with the company is ludicrous. Die, however, the scam did not.
The first email on June 26 instructed McMurtry to wire $780,000, which the FBI statement says he did. The next day, McMurtry was told to wire $7 million, which he also did. Three days later, another email was sent to McMurtry, instructing him to wire $9.4 million. McMurtry again complied. The first two emails from the faux CEO contain the swindle’s setup, swearing the recipient to secrecy over a blockbuster international deal.McMurtry has reportedly been cooperating with the FBI and providing them with the reasons he so easily complied with the rogue emails' requests. Those excuses include some of the scam emails looking like they came from the company's outside accounting firm and that Scoular had indeed been in discussions for an expansion into China. Those excuses, though, don't alter the fact that a simple phone call to the parties involved, to Elsea's office (or, hell, at the watercooler or whatever), or to the general office number for the accounting firm would have exposed the scam entirely and saved the company 17 mil-do in the process. How does something like that happen?
Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.
Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.
While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.
–The Techdirt Team
Filed Under: china, chuck elsea, email scam, gullible, scam
Companies: scoular
Reader Comments
Subscribe: RSS
View by: Time | Thread
[ link to this | view in chronology ]
And therein lies the real problem...
[ link to this | view in chronology ]
Re: And therein lies the real problem...
$17.2 million for a company that size just barely makes it over the rounding error threshold...
[ link to this | view in chronology ]
Re: Re: And therein lies the real problem...
DUH!
[ link to this | view in chronology ]
Re: Re: Re: And therein lies the real problem...
[ link to this | view in chronology ]
Re: Re: Re: Re: And therein lies the real problem...
[ link to this | view in chronology ]
Re: Re: Re: Re: Re: And therein lies the real problem...
Then you're left with the problem of how to get such self-entitled dinosaurs to accept they need to check their email from time to time. Peons don't even want to do email nowadays, thinking Facebook is bleeding edge tech. Masters of the corporate universe resent being told they have obligations even peons don't want to put up with.
[ link to this | view in chronology ]
Re: Re: And therein lies the real problem...
[ link to this | view in chronology ]
Re: And therein lies the real problem...
False. Stupidity can be fixed. However, doing so is illegal in most jurisdictions.
[ link to this | view in chronology ]
Re: Re: And therein lies the real problem...
[ link to this | view in chronology ]
[ link to this | view in chronology ]
Re:
I believe you've confused the victim with the perpetrator. I don't believe McMurtry actually forwarded the spam to anyone.
... including his boss.
[ link to this | view in chronology ]
Re: Re:
[ link to this | view in chronology ]
Re: Re:
No, GP was on target. Spam exists because the sender knows that if he/she sends enough spam mails, one of them will reach someone gullible enough to do something that makes money for the spammer. The cost of sending spam is very low, so even a few suckers per ten thousand mail can make the enterprise profitable. By being that gullible recipient, McMurtry reinforced the idea that a spammer can sometimes get a gullible recipient. Spam will end when it is unprofitable. Raising the price of sending spam is a non-starter, so it will only become unprofitable by reducing the number of capable gullible recipients. (A gullible recipient who has no money to give is unprofitable.)
[ link to this | view in chronology ]
I am a Nigerian prince who happens to have a couple bridges for sale which also have the added bonus of increasing your manhood and stamina. =P
[ link to this | view in chronology ]
[ link to this | view in chronology ]
Re:
Wall St. and stockholders, usually hands-off institutional investors who don't care about anything but stock price and dividends.
[ link to this | view in chronology ]
Just goes to show
[ link to this | view in chronology ]
Re: Just goes to show
I'd be willing to bet that the largest dollar amount wired ($9.4 million) was calibrated to be just under the companies single-signature signing authority.
Absolutely reeks of inside job, although frankly I doubt the controller was in on it. If he was smart enough to put the job together, he'd (presumably) be smart enough to transfer and hide the money in a way that didn't paint a target on his back.
[ link to this | view in chronology ]
[ link to this | view in chronology ]
[ link to this | view in chronology ]
Tale of a Tail
[ link to this | view in chronology ]
Cultural Failure
Millions of dollars moved on instructions emailed from a CEO's personal account reeks of a long-standing attitude of "don't bother me, I'm important."
The tragedy is that the guy who pushed the button will get punished, while the bosses fostered such a scam-friendly environment will skate away, certain they did nothing wrong.
[ link to this | view in chronology ]
I would kindly ask you to send a bajillion gazillion petrol dolars to china@paypay.com as soon as possible....no, dont think about it, trust me im a friend, just push that "send bajillion gazzilion" buton, dont think about, your boss would totally be fiiiiiine with it.
Yours sincerly Not China
Thankyou for your stupidity
P.S
Remember china@paypal.com
[ link to this | view in chronology ]
LOL
[ link to this | view in chronology ]
Ahem...
[ link to this | view in chronology ]
[ link to this | view in chronology ]
Send us millions and don't bother checking if we are legitimet and in return we will give your a few hundred grand
[ link to this | view in chronology ]
[ link to this | view in chronology ]
Not as easy to spot as you might think
Now personally I would double check before sending a single penny somewhere, but I know places where millions, if not tens of millions of dollars are authorized to be moved/paid with just a few emails every day.
[ link to this | view in chronology ]
[ link to this | view in chronology ]