[Tech-l] Scam Alert

Thor Sage sage at mveca.org
Mon Mar 4 15:45:40 EST 2019


Please distribute to all payroll staff and other stakeholders.

http://education.ohio.gov/Media/Ed-Connection/March-4-2019/Please-read-Scam-targets-school-districts-direct

Please read: Scam targets school districts' direct payroll deposits
3/4/2019
The Auditor of State's Office has received information that, over the last few weeks, several Ohio school districts have been victims of an email scam sometimes referred to as "CEO Fraud." This targeted spear phishing attack uses familiarity to trick individuals into taking an action.

Each of the instances reported to the Auditor of State's Office involves a cybercriminal impersonating the superintendent or a principal of a school district. In each case, an email was sent to a payroll department employee asking that a change be made to the bank account linked to the superintendent's or principal's direct deposit. The payroll deposit then is directed to the criminal. The scam is identified only after the impersonated employee realizes he or she did not get paid. These scams are especially effective because the staff member involved believes he or she is dealing directly with a district or school official who has the authority to make such a request.

The Auditor of State's Office encourages districts to educate their staffs on this type of scam and be on the lookout for any such activity. The state auditor also encourages districts to:
*         Examine the procedures in place for making changes to an employee's payroll bank account; and
*         Consider taking verification steps outside of the email system before making such a change.
First and foremost, report all scams to the local police department and the FBI. If a district or school loses cash or assets because of such a scam, officials also should contact Ohio's Fraud Hotline at (866) FRAUD-OH.



Thor Sage
Executive Director
Miami Valley Educational Computer Association
937-767-1468  x3101
[http://www.mveca.org/images/logo.gif]<http://www.mveca.org/>       [i] <https://www.linkedin.com/company-beta/3947840/> [t] <https://twitter.com/mvecarcog> [f] <https://www.facebook.com/MVECA-707401659416692/>
Not-for-profit Technology Services for Education and Local Governments



-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listserv.mveca.org/pipermail/tech-l/attachments/20190304/fe9507d0/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image001.jpg
Type: image/jpeg
Size: 3184 bytes
Desc: image001.jpg
URL: <http://listserv.mveca.org/pipermail/tech-l/attachments/20190304/fe9507d0/attachment.jpg>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image002.jpg
Type: image/jpeg
Size: 1229 bytes
Desc: image002.jpg
URL: <http://listserv.mveca.org/pipermail/tech-l/attachments/20190304/fe9507d0/attachment-0001.jpg>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image003.jpg
Type: image/jpeg
Size: 1197 bytes
Desc: image003.jpg
URL: <http://listserv.mveca.org/pipermail/tech-l/attachments/20190304/fe9507d0/attachment-0002.jpg>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image004.jpg
Type: image/jpeg
Size: 1194 bytes
Desc: image004.jpg
URL: <http://listserv.mveca.org/pipermail/tech-l/attachments/20190304/fe9507d0/attachment-0003.jpg>


More information about the Tech-l mailing list