• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

Ethical Hacking

William Bailey

Ethical Hacking

MIS 5211.701 ■ Fall 2021 ■ William Bailey
  • Home
  • INSTRUCTOR
  • SYLLABUS
  • Gradebook

Canadian University Scammer

August 27, 2019 by William Bailey 8 Comments

Just to kick things off.  Here’s an article describing scammers using phishing techniques netted 11 million Canadian (9 Million US).

https://motherboard.vice.com/en_us/article/yww4xy/a-canadian-university-gave-dollar11-million-to-a-scammer

The article says this is not technically hacking.  I don’t agree, but what do you think?

For those with an audit background, it also points out that anti-fraud controls were either not in place, or not effective.

Filed Under: Week 01: Overview Tagged With:

Reader Interactions

Comments

  1. Eugene Angelo Tartaglione says

    August 25, 2021 at 10:24 am

    The university fell for a phishing scam that was impersonating a vendor they were using. This is definitely an issue where the university did not do its due diligence to verify who they were making the payment to, especially for such a large sum!

    Log in to Reply
  2. Krish Damany says

    August 28, 2021 at 1:39 pm

    Based on your definition of “hacking” (exploring the difference between how something is supposed to work and how it really works), I do believe that what this person did was a form of hacking. This person used a bit of social engineering while in this phishing scam, by impersonating a vendor that has had a previous relationship with the university, to get access to monetary compensation. How it’s supposed to work is that the user (victim) would have to get proof that the person is who they say they are, and how it actually worked was that the victim trusted based on the vendor and subject of the email without a proper vetting process. This is why I believe this is a hack versus just an ordinary phishing scam.

    Log in to Reply
    • Andrew Nguyen says

      December 5, 2021 at 3:47 pm

      I agree that based on the definition, this is considered a form of hacking.

      I also think it brings up an interesting discussion that hacking can take various forms, and it is important to be aware of it (phishing, social engineering, etc.)

      Log in to Reply
  3. Patrick Jurgelewicz says

    September 13, 2021 at 3:03 pm

    Although I initially did not consider this “hacking” when I read the article, I agree with Krish that this does fall under hacking according to this course’s definition. This shows the importance of broadening our views of what hacking is. Attackers will try to achieve their goal by any means necessary, and many times it is not through common methods that most people think of when they think about hacking (example: brute force attacks). To try to keep attackers out, it is important to think like an attacker and consider what they might do.

    Log in to Reply
  4. Parmita Patel says

    September 17, 2021 at 10:44 pm

    The university should have done a better job of confirming who the money was going to and where knowing if it was a large amount of money. I think there should have been security checks in between people to make sure that the money was going to the right place and people. This was a different way to get someone to give them money and it does not necessarily have to be from the backend.

    Log in to Reply
  5. Tal Eidenzon says

    November 30, 2021 at 12:16 am

    “Hacking” is a term with a very wide meaning. In the original meaning, hacking involves using a tool in ways that were not meant to be used. In more recent interpretations, a malicious meaning is attached to the term. Nonetheless, in this instance, phishing has a malicious aspect to it as well as abuse email.

    Log in to Reply
  6. Antonio Cozza says

    November 30, 2021 at 10:48 pm

    After reading this article, I was thinking something similar to what Tal has said; hacking is a term with a much larger scope today than it once had. With this in mind, it is interesting to think about whether or not one would classify this as hacking. Social engineering is a subset of phishing, and doesn’t necessarily have to include any technical breach, but is and also is not considered hacking depending who one asks. One can social engineer their way into a restricted area in a building as well, is this hacking? If we think about the more broad and general concepts, then I would argue that this is hacking in the same vein that cybersecurity is not exclusively an IT function like so many people commonly misperceive.

    Log in to Reply
  7. Andrew Nguyen says

    December 5, 2021 at 2:37 pm

    I think that this can be considered a form of hacking (the combination of phishing and social engineering techniques used to scam the university of $11 million dollars).

    While I do disagree with the article saying that it is not a form of hacking, I think it brings up a discussion point that hacking may take various forms, and that this is something to be aware of.

    Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Uncategorized (1)
  • Week 01: Overview (2)
  • Week 02: TCP/IP and Network Architecture (2)
  • Week 03: Reconnaisance (2)
  • Week 04: Vulnerability Scanning (1)
  • Week 05: System and User Enumeration (1)
  • Week 06: Metasploit (1)
  • Week 08: Malware (1)
  • Week 09: Web Application Security (1)
  • Week 10: Web Application Hacking (1)
  • Week 11: Cloud Computing & Virtualization (2)
  • Week 12: Wireless (2)
  • Week 14: Review of all topics (1)

Copyright © 2025 · Course News Pro on Genesis Framework · WordPress · Log in