Security

Cyber-crime

Police take just 2 days to recover $40M stolen in business email scam

Timor-Leste is a known cybercrime hotspot


Two days is all it took for Interpol to recover more than $40 million worth of stolen funds in a recent business email compromise (BEC) heist, the international cop shop said this week.

Interpol was called in after an unidentified Singaporean commodity biz filed a police report on July 23 claiming it had been scammed out of $42.3 million four days earlier. 

The company only became aware of the bamboozling when a supplier, the intended recipient of the money transfer, got in touch asking why it hadn't been paid.

Cybercrims capitalized on the knowledge that the victim business worked with the supplier in question and asked that the next payment made to it was sent to a new account based in Timor-Leste. The email address from which that request came was slightly misspelled but was convincing enough to trick the employee into sending the funds anyway.

Timor-Leste is known for being an attractive country for organized crime groups (OCGs) given its proximity to both Southeast Asia and the South Pacific. The smuggling of drugs and other illegal produce is usually the crime of choice in this corner of the world, but money laundering and cybercrime is also fairly pervasive.

The country tabled a draft cybercrime bill in 2021 but it has still yet to make any substantial moves toward becoming law. Its vague wording has also caught the attention of digital privacy advocates about it potentially threatening freedom of expression and freedom of the press.

Regardless, the country's local police force assisted their Singaporean and Interpol counterparts, locating and intercepting $39 million from the scammers' bank account. Seven arrests were also made following the intervention, which in turn led to the discovery of more than $2 million in additional funds.

The Singaporean commodity company still hasn't had its stolen funds sent back to it yet, but "steps are being taken" to complete the process.

"Speed is crucial to successfully intercepting the proceeds of online scams, with police, financial intelligence units, and banks cooperating across multiple jurisdictions in a race against time," said Isaac Oginni, director of Interpol's Financial Crime and Anti-Corruption Center.

"The cooperation between authorities in Singapore and Timor Leste in this case was exemplary and demonstrates how quick action through Interpol can help recover funds taken from the fraud victims and identify the perpetrators."

BEC scamming is a highly lucrative business and is more costly to US victims than ransomware, according to a report from the feds earlier this year.

In 2023 alone, more than 21,000 complaints relating to BEC were filed with the FBI, which incurred adjusted losses exceeding $2.9 billion. 

For comparison, the same report said 2,825 ransomware complaints were made with adjusted losses topping $59 million. It's a large discrepancy in monetary losses, however, it should be noted that ransom payments are often made without informing law enforcement, and these losses may not account for downtime, recovery costs, and other finances associated with a ransomware attack. ®

Send us news
9 Comments

North Korean scammers plan wave of stealth attacks on crypto companies, FBI warns

Feds warn of 'highly tailored, difficult-to-detect social engineering campaigns'

Uncle Sam charges Russian GRU cyber-spies behind 'WhisperGate intrusions'

Feds post $10M bounty for each of the six's whereabouts

White House seizes 32 domains, issues criminal charges in massive election-meddling crackdown

Russia has seemingly decided who it wants Putin the Oval Office

Planned Parenthood confirms cyber-attack as RansomHub threatens to leak data

93GB of info feared pilfered in Montana by heartless crooks

Cicada ransomware may be a BlackCat/ALPHV rebrand and upgrade

Researchers find many similarities, and nasty new customizations such as embedded compromised user credentials

UK trio pleads guilty to running $10M MFA bypass biz

Crew bragged they could help crooks raid victims' bank accounts

Transport for London confirms cyberattack, assures us all is well

Government body claims there is no evidence of customer data being compromised

Novel attack on Windows spotted in phishing campaign run from and targeting China

Resources hosted at Tencent Cloud involved in Cobalt Strike campaign

RansomHub hits 210 victims in just 6 months

The ransomware gang recruits high-profile affiliates from LockBit and ALPHV

Iran hunts down double agents with fake recruiting sites, Mandiant reckons

Farsi-language posts target possibly-pro-Israel individuals

Feds claim sinister sysadmin locked up thousands of Windows workstations, demanded ransom

Sordid search history 'evidence' in case that could see him spend 35 years for extortion and wire fraud

Brain Cipher claims attack on Olympic venue, promises 300 GB data leak

French police reckon financial system targeted during Summer Games