Several parents mistakenly paid tuition fees to a fraudster impersonating a private school.
What happened?
The scam began when the school’s bursar, the individual responsible for managing the financial affairs of the school, fell for a credential phishing email. Credential phishing emails are used by cyber criminals to try and trick individuals into voluntarily handing over their login details, typically by directing them to a link that takes them through to a fake login page.
In this case, the bursar received an email from what appeared to be Microsoft, stating that if he wanted to continue to use his email account without interruption, he would have to validate his account details online. Not wanting to face any disruption to his work, the bursar clicked on the link provided, which took him through to an authentic-looking landing page where he inputted his email login details and gave no further thought to the matter.
Despite appearances, the webpage was fake, and the bursar had unwittingly volunteered his email login login details to the cyber criminal. What’s more, his email account didn’t have multi-factor authentication in place so they were then able to access the account remotely and gather valuable information. In particular, the fraudster was able to locate a spreadsheet stored in one of the bursar’s email folders containing a list of email addresses for the parents of current students, which was typically used for distributing general messages and updates from the school.
Using this, the fraudster then set up an email address that looked substantially similar to the bursar’s, with the addition of an extra letter to the address line. The next step was to carefully select which parents to target. Rather than adopting a scatter gun approach and emailing every parent on the list, the fraudster specifically selected parents based overseas. This was presumably done on the assumption that such parents are more likely to be paying both tuition and boarding fees, making them more lucrative targets.
With the targets selected, the fraudster sent out an email relating to the payment of school fees. The email began by outlining what the annual fees for tuition and boarding amounted to, but then stated that parents would be eligible for a discount of up to 25% if they paid for the spring and summer terms in one lump sum as opposed to paying separately at the start of each term. To add a sense of urgency to making payment, the email then went on to say that there was a deadline for payment in place, after which the discount would expire. Social engineering attacks rely on manipulating and exploiting typical human behaviours, and in this case the criminal was clearly aware that the scam would have a better chance of success if the parents were provided with a financial incentive to make the payment within a set time frame.
In addition, the email was well thought through and included a number of features to make it appear more authentic. For example, not only did the fraudster use proper spelling and grammar and include the bursar’s genuine email signature, he also went on to state that if the student was unable to complete the academic year for whatever reason, then the fees would be reimbursed on a pro-rata basis.
Unfortunately, this offer proved to be too tempting for some and six parents fell for the scam, transferring the tuition and boarding boarding fees over to the fraudulent account details provided on the email.
With tuition and boarding fees at the school costing some £10,050 per term, the amount paid out by each parent at a 25% discount amounted to some £15,075.
After a few days, when one of the parents that had received the email forwarded it to one of the school’s administrators to check the validity of the discount offer, the school became aware of the scam. The school immediately notified all parents about the scam and urged them to be aware of any suspicious emails that appeared to have come from the school.
How cyber insurance helped
The parents that fell for the scam reported the incident to their respective banks to see if the transaction could be either frozen or reversed, with mixed results. Of the six parents affected, just two were able to get their money back, with the rest left out of pocket to the tune of £60,300 collectively.
As it was a compromise of one of the school’s email accounts that had allowed the fraudster to gain access to the parents’ email addresses, the school felt morally obliged to reimburse those parents affected by the fraud. Fortunately, the school was then able to recoup most of this loss under the cyber crime section of its policy with CFC, which provides cover for customer payment fraud up to a maximum of £50,000.
Case Study takeaways
People in financial roles are often prime targets for cyber criminals. It is important for businesses to consider customer payment fraud cover, which proved invaluable in this scenario. Previously, educational establishments were targeted for personal details. Now, schools, especially private ones, and parents must remain vigilant and aware of phishing scams. Almost all modern businesses have some form of cyber exposure even if its just through the use of electronic payments or emails.
We hope we have provided you with useful insights on how skilful cyber criminals are becoming at parting businesses from their money, how difficult it is for people to spot a fake, and how a robust insurance policy can help manage those risks effectively. With access to a number of cyber liability products which can be tailored to your needs, McClarrons can help find the right cyber policy and cover for your business, giving you peace of mind around your protection.
For more information, or if you would like a complimentary insurance review, please do not hesitate to contact our Commercial Team on 01653 609151 or by emailing commercial@mcclarroninsurance.com.