VCs find exciting new way to blow $1m: Wire it directly to hackers after getting spoofed

VCs find exciting new way to blow $1m: Wire it directly to hackers after getting spoofed

Who needs an elevator pitch when you have man-in-the-middle attack?


A group of hackers used a compromised email account to steal a start-up's $1m venture capital payment.


The incident response team at security house Check Point says it was called in to investigate the case of money that a Chinese VC firm had reported missing after it was supposedly sent to a startup in Israel.


It was believed that the attack was down to a compromised email account that had been used to re-route the payment to an account controlled by the attacker, a rather cut-and-dry business email compromise (BEC) operation.


As it turned out, however, the attack was a bit more complicated.


"Apparently, a few months before the money transaction was made, the attacker noticed an email thread announcing the upcoming multi-million dollars seeding fund and decided to ..

Support the originator by clicking the read the rest link below.