Construction firm sues after $588,000 online theft
A construction company in Maine is suing its bank after about $588,000 disappeared from its accounts, alleging the bank failed to spot suspicious account activity before it was too late.
Over a week-long period in May, fraudsters made six transfers from the online bank accounts of Patco Construction Company, a family-owned developer in Sanford, Maine, according a copy of the lawsuit on the Washington Post's Web site.
The money went to so-called "mules," or people who have agreed to receive the funds and then further transfer it to the fraudsters. The hefty withdrawals exceeded the amount of money Patco had in its account, which was used solely for payroll.
To make matters worse for Patco, its bank -- People's United Bank, or Ocean Bank of Delaware -- drew $223,237 on the company's line of credit to cover the withdrawals. Ocean Bank now wants Patco to pay that money back with interest, the lawsuit said.
After the bad transfer came to light, Ocean Bank did recover or block $243,406, but Patco is still on the hook for $345,444.
The fraudsters had a lot of key information needed to do the transfers, conducted through the ACH (Automated Clearing House) Network, used by institutions to handle direct deposits, checks, bill payments and cash transfers between businesses and individuals.
The ACH system has proved vulnerable to fraud as of late, due to its age and a lack of controls in the underlying transfer system, investigators have said.
Several Patco employees were authorized to use the account. They logged in with a company ID and password and also their own ID and password, the suit said. For transfers over $1,000, the employees then had to answer two challenge questions. Since most of their transfers exceeded that amount, the challenge questions were used often.
Apparently the fraudsters were able to collect that security information. They could have done that by infecting computers used to perform transfers with spyware, often installed through social engineering techniques or by exploiting vulnerabilities in out-of-date software.
Patco argues that Ocean Bank did not offer two-factor authentication, which often involves the use of a token that displays a one-time password or a verification telephone call.
Patco also said the transfers were initiated from IP (Internet Protocol) addresses that had never been used by Patco, the transfers far exceeded what the company normally performed and were on days other than Friday, when the company paid its employees by direct deposit.
"None of these transactions triggered any suspicious activity alerts on the part of Ocean Bank," the lawsuit alleges.
One of Patco's owners, Mark Patterson, did received a notification on May 13 that one of the ACH transfers was rejected due to an invalid account number supplied by the scammers.
Patco notified the bank the next morning, but the bank already started the day's ACH transfers and $111,963 floated away. Some of that amount was recovered.
IDG News Service
Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world
On Twitter now
Patco Construction Company
Powered by TwitterOn Twitter now
Patco Construction Company
Brian Proffitt
Microsoft/Novell: Breaking Down the Coupon Numbers
Esther Schindler
Drupal's Dries Buytaert on Building the Next Drupal
Tom Henderson
Top Ten General Operating Systems Rants
pasmith
PS3 motion controller delayed; goes up against Project Natal
sjvn
Neolithic Windows security hole alive and well in Windows 7
claird
Perl source code comparison makes for good reading
James Gaskin
Learn How To Print Pages In Order with Ink Jet Printers
mikelgan
Cell phones don't create stress or interrupt much
Sandra Henry-Stocker
How to: The Unix Interview
Where Google Chrome security fails: the password
I heard mention that the Chrome OS will have some sort of encryption available a la bitlocker. If it's possible to encrypt personal data using another password or key, then it may have potential for very secure data.... And Ubuntu has an 'encrypt home directory' option, perhaps google should follow suit.
- Dann
Join the conversation here
Quick, practical advice for IT pros. Made fresh daily.
- Ubuntu advances: Why Ubuntu server installations will surge in 2010
- Social media marketing: How to make friends with benefits
- More...
Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.






