MNS Credit Management Group

Mail Hacking/ Change Of Bank Account

Mail Hacking / Change Of Bank Account

MNS Credit Management Group
What

Mail Hacking / Change Of Bank Account

Industry

Air Cooling Systems

When

April, 2021
Details


An importer in India delivered air conditioner and its spare components to a reputable company whose shareholder is a prominent player in India's electronics industry.
 
Exporter filed a claim with the foreign insurance company after Importer missed his payment deadlines.
 
A renowned Chinese company is the exporter that provides branded air conditioners globally.
 
MNS contacted Importer who explained the issues behind the non-payment. According to the Importer, there was a hacking issue in both Exporter and Importers mail IDs and Importer remitted a sum of approx. 2 Millions USD to the hacker’s account in USA, after receiving formal documentation on the exporter’s letterhead duly sealed though were obtained from some previous email attachments. All the Emails received from the fraudster used the domain name of Exporter - which can be easily overlooked (example: xyz@abc- home.com & xyz@abc--home.com) and the subject matter of the email was accurate and matched with details available with Importer. The said emails have identical content to the original emails actually sent by Exporter, showing Fraudster accessed to the Exporter emails by bcc or hacking. The hacker also used the rubber stamp of the Exporter probably extracted from some previous email attachments.
 
It is also observed that the hacker has played a double game and the responses to the exporter’s legitimate email IDs were shot from another similar domain he registered which was very similar to the Importer’s domain (example: abc@globalworld.com & abc@globalworlds.com) with fabricated SWIFT copies.

Authorized Communications Notice

An important advisory from MNS Credit Management Group

All official communications from MNS Credit Management Group Private Limited are issued only through authorized company email domains and include appropriate sender identification and contact details.

We do not conduct business communications through free or public email services (such as personal webmail accounts).

If you receive any communication claiming to represent MNS Credit Management Group Private Limited from an unrecognized source, containing threats, or lacking proper company identification, please treat it as suspicious and report it to us immediately at info@mnscredit.com.

Please note that our only official domains are:
  • mnscredit.com  —  Official Public Domain
  • mnscredit.in  —  Official Internal Domain (for Reporting Purpose)
Any communication originating from other domains or unofficial sources claiming to represent our organization should be independently verified with us before taking any action.