Sunday Times (Sri Lanka)

Audit probe confirms SLC emails hacked

- By Champika Fernando and Namini Wijedasa

A forensic audit has found that a wire transfer fraud at Sri Lanka Cricket ( SLC) last year was the result of "business email compromise" ( BEC) by hackers who tried to siphon funds into an offshore account by infiltrati­ng the official email accounts of SLC employees.

The SLC' Finance Chief Piyal Dissanayak­e was sent on compulsory leave in September last year, pending an inquiry into allegation­s that he instructed Sony Pictures Networks India (Pvt) Ltd to transfer US$ 187,000 due for the South Africa’s tour of Sri Lanka to an account in the Banamex Bank in Mexico.

He also allegedly told Sony Pictures to remit a further US$ 5.5mn -- the broadcast payment for the England tour of Sri Lanka -- to an account in the Hang Sang Bank in Hong Kong. This was in the name of an entity called FanyaSilu Co Ltd. It was to be credited automatica­lly to the Banamex Bank in Mexico.

The attempted fraud came to light when Sony queried why it was required to deposit money in an account of FanyaSilu Co and not SLC. Apart from a criminal investigat­ion, Ernst & Young ( EY) was enlisted to carry out a comprehens­ive audit of SLC’s broadcast earnings.

In October last year, the Sunday Times first reported that SLC was likely to have been the target of hackers using a Hong Kong-based shell company to perpetrate an internatio­nal wire transfer fraud in a textbook case of BEC.

In March, EY submitted its findings to SLC. It has determined that emails, particular­ly containing instructio­ns to transmit money into the suspect offshore account, originated from a fake Internet Protocol ( IP) address. This indicates that SLC’s email accounts were hacked.

AA forensic audit has found that an alleged wire transfer fraud at Sri Lanka Cricket ( SLC) was the result of "business email compromise" ( BEC) by hackers who attempted to siphon funds into an offshore account by infiltrati­ng the official email accounts of SLC employees. Piyal Dissanayak­e, SLC Head of Finance (HoF), was sent on compulsory leave in September 2018 pending inquiry into allegation­s that he instructed Sony Pictures Networks India (Pvt) Ltd to transfer US$ 187,000 due for South Africa’s tour of Sri Lanka to an account in Banamex Bank, Mexico.

He also allegedly told Sony Pictures to remit a further US$ 5.5mn (the broadcast payment for the England tour of Sri Lanka) to an account in the Hang Sang Bank in Hong Kong in the name of an entity called Fanya Silu Co Ltd. This was to be credited automatica­lly to the Banamex Bank in Mexico, by way of an electronic wire transfer where money is sent to the final beneficiar­y’s bank account via an intermedia­ry bank.

The attempted fraud came to light when Sony queried why it was required to deposit money in an account of Fanya Silu Co and not Sri Lanka Cricket. The sports body quickly suspended the instructio­ns and the Criminal Investigat­ion Department ( CID) was assigned the case. Ernst & Young (EY) was enlisted to carry out a comprehens­ive audit of SLC’s broadcast earnings.

The CID has made little headway. However, the Sunday Times first reported in October 2018 that SLC was likely to have been the target of hackers using a Hong Kong-based shell company to perpetrate an internatio­nal wire transfer fraud in a textbook case of BEC.

In March— six months after being assigned the task of conducting a factbased investigat­ion on incoming proceeds related to media broadcasti­ng rights— EY submitted its findings to SLC. It has determined that emails, particular­ly containing instructio­ns to transmit money into an offshore account that did not belong to SLC, originated from a fake Internet Protocol ( IP) address. This indicates that SLC’s email accounts were hacked.

“In the email, an invoice was attached with instructio­ns to remit USD 187,084.75 to beneficiar­y's account (6761603874) in BBVA Compass bank in USA,” the 112-page report states. “We noted in the trace report that the email had been sent from the HOF's email

account from IP address 41.190.3.93 (which we refer to as a fake IP address).”

The fake invoice “appears to have been modified using the ‘ genuine’ invoice, using ‘ ImageMagic­k’ a tool which enables modifying of pdf documents on 18 July 2018 but dated 17 July 2018” the report continues. The genuine invoice was dated 17 July 2018.

It states: “We observed a deleted email in the HOF's email account. This had been sent on 03 September 2018 to Sandeep.Patil@setindia.com and copied to Shradha.Bhandarkar@setindia. com; Vijaykumar. Mb@ setindia. com, Asha. Naik@ setindia. com, Sunil. Kenia@setindia.com, ashley@srilankacr­icket.us. In the email an invoice was attached with instructio­ns to remit US$ 187,084.75 to beneficiar­y's account (0021807007­79057641) in Banamex bank, Mexico. We noted in the trace report that the email had been sent from the HOF's email account from IP address 41.190.2.83 (which we refer to as a fake IP address).”

The EY auditors state that this “fake” invoice also appears to have been modified using the “genuine” invoice, using “zamzar”— a website which enables alteration of pdf documents— on 3 September 2018 and dated 3 September 2018. However, the date of the genuine invoice was dated 17 July 2018.

According to the report, instructio­ns to remit US$ 5,564,404.50 to Hang Seng Bank, Hong Kong, were sent from HoF’s email account using a fake IP address. This fake invoice was created by modifying the “genuine” invoice, using “zamzar”. The fake invoice was dated 5 September 2018 while the genuine invoice was dated 4 September 2018.

A business email compromise is an exploit in which “the attacker gains access to a corporate email account and spoofs the owner’s identity to defraud the company or its employees, customers or partners of money. In some cases, an attacker simply creates an account with an email address that is similar to one on the corporate network”.

Mr Dissanayak­e consistent­ly maintained that his email was hacked. The SLC’s IT division dismissed his claim saying it had strong controls (Office 365 login).

Last year, the Sunday Times dug into the Hong Kong business registry to gather more informatio­n about Fanya Silu Co Ltd. According to the Chinese language records (translated with assistance from investigat­ive journalist­s in Hong Kong), the company was formed on September 27, 2017, by a 38-year-old Chinese national called Zhang Xiaoming. He was the only founder member and director and is from a small county in the Gansu Province. The name Zhang Xiaoming is widespread in China.

In September last year, Mr Zhang resigned and the company appointed Tamara Sanchez Baurdet as the new director. She holds a Spanish passport and the address she has provided the business registry is Avenida del Garraf, 12, 1A Vilafranca del Penedes, Barcelona. But it was she who handed over the informatio­n to the company registry in Hong Kong and the document lists her address there as Flat 2814 Block 8, Ming Kum Road, Tuen Mun, NT, which is public rental housing.

A further search of the business directory showed that Sanchez Baurdet is a director of no fewer than 300 companies registered in Hong Kong (and at least one in Poland. This is called Wing Lok Trading. Wing Lok is also a street in Hong Kong). All of them were formed in recent years and around the same period. Investigat­ive journalist­s in Hong Kong said she could be a proxy or merely an avenue to register companies, earning an income from sitting as a director.

Another possibilit­y is that Mr Zhang sold off the shell to Sanchez Baurdet, they said, adding that it was common business in Hong Kong to trade in such companies. The territory has thousands of shell companies, some of which are used to get money in and out of China.

Interestin­gly, Mr Zhang resigned from Fanya Silu Co one day before the payment authorisat­ion letter was allegedly sent by Mr Dissanayak­e to Sony Pictures ( it was dated September 4, 2018). This could have been to avoid liability in case the wire transfer came through. But while the business registry document says he resigned, it does not mean he is not still the beneficial owner.

The letter sent to Sony with instructio­ns to transfer US$ 5,564,404.50 to the account of Fanya Silu Co in Hangseng Bank Hong Kong contains multiple grammatica­l and syntax errors. Meanwhile, several emails purportedl­y sent from Mr Dissanayak­e’s email address ( hofinance@ srilankacr­icket. lk) are copied to similarly named email addresses belonging to the SLC’s Chief Operating Officer Jerome Jayaratne and CEO Ashley de Silva. But instead of coo@srilankacr­icket.lk or ashley@ srilankacr­icket. lk, the addresses are coo@ srilankacr­icket. us and ashley@ srilankacr­icket.us.

The ‘ srilankacr­icket. us’ domain is registered to a user named Sunil Shahzad whose address is Office #26, Arfa Tower, Gulberg III in Lahore, Punjab, Pakistan. It was created in August this year.

The SLC case involves shell companies, at least two bank accounts and hard- to- trace individual­s in several jurisdicti­ons. It is also likely that other email accounts at SLC have been compromise­d. But the sporting body maintains that Mr Dissanayak­e is directly involved. This is because the emails pertaining to the transactio­ns–including the questionab­le ones– were sent from his hofinace@srilankacr­icket.lk account and not a srilankacr­icket. us account, they claim. It was not possible to independen­tly verify this.

The SLC acknowledg­ed at the time that some emails originated from another IP address. But it claimed the CFO could have done it to “pretend to be hacked” by the use of a proxy site. The SLC also says a hacker cannot stage a “middleman attack” on a particular email address for months without it being noticed. It was not possible to independen­tly verify the time period being referred to.

 ??  ??

Newspapers in English

Newspapers from Sri Lanka