Agari Identifies Cybercriminal Organisation Behind Spate of Fraudulent COVID-19 Unemployment and CARES Act Claims
May 2020 by Agari
Agari announced that it has linked the West African cybercriminal organisation dubbed Scattered Canary to massive fraudulent schemes related to the COVID-19 pandemic, targeting at least eight states that now include Hawaii.
“We have been tracking Scattered Canary for more than one year and briefed the U.S. Secret Service on this new development yesterday,” said Armen L. Najarian, CMO and Chief Identity Officer, Agari. “We’ve observed that this is by far one of the most complex and prolific cybercriminal organisations we have uncovered to date. Scattered Canary perpetrates a range of fraudulent schemes, including business email compromise (BEC) scams, unemployment fraud, social security fraud, student aid fraud, and now COVID-19 related fraud.”
Observations and threat intelligence gathering from Agari Cyber Intelligence Division (ACID) indicates that as of Sunday, May 17, Hawaii became Scattered Canary’s latest unemployment fraud victim, joining Florida, Massachusetts, North Carolina, Oklahoma, Rhode Island, Washington, and Wyoming.
While it is too early to measure the full fraud dollar loss impact on Hawaii, an assessment of Scattered Canary’s fraudulent attacks on the state of Washington could be a bellwether. Since April 29, the group has filed at least 174 fraudulent claims for unemployment with Washington. This is consistent with public reporting of a recent U.S. Secret Service alert mentioning that Washington has been the primary target of fraudulent unemployment claims. Based on communications sent to Scattered Canary from the state of Washington, these claims were eligible to receive up to $790 a week for a total of $20,540 over a maximum of 26 weeks. Additionally, the CARES Act includes $600 in Federal Pandemic Unemployment Compensation each week through July 31. This adds up to a maximum potential loss as a result of these fraudulent claims of $4.9 million.
Agari analysis shows that Scattered Canary exploits Green Dot prepaid cards to “cash out” its fraudulent claims. Prepaid cards have previously been exploited to facilitate payroll diversion BEC attacks because the cards can be used to receive direct deposit payments. Green Dot cards are also advertised as being able to receive government benefits, such as unemployment payments, up to four days before they’re due to be paid, making them an attractive vehicle for groups like Scattered Canary to use in scams.
Another tactic Scattered Canary employs to scale its operations is the use of Google Dot Accounts. The group sets up its attacks using versions of related Gmail addresses to mass-create email accounts for each target website. Scattered Canary has been able to create dozens of accounts on state unemployment websites and the IRS website dedicated to processing CARES Act payments for non-tax filers (freefilefillableforms.com), because Google ignores periods when interpreting Gmail addresses. This tactic provides Scattered Canary the ability to scale its operations more efficiently by directing all communications to a single Gmail account. Ultimately, use of “dot accounts” makes Scattered Canary very fast and efficient at committing large scale financial crimes.
Scattered Canary organised itself more than 10 years ago and is based in Nigeria. Its long operating history hardened its methods and prowess for committing fraud and socially engineered attacks. Agari first alerted law enforcement to Scattered Canary in early 2019.