I’d like to tell you a story. Unfortunately it’s a true story, and it happened to me. I’m passing it on you so that my experience may hopefully serve you. I have changed some of the story a little, but the basics remain exactly as they happened.
On 21st November last year I made initial inquiries as to the purchase of a fibre/yarn related product through a very reputable maker. This family company has been in business since the 1970’s, and supplies the product I was interested in to Europe, New Zealand, Australia, Canada and America. The product is highly regarded, and extremely reliable. The woman I was writing to was very knowledgable, and I was very happy with what I learned.
We emailed back and forth and agreed on the style, and the price -$1200.
On 25th November I transferred the money to her account via bank transfer, and sent her a confirmation email.
One week later, I received an email from her, asking where the money was, as the product was ready to send. I replied, showing details of the bank transfer. 2 days later another email from her asking where the money was. I tried to ring her, but the number she’d sent me must have been incorrect, and I couldn’t get through.
Once again, I copied the bank transfer information into the email. I also asked her if the emails were going into her junk file. Sure enough I received a response. “Sorry, we checked the account and the money was there all the time. We will send the product next week”.
On the 12th December I received another email “Could you please send the money, we have the product waiting to despatch to you”. I tried a couple of times to ring the number on the website, but the number rang out.( At this point, I was starting to wonder if the lady had dementia or was unwell. After all, the business was a family business, and had been going since the 70’s.)
I send a response back,copying and pasting all the email correspondence we’d had -just in case she really did have dementia and had forgotten everything. In return, she said sorry, that she had to wait for another extra part to be made – but because I had waited for so long she’d throw it in for nothing. She would send it on the 18th and forward me a tracking number.
I still hadn’t received anything by 20th December, but I figured she’d closed for Christmas holidays.
On the 3rd January, I sent yet another email, outlining, once again, all correspondence, including the fact that I’d made payment more than a month before. When I came home from work the next day, there was an email from her- “please ring me urgently on this number”.
We finally got to speak, and she told me that from the email I’d sent the day before, she realised that her email account had been hacked.
The hackers had inserted their own account details when she’d sent the bank transfer information to me- way back on the 25th November, leaving the rest of her email intact. I’d paid into their account, not hers -I had never seen her account details at all.
What was more scary was that each time we emailed each other, they were changing the words, so I thought she had dementia, and she thought I was not going to pay.
Quite a scary case of stolen identity and internet theft.
I immediately went to my bank and told them the story, asking if the payment could be reversed. They rang their head office, but the following day, I was told that “because I had done the transaction myself, (the bank hadn’t done it) there was nothing they could do, and I should speak to the police instead”
I went to the local police station and reported the matter. Unfortunately, they could do nothing and suggested that I should report to ACORN, the federal government cybercrime arm. I raised a report online, and was given a reference number, but no time frame as to when action would be taken.
As you can maybe imagine, I was a bit frustrated. My thoughts were as follows. “I know the bank account of the hackers, because I have the bank record of transaction. Surely someone, somewhere can just freeze that account and investigate it”.
A friend suggested I ring my local MP’s office.
I can only wish our State and Federal Government were as efficient as the office of my local Member of Parliament, as I was given some very good advice, and a couple of different avenues to try.
The avenue I took was to contact the Financial Ombudsman, who said I should email the bank and ask for a “Final Decision Letter”, outlining why they felt they could take no further action.
So on 12th January I sent an email to my bank, mentioning that I had spoken to the Financial Ombudsman service and that he had suggested I ask for that letter.
About an hour after I sent that email, I received a phone call from a rather agitated person at the head office of the bank. “Why are you so impatient, these things take time, you can’t just rush inquiries like this, why did you contact the ombudsman, we are doing all we can”, and really getting quite angry.
So angry, in fact, that I had to raise my voice and interupt him “Just hang on a minute!. Your staff told me that I had to go to the police, that you couldn’t do anymore. What are you saying about an inquiry?”
“Yes well” he muttered, “they told you wrong, there is an inquiry, you only had to wait”.
To be honest, I was a bit ticked off. I didn’t know they were still investigating; his staff had told me there was nothing more they could do and they had received guidance from their head office – his department!.
I swallowed my annoyance, and told him how wonderful it was that they were taking action. He calmed down but still kept trying to insist that I’d jumped the gun.
So now, I will wait. I do not know if I will ever get my money back, nor do I know if I will ever find out whether they (hackers) will be caught and charged.
But my bank is trying to help, I’ve reported it to ACORN, and I’ve learned a few things.
Points to ponder.
- I paid by bank transfer because I deliberately keep a low credit card limit (and thus limit what pay. Both I, and the lady running the business, preferred bank transfer. I do NOT intend to increase my credit card limit just because of this issue. What would you do?
- I was asked why I don’t have a telephone number on my website. The idea has merit, but I am unable to take personal calls or respond to messages whilst working my other jobs. Initially, I added phone details to the site, but received a large number of unusual messages. (The word Platypus does not only refer to an Australian mammal, so I found out). Email, therefore, is my preferred method of correspondence. What’s your preferred method of correspondence?
- I have set up the font in my email to a slightly unusual one. If someone wants to change a sentence within, they will have to do a bit of extra work, eithermatch my font, or to change the whole of the email. Would you notice a change in font part-way through an email?
- The lady I bought the product off suggested changing the colour of the font each email, when dealing with money.
- I can’t help wondering if the words ‘Financial Ombudsman’ were actually what got some response from the bank. Have you had a similar experience?
- I found that the office of my local Member of Parliament were extremely helpful. I could only wish politicians at all levels were the same. I would suggest now, to anyone who is unsure of next steps in cases like this to talk to your local MP.
- Will I change who I bank with? Would you?
Please feel free to add any comments or ideas in the comments field at the bottom of the page.
It seems to me that the hackers made an awful lot of work for themselves. They had to check every email sent between us, (and I was the only customer affected) and they had to change the wording in the email, yet still keep on subject,(and the subject matter is a little unique). Not only that, the account that I paid the money into (the hackers account) was a genuine Westpac account. To open this account, they would have needed identity, including address, drivers licence etc. Totally traceable.
If I had the knowledge to become a hacker, I reckon I’d try to find an easier way!!
I still wanted the machine I’d ordered, so I paid the lady (and she got the money this time) and I got my machine. Over the next month or so, I will hone my skills, and then……..
That will be another story!
The team at Platypus Yarn value our readers. Please feel free to comment, we gratefully accept all feedback, good and bad.