{"id":11566,"date":"2020-05-04T22:58:19","date_gmt":"2020-05-04T20:58:19","guid":{"rendered":"https:\/\/amabhungane.org\/?post_type=stories&#038;p=11566"},"modified":"2024-09-20T13:17:44","modified_gmt":"2024-09-20T13:17:44","slug":"gone-phishing-business-owner-almost-scammed-by-fake-covid-19-government-tender","status":"publish","type":"post","link":"https:\/\/further.co.za\/amabwp\/gone-phishing-business-owner-almost-scammed-by-fake-covid-19-government-tender\/","title":{"rendered":"Gone phishing: Business owner almost scammed by fake Covid-19 government tender"},"content":{"rendered":"<p class=\"p1\">Bogus government tenders appear to be targeted at businesses listed on the national treasury\u2019s Central Supplier Database (CSD) because of a suspected leak within the publicly inaccessible database.<\/p>\n<p class=\"p1\">This database is, as it claims, a \u201csingle source of key supplier information\u201d for organs of state. Businesses register on the CSD and can then be considered for government contracts.<\/p>\n<p class=\"p1\">One business owner, who spoke to amaBhungane on condition of anonymity, explained that she only began to receive these bogus tenders when she applied to list her company on the database. She also fell for one such tender.<\/p>\n<blockquote><p><strong><em>Click on the Evidence docket for access to the website information we used in this story.<\/em><\/strong><\/p><\/blockquote>\n<p class=\"p1\">On 8 April 2020, the department of health sent out an email to businesses about a new tender for industrial sanitiser machines \u2013 specifically, for the DX610M model.<\/p>\n<p class=\"p1\">Prospective suppliers had six days to respond to the bid, which closed on 14 April.<\/p>\n<p class=\"p1\">Typically, when responding to a tender, there should be sufficient generic information accompanying the description of the tender, so that individual businesses can meet almost all the requirements with their own products \u2013 in this case, a sanitiser machine.<\/p>\n<p class=\"p1\">The business owner did a cursory investigation and concluded that the request for quotation (RFQ) seemed legitimate. She then responded to the request.<\/p>\n<p class=\"p1\">One day after submitting her bid, the business owner received a call from a supply chain official, Tshepo Mokoena. He congratulated her on her successful bid application.<\/p>\n<p class=\"p1\">Mokoena then asked her for the batch number on the product to check whether it would meet the requirements of the South African Bureau of Standards. \u201cThis seemed weird,\u201d the business owner said \u2013 because a batch number is only given after a product is manufactured.<\/p>\n<p class=\"p1\">He then asked her if she was sourcing the sanitiser machines locally, explaining that she had a 90% chance of losing out on the bid if she did not do so. He promised to provide her with a list of local producers.<\/p>\n<p class=\"p1\">In the end, he sent her the name and contact numbers of one company: Sanetex Hygiene.<\/p>\n<p class=\"p1\">Sanetex Hygiene also appeared to be the only company, after a cursory <a href=\"https:\/\/amabhungane.org\/wp-content\/uploads\/2020\/05\/200420-DX610M-Saniteser-Machine-Web-search.jpg\" target=\"_blank\" rel=\"noopener noreferrer\">Google search<\/a>, that could source the specific DX610M sanitiser machine for R7 500 per unit.<\/p>\n<p class=\"p1\">To secure her bid, the business owner planned to order the machines from Sanetex Hygiene to supply the department of health. However, she was alarmed when she received a response from the Russian equivalent of a Gmail address \u2013 an unusual email account for a South African business.<\/p>\n<h4>Phishing: Impersonating officials and what to do about it<\/h4>\n<p>Government departments have warned businesses against being fooled by email scams for some time. But the economic hardship from the coronavirus lockdown has increased the number of fraudulent emails circulating online.<\/p>\n<p>Even the <a href=\"https:\/\/www.who.int\/news-room\/detail\/23-04-2020-who-reports-fivefold-increase-in-cyber-attacks-urges-vigilance\" target=\"_blank\" rel=\"noopener noreferrer\">World Health Organisation<\/a> has warned the public about fake emails sent in its name. The problem with the fake emails is that cybersecurity is not a priority. According to a 2018 report from cybersecurity leader Varonis, \u201c58% of companies have over 100 000 folders open to everyone, and 41% have over 1 000 sensitive files open to everyone\u201d.<\/p>\n<p>This means that if one person in the corporate ecosystem lacks the necessary security and opens a dodgy email or PDF document, they could affect the company\u2019s overall security.<\/p>\n<p>Over the last five years, the principal at Pienaar Consulting, Maria Pienaar, has found that companies have dramatically cut their IT and security budgets, which is a problem as it opens the company to increased cyber and phishing attacks because of more gaps in their security solutions.<\/p>\n<p>She explained that there needed to be more public awareness and education \u201clike what the banks and cellphone networks have done with the scam alerts\u201d, \u201cCybersecurity must be a priority from the board level down, with closer collaboration with the business side, finance department and IT,\u201d she explained.<\/p>\n<p>Investigating cybercrime has increasingly become a priority for the police and the Specialised Commercial Crimes Unit of the Hawks, which handles cybercrime and has trained over 3 000 members between 2017 and 2019.<\/p>\n<p>In the <a href=\"https:\/\/nationalgovernment.co.za\/department_annual\/296\/2019-south-african-police-service-(saps)-annual-report.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">2018\/19 financial year<\/a>, the Hawks successfully investigated 104 cyber-related cases out of a total of 130 complaints \u2013 almost all of them leading to convictions.<\/p>\n<p>In its <a href=\"https:\/\/www.npa.gov.za\/sites\/default\/files\/annual-reports\/NDPP%20Annual%20Report%20-2018-19.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">annual report<\/a>, the National Prosecuting Authority noted the successful conviction of an IT specialist, who pleaded guilty to two counts of fraud and was sentenced to 10 years\u2019 imprisonment, three years of which were suspended.<\/p>\n<p>\u201cThe accused introduced, or caused to be introduced, or loaded into the company computer system a computer software which had the capacity to allow an unauthorised person to remotely access the company\u2019s user access codes, online bank account portal and users\u2019 online banking passwords,\u201d wrote the NPA.<\/p>\n<p>Then, in October 2016, someone accessed the company\u2019s accounts and stole R703 079. Although there has been an increase in training received by SAPS officials, Jacqueline Fick, a forensic investigator specialising in electronic fraud, believes that more needs to be done.<\/p>\n<p>According to Fick, the police do not have an accurate figure of the number of cybercrime cases because \u201cvictims do not report all these instances to the police\u201d. \u201cOr,\u201d she said, \u201cwhere the victim does report the crime, the docket is not opened.<\/p>\n<p>For example, a complainant is sent away, with police saying it is a commercial matter.\u201d _<em>Gemma Ritchie<\/em> [\/sidebarContentStory]<\/p>\n<p class=\"p1\">When Mokoena called the business owner the next day, she asked him about the Yandex email address. He hung up on her.<\/p>\n<p class=\"p1\">Had the business owner followed through with the tender, she would have paid for non-existent machines for a non-existent tender from a fake department of health official.<\/p>\n<p class=\"p1\">Several business owners say they have received RFQs for products ranging from geysers and wheelchairs to the electric cables required for trains used by the Passenger Rail Agency of South Africa. Such requests might have been appropriate if the businesses specialised in these products.<\/p>\n<p class=\"p1\">Advocate Jacqueline Fick, a forensic investigator specialising in electronic fraud, told amaBhungane that because of the large ecosystem of departments connected to the database to verify suppliers\u2019 credentials, there were vulnerabilities in the system.<\/p>\n<p class=\"p1\">This ecosystem includes the department of home affairs, the South African Revenue Service, company registrations that appear on the database of the Companies and Intellectual Property Commission, and government employees on the public service payroll system known as Persal.<\/p>\n<p class=\"p1\">Maria Pienaar, principal at Pienaar Consulting and formerly the chief information officer at Cell C, said: \u201cWhen departments in organisations are disjointed, it creates opportunities for fraud. In the case of government departments, each government department is responsible for their own budgets and how they apply these standards in the systems they implement.<\/p>\n<p class=\"p1\">\u201cThis leaves gaps for cyber fraud if there are not appropriate governance measures and audits in place to ensure compliance or if budgets are not appropriately applied to alleviate these risks.\u201d<\/p>\n<p class=\"p1\">When asked for comment, national treasury said: \u201cThe system was checked and proofed against phishing and hacking before the volatile situation of Covid-19. This is done frequently to ensure that possible breaches are prevented.\u201d<\/p>\n<p class=\"p1\">According to the treasury, there are more than 500\u00a0000 listed suppliers on the website and more than 700\u00a0000 registered users. More than 800 government departments and state-owned enterprises use the database to identify suppliers and check for compliance.<\/p>\n<p class=\"p1\">With the marked decrease in face-to-face human interaction as a result of the outbreak of the coronavirus pandemic, the opportunity for fraudsters to take advantage of business owners will rise exponentially.<\/p>\n<p class=\"p1\">So, what had the business owner missed?<\/p>\n<p class=\"p1\">This bid had several dodgy elements to it: the urgency of the bid; the short timeframe that businesses had to respond to it; the monopoly of suppliers for the item; and the unusual government email address: healthsupplychain-za.org.<\/p>\n<p class=\"p1\">When amaBhungane called the number listed on the email for comment and explained our intentions, the operator dropped the call.<\/p>\n<p class=\"p1\">According to the <a href=\"https:\/\/secure.csd.gov.za\/Home\/FraudAwereness\">CSD<\/a> website, fraudsters \u201csend a fictitious RFQ from what would seem to be a governmental email address and use a fake RFQ form with a logo and contact details of the contact person. These requests are usually \u2018urgent\u2019 and the whole process is concluded within a short period of time.\u201d<\/p>\n<p class=\"p1\">In 2016, the <a href=\"https:\/\/www.vukuzenzele.gov.za\/department-health-high-scam-alert-suppliers-and-service-providers-national-department-health\">department of health<\/a> complained of a high number of scammers using the following emails:<\/p>\n<p class=\"p1\"><span class=\"s2\">\u2022 <\/span>@gautenghealth-gov.org.za<br \/>\n<span class=\"s2\">\u2022 <\/span>treasury-gov.org.za<br \/>\n<span class=\"s2\">\u2022 <\/span>ghd@gautenghealth-gov.org.za<br \/>\n<span class=\"s2\">\u2022 <\/span>mphumalang-gov.org.za<br \/>\n<span class=\"s2\">\u2022 <\/span>NDOH@nationalhealth<br \/>\n<span class=\"s2\">\u2022 <\/span>@dh.gov.co.za<br \/>\n<span class=\"s2\">\u2022 <\/span>gov.org.za<br \/>\n<span class=\"s2\">\u2022 <\/span>tebogomambolo@healths-gov.org.za<br \/>\n<span class=\"s2\">\u2022 <\/span>tenders@doh.za.orgdoh<\/p>\n<p class=\"p1\">The official national department of health\u2019s emails end with \u201c@health.gov.za\u201d.<\/p>\n<p class=\"p1\">To top it all, Sanetex Hygiene was not registered with the companies\u2019 registrar and its website was <a href=\"https:\/\/amabhungane.org\/wp-content\/uploads\/2020\/05\/200429-sanetexhygiene.com-1-of-2-redacted_LI-1.jpg\" target=\"_blank\" rel=\"noopener noreferrer\">created a day before lockdown<\/a> was implemented. When amaBhungane phoned the business to ask about its company registration, the operator dropped the call.<\/p>\n<p class=\"p1\">Sanetex Hygiene\u2019s website has since been taken down after the businesswoman reported it to its domain registry, but you can see a cached version of it <a href=\"https:\/\/amabhungane.org\/wp-content\/uploads\/2020\/05\/200420-Sanetex-Hygiene-cached-website-1.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>, and a screenshot of the website <a href=\"https:\/\/amabhungane.org\/wp-content\/uploads\/2020\/05\/SanetexHygiene-Information.jpg\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/p>\n<p class=\"p1\">In August last year, the treasury advertised a tender for the maintenance of the database and awarded the contract to local IT firm Gijima for three years, starting from 1 April 2020. The contract is valued at over R42 million.<\/p>\n<p class=\"p1\">According to the tender document, Gijima will not only be expected manage the database and prevent the duplication of suppliers, but in terms of cybersecurity, it will also be required to implement standardised electronic verification of supplier information to reduce fraud.<\/p>\n<p class=\"p1\">In the meantime, the treasury has said that the key to avoid being scammed is for businesses to \u201creduce the number of sectors and commodities they register for, so that they recall these when the scam RFQ reaches them, that they are not registered for this particular item or commodity.<\/p>\n<p class=\"p1\"><em>Like this story? Be an<span style=\"text-decoration: underline;\"> <a href=\"https:\/\/amabhungane.org\/be-an-amab-supporter\/\" target=\"_blank\" rel=\"noopener noreferrer\">amaB Supporter<\/a> <\/span>to help us do more. Sign up for our <span style=\"text-decoration: underline;\"><a href=\"https:\/\/amabhungane.org\/#signup\" target=\"_blank\" rel=\"noopener noreferrer\">newsletter<\/a><\/span> to get more.<\/em><\/p>\n<p class=\"p1\">\u201c[Businesses need to] make sure they do not deviate from the services or commodities they registered for on the CSD, as most [business owners] who fall for scams do.<\/p>\n<p class=\"p1\">\u201c[They need to] be familiar with the institutions they do business with, and their mandates, amongst others. [They need to] protect their company information when sharing in what they refer to [as] \u2018networking sessions\u2019.\u201d<\/p>\n<p><strong>Also read<\/strong><\/p>\n<blockquote><p><a href=\"https:\/\/amabhungane.org\/stories\/wild-west-web-the-return-of-the-scam\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Wild West Web: the return of the scam<\/strong><\/a><\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>Fraudsters claiming to be health department officials are peddling tenders for a non-existent sanitiser machine.<\/p>\n","protected":false},"author":2,"featured_media":21497,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2],"tags":[326,360,361],"class_list":["post-11566","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-stories","tag-covid19","tag-phishing","tag-treasury"],"acf":[],"_links":{"self":[{"href":"https:\/\/further.co.za\/amabwp\/wp-json\/wp\/v2\/posts\/11566","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/further.co.za\/amabwp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/further.co.za\/amabwp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/further.co.za\/amabwp\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/further.co.za\/amabwp\/wp-json\/wp\/v2\/comments?post=11566"}],"version-history":[{"count":1,"href":"https:\/\/further.co.za\/amabwp\/wp-json\/wp\/v2\/posts\/11566\/revisions"}],"predecessor-version":[{"id":30220,"href":"https:\/\/further.co.za\/amabwp\/wp-json\/wp\/v2\/posts\/11566\/revisions\/30220"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/further.co.za\/amabwp\/wp-json\/wp\/v2\/media\/21497"}],"wp:attachment":[{"href":"https:\/\/further.co.za\/amabwp\/wp-json\/wp\/v2\/media?parent=11566"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/further.co.za\/amabwp\/wp-json\/wp\/v2\/categories?post=11566"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/further.co.za\/amabwp\/wp-json\/wp\/v2\/tags?post=11566"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}