CSIDB logo
Incident

Essex Region Conservation Authority

Incident posture

Attack window
Jul 2020
Location
Canada
Status
Historical
CIA posture
Available to members
Updated
2025-10-29 00:00

Linked entities

Victim
Essex Region Conservation Authority
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Essex Region Conservation Authority was defrauded of $300,000 through a phishing attack where an impersonator posed as an internal staff member, tricking an employee into sending two unauthorized e-transfers to falsified accounts. Following discovery, the organization reported the incident to its bank, law enforcement, and insurers while confirming no donor funds or additional IT systems were compromised. Internal controls were strengthened to prevent recurrence, and a criminal investigation remains ongoing alongside a review of existing processes.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Essex Region Conservation Authority (ERCA) fell victim to a phishing scam in July 2020, resulting in a total loss of $300,000 CAD. The incident began when an unidentified fraudster sent a "complex phishing email" impersonating an internal ERCA staff member to an employee. This deception led to two unauthorized electronic transfers to falsified bank accounts. The first transaction occurred on July 14, 2020, when $61,876 was transferred. A second fraudulent request followed on July 27, 2020, resulting in a substantially larger transfer of approximately $230,865. ERCA management discovered the fraud on September 3, 2020, nearly seven weeks after the initial transaction.

Upon detection, ERCA immediately reported the unauthorized payments to its financial institution and engaged the Ontario Provincial Police to initiate a criminal investigation. The organization notified its insurer and implemented additional internal financial controls to prevent recurrence. ERCA confirmed its IT systems weren't further compromised beyond the initial phishing attack and committed to reviewing existing processes for potential improvements. The conservation authority clarified that no funds from the Essex Region Conservation Foundation or donor contributions were impacted. Board Chair Kieran McKenzie publicly assured stakeholders that authorities were conducting a full investigation. As of September 4, 2020, the investigation remained ongoing with no public disclosure of suspect identification or fund recovery. The incident highlighted vulnerabilities to social engineering attacks within organizational financial workflows.

Sources

Sources available to members: 1 source.

CSIDB