CSIDB logo
Incident

Northwest University

Incident posture

Attack window
May 2018
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-27 01:19

Linked entities

Victim
Northwest University
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Northwest University suffered a financial loss after attackers compromised the email account of its chief financial officer, John Jordan. The intruders monitored the correspondence and, when a legitimate payment to a vendor was pending, diverted the funds to their own accounts. As a result, the institution lost nearly sixty thousand dollars. The Kirkland Police Department opened an investigation to identify the perpetrators and trace the illicit transfers.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The email account of Northwest University’s chief financial officer, John Jordan, was compromised in a cyber intrusion. According to investigators, the attackers secretly monitored the contents of Jordan’s email correspondence. When a legitimate payment was scheduled to be sent to a university vendor, the perpetrators intercepted the transaction. The hackers altered the payment instructions to redirect the funds to an account under their control. As a result of the fraudulent redirection, Northwest University suffered a financial loss of nearly sixty thousand dollars. The incident was first reported by local media outlet KIRO 7 on May 4, 2018.

The Kirkland Police Department opened an investigation into the email hijacking and the associated fraud. Detectives indicated that either a single suspect or a coordinated group of suspects was responsible for the compromise. The investigation focused on how the attackers gained access to the CFO’s email account and maintained covert surveillance. No further details about the attackers’ identity, methods, or any remedial actions taken by the university were disclosed in the source. The article noted that the investigation remained ongoing at the time of publication. The loss amount and the nature of the email compromise were the primary facts conveyed in the report.

Sources

Sources available to members: 1 source.

CSIDB