Blog
Mandate fraud / Mandaat fraude
Mandate fraud / Mandaat fraude

Mandate fraud costs Pathé more than US$ 22 million

The European cinema group, Pathe, recently lost €19.2 million (around US$22 million) in an internet scam (named Mandate fraud). The fraud kicked off in March and targeted their Dutch office. Several emails, apparently sent from the personal account of Pathe CEO Marc Lacan, asked the Dutch office to wire the money in four tranches to a bank account based in Dubai. But these emails came from scammers.

Mandate Fraud

The technique used by the scammers is called “Mandate fraud“. This is when someone convinces an organization to make payments. The scammers claim to be a company that receives regular payments from them, a business supplier, or a senior manager. In the case of Pathe senior managers in the Netherlands received a request to transfer the money to finance a takeover. The request appeared to come from their CEO in France. But it was actually sent by scammers. They were somehow able to make use of the CEO’s e-mail account, or an account that appeared to be his.

It is actually becoming easier for scammers to set up such frauds. This is because many companies now rely on cloud-based mail systems such as Office 365 or Gmail. So if attackers know a few surnames and e-mail accounts within a company, they can use brute-force attacks to guess passwords. Once they have access to an account, they can then use it to attempt frauds such as Mandate Fraud. If you want to avoid such attacks, you need administrators that set up alerts, in-depth logs, and block all email-forwarding attempts. In addition, you need to make your personnel aware of techniques to keep their passwords secure. For example, you can insist on two step-authentication.

Inside Job

Skilled scammers with access to internal mails are known to ‘lurk’ on corporate networks. Firstly they work out the management structure. They follow the business processes. They even check when senior personnel are out of the office, travelling, or are otherwise not easy to reach. That’s when they send their victim an e-mail – that maybe looks like it comes from their manager. The mail asks them to make an urgent payment…

One recent attack hacked into cloud-based email accounts of two executives inside an organization. Using computers located in Africa, the fraudsters first studied their behavior. When both executives were out of the office, the attackers then sent mails back and forth between the executives’ accounts. These mails appeared to authorize a wire transfer. They forwarded the mails to a junior. And this junior saw them as proof that the money should be moved. A mistake that cost several people their jobs. As well as several million dollars.

Signature Registration

Within many large organizations, it’s quite common for personnel to receive instructions from colleagues located in other countries. Colleagues they don’t know directly.  Or maybe they receive contracts signed by people they’ve never met.

Within ABN AMRO, staff confirm important decisions by means of a Power of Attorney assigned to individual employees. The bank uses POAs to manage transactions between branches. And also between ABN AMRO and third parties. It is therefore essential that bank staff can check the signatures, as well as the authority of these employees. Irrespective of their location. We were therefore asked to design a system to improve this process. Our developers came up with a customized solution: Signature Registration System (SRS).

Integrated Solution

To ensure its success, we developed SRS to work with existing systems already used within the ABN AMRO infrastructure.  We designed SRS to use ABN AMRO authentication for access. In addition, it is hosted within their server infrastructure. More importantly, SRS links personnel information to ABN AMRO’s in-house HR system. As a result, employees can only add data  that has already been verified within the bank’s HR/SAP system. SRS provides a web-service that bank employees use to authenticate signatures, and to confirm the authority of the person signing. Whilst we designed this web-service to provide easy access within their network, our developers also ensured the administration of SRS includes a number of security measures to keep their data secure – and accurate.

SRS is available as a web service within the ABN AMRO Intranet. Bank employees use it every day. They can quickly and securely check if instructions, contracts and documents have been correctly authorized. Perhaps if Pathe employees had access to such a system, their money would not have found its way to scammers in Dubai!

Easy integration

SRS is a flexible system, one that we can easily integrate with almost any infrastructure. So if you would like to  introduce a similar system within your network, or if your company is faced with a challenge in terms of automation, cost reduction or smarter and more efficient working – get in touch.

Drupal 9 replaces Drupal 8. Long live Drupal 7!

Drupal 9 replaces Drupal 8. Long live Drupal 7!

Drupal 9 arrived last year, and Drupal 8 is end-of-life in November 2021. Nothing strange about this. But did you know that Drupal 7’s life has been extended to November 2022? Due to the high number of active users, it will remain in use longer than Drupal 8! Nevertheless, if you’re still using Drupal 7, you’re drinking in the last chance saloon, and it’s time to plan your transition to Drupal 9.

BSL delivers a new Pulse importer using the Forrester API

BSL delivers a new Pulse importer using the Forrester API

We developed our “Pulse” Business Intelligence Software for PwC. It’s a global service, maintained and supported by BSL. Pulse imports thousands of documents daily from commercial content providers and website feeds, delivering personal briefings to PwC subscribers throughout the PwC organisation. At the request of PwC, we recently created a new importer for Forrester using their API.

Outsourcing, retainers and long-term development partnerships

Outsourcing, retainers and long-term development partnerships

It’s not always straightforward for even large companies to create cutting edge development teams, as their core business may not be related to IT. Moreover, even when IT is a significant part of their business, there is frequently a wide gap between delivering core services and innovating with new technologies. BSL offers development services that can help fill the gap.

Machine Learning technology for Library services

Machine Learning technology for Library services

We’ve worked for many years with NBD Biblion, a unique organisation that selects and distributes books to public libraries in the Netherlands. They recently introduced Machine Learning (ML) technology to automate their client recommendations. After this success, NBD Biblion asked BSL to integrate a new Machine Learning service with MIPS, developed by BSL.

Drinks and a movie at BSL

Drinks and a movie at BSL

Enjoying a few drinks and watching a film together was a regular feature of life at BSL. I write ‘was’ because COVID-19 has kept most of us working from home. As a result, sharing a drink and watching a film together has not been an option. So instead, we’ve organised Digi-parties, Easter surprises and other events. Most recently, we arranged for everyone to enjoy a movie at home.

Two BSL anniversaries in May, time for a party

Two BSL anniversaries in May, time for a party

Two BSL anniversaries this week. Senior developer Peter Verbaan has been a key resource within BSL for 15 years, and front-end developer Roderick Gadellaa for 5 years. Reason enough for a party, you might say, and that’s something we love at the “Bright Side of Life.” For now, Corona makes this impossible, so it’s an online drink and a virtual hug.

Designing a simple phone app for 1888 information numbers

Designing a simple phone app for 1888 information numbers

1850 BV has asked us to design and develop a new simple phone app for Android and iOS, designed to help people who have difficulty using modern smartphones. After all, not everyone is excited about all the hundreds of features provided by a typical smartphone. It’s hard for people who lack the technological skills to figure all this stuff out. And or course, many simply find tiny screens challenging.

Early to market? Try developing a Minimum Viable Product

Early to market? Try developing a Minimum Viable Product

Entrepreneurs frequently contact us with ideas for their ground-breaking app, web-service, or web application. Their market research completed, business plan ready, financial backing sorted. They want to start, and get their product to the market as quickly as possible. This is when we introduce the concept of an MVP or Minimum Viable Product.

The Entoen Nu app makes history lessons easy

The Entoen Nu app makes history lessons easy

Do you sometimes have trouble with Dutch history? The EnToen Nu app is intended for those interested in Dutch culture and history, particularly children from grade 5 up to and including secondary school. It can be used at school, and at home. We’ve recently updated the app, adding support for the latest version of the Canon of the Netherlands.

SRS: New Job Model and Access Governance Foundation

SRS: New Job Model and Access Governance Foundation

Since developing the original Signature Registration System (SRS) on behalf of a large international bank we’ve made many changes. Migrating SRS to an Azure SQL cloud service is our current focus, but earlier this year we worked on two other infrastructure changes: Introducing NJM (New Job Model) and AGF (Access Governance Foundation) support in SRS.

Oracle migration to Azure SQL database – Part 2

Oracle migration to Azure SQL database – Part 2

In recent months, two clients have asked us to migrate legacy Oracle systems to Azure. In the previous blog, we explained how our tiered web applications make it easy to maintain our software and to migrate from one database to another. We asked Eric Wijnands to tell us about one of these migrations, moving a Banking solution from Oracle to Azure SQL.

Oracle migration to Azure SQL database – Part 1

Oracle migration to Azure SQL database – Part 1

Is Azure the flavour of the month? We’ve been approached by two clients in recent months to help them transition legacy Oracle systems to an Azure Cloud database. We’ve been building tiered database solutions for many years, with Front-end web applications calling web-services that use Oracle databases for storage. Just how easy is it to migrate these applications to Azure?

BSL creates a new Corporate site for WCC Group

BSL creates a new Corporate site for WCC Group

The WCC Group is a leading provider of advanced solutions for Public & Private Employment Services and ID/Security government agencies. Two years ago we designed and developed a dedicated Careers site to help find the specialized personnel needed to support their rapid expansion. This year they asked us to create a new, modern, responsive Corporate site.

Bright Side of Life Director – Martyn Simpson – Part 2

Bright Side of Life Director – Martyn Simpson – Part 2

In his previous blog, Martyn introduced us to his time working for Computervision/CIS, creating custom solutions for their clients. Experiences that he uses daily within BSL. After leaving CV, he continued to travel, working firstly with a company you’ve maybe never heard of (although you’ve probably used their products). And then with a company that you all know: Apple Computer.

Bright Side of Life Director – Martyn Simpson

Bright Side of Life Director – Martyn Simpson

So rounding off our current series of Bright Stories, it’s the turn of Martyn, our director. Martyn created the Bright Side of Life more than 25 years ago, and he’s been developing software since 1977. It’s not easy to condense 43 years of software development into a single blog, so in this first part, we find out just why he became a software developer, with some “Lessons Learned” on the way.

Front-end Developer – Roderick Gadellaa

Front-end Developer – Roderick Gadellaa

Continuing our “Bright Stories”, this week we turn our attention to Front-end Developer, Roderick Gadellaa. Someone with a very sweet tooth, and who enjoys solving design and UX problems. You’ll frequently find him on Twitter, tweeting about design changes and concepts. Here at BSL, Roderick’s enthusiastic whistling and singing are part of our soundscape!

PA / Customer Relations Manager – Caroline Bos

PA / Customer Relations Manager – Caroline Bos

As part of our “Bright Stories” series, it’s now the turn of Caroline, PA / Customer Relations Manager at BSL. We tell you why her varied background, outgoing personality, and talent for organization make her ideal for the role. Connecting and communication with people is in her DNA! Having worked nearly 8 years at BSL, she plays a pivotal role in our organization.

Software Developer – Jurjen Schröder

Software Developer – Jurjen Schröder

Our “Bright Stories” campaign is your chance to get to know some of the talented individuals that make up the Bright Side of Software. This week, the spotlight is on one of our software developers: Jurjen Schröder. An opportunity to find out more about Jurjen, and at the same time discover why he keeps some very unusual housemates!

Agile working is a success even during Corona

Agile working is a success even during Corona

Agile working is ideal for teams working remotely. Although we’ve used Agile for several years, there’s always room for improvement. Flexibility is part of this approach. Each client has their preferences, and so we refine our working methods to suit each customer. Fortunately, this type of refinement is more or less built-in to Agile: The Sprint Retrospective…

NBD’s LiteRom and Uittrekselbank online websites refreshed

NBD’s LiteRom and Uittrekselbank online websites refreshed

Agile development is part of our culture. During two recent Sprints, BSL delivered new versions of NBD’s Literom and Uittrekselbank online web services. LiteRom contains thousands of book reviews, as well as many articles about authors. Uittrekselbank subscribers can access thousands of extracts about books, as well as detailed author profiles. Find out more in our blog…

Working from home, but staying connected

Working from home, but staying connected

We’re working from home as much as possible due to the Coronavirus (COVID-19). We’re doing all we can to keep Business as Usual. Technical innovation is part of our DNA, and so we’re perhaps finding this easier than others. Nevertheless, we are having to change the way we work in response to these challenges. Our blog tells you about some of the steps we are taking.

Eric Wijnands, Designer and Developer, with a love of Jazz

Eric Wijnands, Designer and Developer, with a love of Jazz

BSL has always looked for designer and developer candidates who have their own stories to tell. Rounded individuals who offer more than just IT skills. Our work frequently begins with understanding the work carried out by our clients. So we supply inventive teams that deliver usable, productive solutions – not just code. Offering designers and developers with wide interests outside of IT.

Long-term relationships brings rewards to clients

Long-term relationships brings rewards to clients

2019 is a year where our long-term relationships with clients have kept us extremely busy. BSL provides highly skilled teams that complement our clients’ needs. As a result, we respond quickly to new demands. Designing, developing and delivering unique applications. This year we’ve worked on many new developments for existing clients.

Moscow performance for Marc Stoffels

Moscow performance for Marc Stoffels

Before Marc Stoffels made the move into IT, he was an actor. One of the theatre companies where he played, Het Houten Huis was recently invited to bring their performance to Moscow. A trip to Moscow is an experience in itself, and BSL didn’t want to deprive him of the opportunity. But with one condition – we asked him to write a blog about his trip!

Conversational Design helps increase conversion rates

Conversational Design helps increase conversion rates

Many websites ask visitors to share their contact details. And for many years the best anyone could come up with is a contact form. There are ways to make such forms more inviting, but a contact form shares many characteristics with a nightclub bouncer – it keeps people out. So we’ve started using Conversational Design UI’s. A technique that puts website visitors at their ease…

Don’t know your MVP from your SUV, read on…

Don’t know your MVP from your SUV, read on…

At the Bright Side of Life it’s in our blood to help clients to think about their needs, and to work with them to define the features needed in a first release. Going for an all singing and dancing first release is rarely the right approach. Focus on what you need – an MVP demonstrating great value to your users. It will save you money, gain insights into your users’ needs, and help to create a better product.

Summer Event – BSL and the Soldier of Orange

Summer Event – BSL and the Soldier of Orange

Our summer event this year was an opportunity for Martyn (Director, BSL) to finally experience a little Dutch culture. He’s not yet ready for the full Marco Borsato/Andre Hazes experience. So on June 6, we tore ourselves away from our work, and stood in the sunshine outside the office, waiting for a coach. A coach that was going to take us all to Katwijk, and the Soldier of Orange!

Keylane Careers – a Recruitment Challenge

Keylane Careers – a Recruitment Challenge

Recruiting talent for IT service providers is not easy. Good developers and designers are scarce. BSL uses our own website and several social platforms to find new talent. But when you’re a multinational, looking to recruit talent across Europe, you need to “Think Different”. And that’s just what the Keylane Careers team has been doing.

BSL team at the NN Rotterdam Marathon 2019

BSL team at the NN Rotterdam Marathon 2019

In February, BSL received an invitation to take part in a charity Business Run during the NN Rotterdam Marathon on 7 April. Participants could sign up for a 10K (1/4 marathon), with the goal of raising money for a good cause – the Linda Foundation. This charity helps make life a little brighter for less fortunate children in the Netherlands.

Oracle – MySQL Bootcamp in Dusseldorf (the boys on tour)

Oracle – MySQL Bootcamp in Dusseldorf (the boys on tour)

BSL has a lot of experience with Oracle databases and has been an Oracle partner for years. We were recently invited by Oracle to a MySQL Bootcamp held in Dusseldorf. The purpose of the Bootcamp was to learn more about the MySQL Enterprise edition, the commercial edition of MySQL. Two of our developers want to share their experience…

4

Previous

5

Next

Any questions?

Do you want to get an estimate for developing your custom software. Or advice on creating new websites, or integrating web applications with existing systems. We're happy to answer any questions you may have, no strings attached. Give us a call, or get in touch at sales@brightside.nl!

    Get in touch

      Contact BSL
      Contact BSL