ATTENTION : SCAM ALERT, News (Owen Sound Minor Hockey Group)

News Article
News Article Image
May 22, 2019 | OSMHG | 1555 views
PLEASE disregard any E-Mails that come from OSMHG Executive, Staff, or Coaches etc. asking you to complete a "task" or do them a favour ASAP because they are in a meeting and can't do it themselves. 
Please read more to see an example and learn what "Phishing" and "Spear Phishing" is...

I got an interesting email this morning. It was “from” Grant Oldrieve, the "Executive President" of Owen Sound Minor Hockey Group – but the return address was a bit odd: “[email protected]” As this unfolded, it became obvious that this was a classic “spear phishing” attack. I’ll run you through the email exchange for entertainment purposes, and then talk about the lessons to be learned here. The original message was short and sweet:

Please do you have a moment? Am tied up in a meeting and there is something I need you to take care of.


Executive President

Lots of things about messages like this should raise your eyebrow. First, always look at the return E-Mail address. Second the language is often not what you would expect. Third, it was signed Executive President, and lastly, would this person really ask you to take care of such a task? And without chatting in person or a phone call?

Sometimes, I string the person along and it might look something like this ...

Sure – what’s up?

I’m currently in a meeting right now and I want to gift out some Gift Cards to some clients today ASAP. I want you to make arrangements to get the gift cards. Is that okay with you?

P.S.: I’m currently in a meeting right now, just reply back. Is that okay with you?


Aha. Now money is involved. And notice the use of “I’m currently in a meeting right now” as an obvious attempt to discourage me from calling to check on the legitimacy of the messages. Let’s see how far we can run this:

Sure. How can I help?

And the reply again:

I need 10 PHYSICAL Apple iTunes gift cards of $100 face value. That’s $100 x 10 = $1,000.

Note: $100 x 10 qty of Apple iTunes Gift Cards are needed. Once you get the physical cards, you should gently scratch-off silver lining at the back for the pin codes, lay them all out in batches, then snap a photo and email the clear picture to me via email before leaving the store right away. Make sure you email them to me before leaving the store. Is that okay with you?

P.S.: I’m currently in a meeting right now, just reply back.



Yep, nothing suspicious at all about that, is there? Let’s push it a little:

I’m on my way into the office now. I can either drop them by your office, or just leave them at the front desk. Will that work?

Well, apparently not:

No, I want them via email.I want you to gently scratch-off silver lining at the back for the pin codes, lay them all out in batches, then snap a photo and email the clear picture to me via email. Is that okay with you?


They won’t accept the company credit card – they want cash only for the gift cards. Looks like you’re out of your meeting – can you have someone cut a cheque for me? I’ll be happy to run it down to the store and pick up the gift cards.

Apparently that’s not going to work…

You may go to Apple store and try. Is that okay with you?

I did. They insist on cash only. How would you like to proceed?

Okay, you can pay with your cash. You’ll obviously be reimbursed,is that okay with you?



Well, geez, that’s mighty kind of you to let me front this with $1,000 of my own cash, but…

I’m sorry, but I don’t have an extra $1,000 at the moment to front this. I’ll be at the office in 5 minutes, we can talk then.

But these folks just don’t want to let it go:

Can you buy $300 card?

They obviously think I’m pretty stupid, and the feeling is mutual. Bear in mind that I’ve already told them that I would be in the office in 5 minutes, and that was about a half hour ago. But let’s try to milk it a bit longer:

You want one $300 card or three $100 cards? And which email address do you want me to send to?

I won’t bore you with the rest of the exchange. At this point, I just want to see how long I can successfully jerk them around, and whether maybe, just maybe, I can get a mailing address of some kind to send the “gift cards” to.

So…what should we learn from this?

  • This was a targeted attack (which is what distinguishes “spear phishing” from ordinary “phishing” emails that are blasted out to thousands of recipients). Someone did enough research on OSMHG to identify which individuals within our organization was likely to have the authority to make a request like this, and used that individual’s name to specifically target others.

  • You might think that we would be too small for someone to go to that much trouble to target us. You’d be wrong.

  • The amount they requested ($1,000) was not an unreasonable amount for a company our size. Trying to scam us for $50K would have been an obvious overreach. Again, you might think that it’s not worth the trouble to only score $1,000 – let alone the $300 that I negotiated down to. But if they can actually score a half dozen times a month, it adds up to a reasonable payday.

  • These guys didn’t care whose money they took. Company credit card? Fine – even if it ended up costing me my volunteer job, lol.  My own money? That’s fine too. Can’t afford $1,000? How about $300? They’ll take whatever I’m dumb enough to give them.

  • You are not exempt from attacks like this! Your organization is not too big or too small to be targeted. Whether you know it or not, you probably have already been targeted. If you haven’t been, you will be. I know the Bluewater District School Board has been targeted several times over the past couple of years.

It is axiomatic that the “weakest link in the security chain” is the end user.  IT professionals may live and breathe this security stuff, but end users don’t. They’re just busy trying to get their jobs done. And one end user who clicks on the wrong link, or responds incorrectly to a phishing attempt like this one, can circumvent all of the expensive technological security solutions that may be in place. It’s important to always verify with personal contact when money is involved. And NEVER give out confidential or other sensitive information via E-Mail.

Harold Sutherland Construction Ltd
Established in 1960, Harold Sutherland Construction Ltd. has continuously grown and evolved into a diversified company. Over the past 55 years, Harold Sutherland Construction Ltd. has gained a solid reputation in construction and aggregate excellence. We are committed to supporting our community, protecting the environment and are dedicated to providing a safe workplace for our employees.
Krueger Custom Steel and Machining
Manufacturing Facility Since our founding in 1994, Krueger Custom Steel and Machining has experienced tremendous growth. Starting out with a staff of four, fourteen associates can now take credit for the company’s success A strong commitment to custom service is the driving force behind our company’s success. . We strive to provide the same high level of quality service and timely delivery to all our customers. We have forged alliances with London Ont based Canada Steel and Toronto Based Valmar Machine and Manufacturing We now offer the full inventory of Canada Steel products – now made available with free delivery. In partnership with Valmar Machine we now can offer experienced CNC machining capabilities and mechanical engineering and design services We provide a wide range of products and services and have a strong loyal customer base. These Services Include • Steel and Specialty Metals Material • On Site Millwright Services • Equipment Relocates and Installation • On Site Equipment Repairs • Machining CNC and Conventional • CWB Certified Welding • Aluminium and Stainless Steel welding • Printing Press Services and Repair • Printing Press Rebuilds • Machinery Manufacturing • Preventative Maintenance • Emergency Repairs
Joe's Garage
If you are looking for an automotive service centre in Owen Sound, head to Joe's Garage. Joe's Garage is conveniently located in Owen Sound and can help you find exactly what your looking for when it comes to automotive service & repair.
Owen Sound Fire & Emergency Services
Working Together to Make A Safer Community The City of Owen Sound can indeed be very proud of their dedicated group of professional fire fighters, who have a history of more than 150 years of service. The department has 26 full time Firefighters, 1 full time Training Officer, and 2 full time Fire Prevention Professionals. Owen Sound is a 911 Community.
Nicol Insurance
Since 1950 we have been helping clients to identify their insurance needs and provide them with the best value in personal and commercial insurance. At Nicol Insurance we believe in protecting what matters to you most — your family, your home, your business; your lifestyle. We are a professional organization dedicated to providing insurance solutions at competitive pricing. Our firm is registered as a licensed insurance broker with the Registered Insurance Brokers of Ontario (RIBO). We act in the capacity of intermediary between the consumer (the buyer of insurance) and the insurer (insurance company accepting the risk), and as a result, earn commissions and/or fees payable by the insurer for providing this service.
Kunkel Bus Lines
Kunkel Bus Lines Ltd. has been serving Southwestern Ontario and beyond since 1953. Our goal has always been to provide personalized transportation service, combined with a high level of customer satisfaction. We pride ourselves on the personalization and knowledgeable experience we have established over our many years of operation. Our equipment is maintained in immaculate condition both inside and out. We offer 24-hour customer service, and our Licensed Mechanics are on duty 24 hours a day, 7 days a week. All of our Team Members are trained in what it takes to create an incredible experience for our customers. The Kunkel Team goes above and beyond expectations when it comes to the needs, safety, and comfort of all passengers. We pride ourselves not only on the stellar customer service that Team Members demonstrate, but the fact that we have an impressive fleet of luxurious highway coaches of varying capacity. We can comfortably transport your group to anywhere in Canada or the USA and allow you to relax and enjoy a stress-free trip.