All Article Properties:
{
"access_control": false,
"status": "publish",
"objectType": "Article",
"id": "620640",
"signature": "Article:620640",
"url": "https://staging.dailymaverick.co.za/article/2020-05-05-gone-phishing-business-owner-almost-scammed-by-fake-covid-19-tender/",
"shorturl": "https://staging.dailymaverick.co.za/article/620640",
"slug": "gone-phishing-business-owner-almost-scammed-by-fake-covid-19-tender",
"contentType": {
"id": "1",
"name": "Article",
"slug": "article"
},
"views": 0,
"comments": 0,
"preview_limit": null,
"excludedFromGoogleSearchEngine": 0,
"title": "Gone phishing: Business owner almost scammed by fake Covid-19 tender",
"firstPublished": "2020-05-05 14:16:49",
"lastUpdate": "2020-05-06 10:43:48",
"categories": [
{
"id": "9",
"name": "Business Maverick",
"signature": "Category:9",
"slug": "business-maverick",
"typeId": {
"typeId": "1",
"name": "Daily Maverick",
"slug": "",
"includeInIssue": "0",
"shortened_domain": "",
"stylesheetClass": "",
"domain": "staging.dailymaverick.co.za",
"articleUrlPrefix": "",
"access_groups": "[]",
"locale": "",
"preview_limit": null
},
"parentId": null,
"parent": [],
"image": "",
"cover": "",
"logo": "",
"paid": "0",
"objectType": "Category",
"url": "https://staging.dailymaverick.co.za/category/business-maverick/",
"cssCode": "",
"template": "default",
"tagline": "",
"link_param": null,
"description": "",
"metaDescription": "",
"order": "0",
"pageId": null,
"articlesCount": null,
"allowComments": "1",
"accessType": "freecount",
"status": "1",
"children": [],
"cached": false
},
{
"id": "29",
"name": "South Africa",
"signature": "Category:29",
"slug": "south-africa",
"typeId": {
"typeId": "1",
"name": "Daily Maverick",
"slug": "",
"includeInIssue": "0",
"shortened_domain": "",
"stylesheetClass": "",
"domain": "staging.dailymaverick.co.za",
"articleUrlPrefix": "",
"access_groups": "[]",
"locale": "",
"preview_limit": null
},
"parentId": null,
"parent": [],
"image": "",
"cover": "",
"logo": "",
"paid": "0",
"objectType": "Category",
"url": "https://staging.dailymaverick.co.za/category/south-africa/",
"cssCode": "",
"template": "default",
"tagline": "",
"link_param": null,
"description": "Daily Maverick is an independent online news publication and weekly print newspaper in South Africa.\r\n\r\nIt is known for breaking some of the defining stories of South Africa in the past decade, including the Marikana Massacre, in which the South African Police Service killed 34 miners in August 2012.\r\n\r\nIt also investigated the Gupta Leaks, which won the 2019 Global Shining Light Award.\r\n\r\nThat investigation was credited with exposing the Indian-born Gupta family and former President Jacob Zuma for their role in the systemic political corruption referred to as state capture.\r\n\r\nIn 2018, co-founder and editor-in-chief Branislav ‘Branko’ Brkic was awarded the country’s prestigious Nat Nakasa Award, recognised for initiating the investigative collaboration after receiving the hard drive that included the email tranche.\r\n\r\nIn 2021, co-founder and CEO Styli Charalambous also received the award.\r\n\r\nDaily Maverick covers the latest political and news developments in South Africa with breaking news updates, analysis, opinions and more.",
"metaDescription": "",
"order": "0",
"pageId": null,
"articlesCount": null,
"allowComments": "1",
"accessType": "freecount",
"status": "1",
"children": [],
"cached": true
}
],
"content_length": 8018,
"contents": "<a style=\"width: 160px; float: left; margin-right: 10px;\" href=\"https://amabhungane.org\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" class=\"ctx-nodefs\" src=\"https://amab-analytics-img.sourcery.info/stories/200505-gone-phishing-part1-dm\" alt=\"\" height=\"47\" /> </a>\r\n\r\n \r\n\r\n \r\n\r\n<em>See accompanying article: <a href=\"https://www.dailymaverick.co.za/article/2020-05-05-phishing-impersonating-officials-and-what-to-do-about-it/\">Phishing: Impersonating officials and what to do about it , </a>and Part 2 ,<a href=\"https://www.dailymaverick.co.za/article/2020-05-05-wild-west-web-the-return-of-the-scam/\">Wild West Web: the return of the scam.</a></em>\r\n\r\nBogus government tenders appear to be targeted at businesses listed on the national Treasury’s Central Supplier Database (CSD) because of a suspected leak within the publicly inaccessible database.\r\n\r\nThis database is, as it claims, a “single source of key supplier information” for organs of state. Businesses register on the CSD and can then be considered for government contracts.\r\n\r\nOne business owner, who spoke to amaBhungane on condition of anonymity, explained that she only began to receive these bogus tenders when she applied to list her company on the database. She also fell for <a href=\"https://www.dropbox.com/s/a9j4hnp15pv4bj6/200409_Tshepo_Mokoena_Email_Redacted.jpg?dl=0\">one such tender</a>.\r\n\r\nOn 8 April 2020, the Department of Health sent out an email to businesses about a new tender for industrial sanitiser machines – specifically, for the DX610M model.\r\n\r\nProspective suppliers had six days to respond to the bid, which closed on 14 April.\r\n\r\nTypically, when responding to a tender, there should be sufficient generic information accompanying the description of the tender, so that individual businesses can meet almost all the requirements with their own products – in this case, a sanitiser machine.\r\n\r\nThe business owner did a cursory investigation and concluded that the request for quotation (RFQ) seemed legitimate. She then responded to the request.\r\n\r\nOne day after submitting her bid, the business owner received a call from a supply chain official, Tshepo Mokoena. He congratulated her on her successful bid application.\r\n\r\nMokoena then asked her for the batch number on the product to check whether it would meet the requirements of the South African Bureau of Standards. “This seemed weird,” the business owner said – because a batch number is only given after a product is manufactured.\r\n\r\nHe then asked her if she was sourcing the sanitiser machines locally, explaining that she had a 90% chance of losing out on the bid if she did not do so. He promised to provide her with a list of local producers.\r\n\r\nIn the end, he sent her the name and contact numbers of one company: Sanetex Hygiene.\r\n\r\nSanetex Hygiene also appeared to be the only company, after a cursory <a href=\"https://www.dropbox.com/s/zxbmcdl8ylhwk0n/200420_DX610M_Saniteser_Machine_Web_search.jpg?dl=0\">Google search</a>, that could source the specific DX610M sanitiser machine for R7 500 per unit.\r\n\r\n<img loading=\"lazy\" class=\"aligncenter size-medium wp-image-620678\" src=\"https://www.dailymaverick.co.za/wp-content/uploads/200420-DX610M-Saniteser-Machine-Web-search-480x335.jpg\" alt=\"\" width=\"480\" height=\"335\" />\r\n\r\nTo secure her bid, the business owner planned to order the machines from Sanetex Hygiene to supply the Department of Health. However, she was alarmed when she received a response from the Russian equivalent of a Gmail address – an unusual email account for a South African business.\r\n\r\nWhen Mokoena called the business owner the next day, she asked him about the Yandex email address. He hung up on her.\r\n\r\nHad the business owner followed through with the tender, she would have paid for non-existent machines for a non-existent tender from a fake Department of Health official.\r\n\r\nSeveral business owners say they have received RFQs for products ranging from geysers and wheelchairs to the electric cables required for trains used by the Passenger Rail Agency of South Africa (Prasa). Such requests might have been appropriate if the businesses specialised in these products.\r\n\r\nAdvocate Jacqueline Fick, a forensic investigator specialising in electronic fraud, told amaBhungane that because of the large ecosystem of departments connected to the database to verify suppliers’ credentials, there were vulnerabilities in the system. This ecosystem includes the Department of Home Affairs, the South African Revenue Service, company registrations that appear on the database of the Companies and Intellectual Property Commission, and government employees on the public service payroll system known as Persal.\r\n\r\nMaria Pienaar, principal at Pienaar Consulting and formerly the chief information officer at Cell C, said: “When departments in organisations are disjointed, it creates opportunities for fraud. In the case of government departments, each government department is responsible for their own budgets and how they apply these standards in the systems they implement.\r\n\r\n“This leaves gaps for cyber fraud if there are not appropriate governance measures and audits in place to ensure compliance or if budgets are not appropriately applied to alleviate these risks.”\r\n\r\nWhen asked for comment, national Treasury said: “The system was checked and proofed against phishing and hacking before the volatile situation of Covid-19. This is done frequently to ensure that possible breaches are prevented.”\r\n\r\nAccording to the Treasury, there are more than 500,000 listed suppliers on the website and more than 700,000 registered users. More than 800 government departments and state-owned enterprises use the database to identify suppliers and check for compliance.\r\n\r\nWith the marked decrease in face-to-face human interaction as a result of the outbreak of the coronavirus pandemic, the opportunity for fraudsters to take advantage of business owners will rise exponentially.\r\n\r\nSo, what had the business owner missed?\r\n\r\nThis bid had several dodgy elements to it: the urgency of the bid; the short time-frame that businesses had to respond to it; the monopoly of suppliers for the item; and the unusual government email address: healthsupplychain-za.org.\r\n\r\nWhen amaBhungane called the number listed on the email for comment and explained our intentions, the operator dropped the call.\r\n\r\nAccording to the <a href=\"https://secure.csd.gov.za/Home/FraudAwereness\">CSD</a><u> website</u>, fraudsters “send a fictitious RFQ from what would seem to be a governmental email address and use a fake RFQ form with a logo and contact details of the contact person. These requests are usually ‘urgent’ and the whole process is concluded within a short period of time.”\r\n\r\nIn 2016, the <a href=\"https://www.vukuzenzele.gov.za/department-health-high-scam-alert-suppliers-and-service-providers-national-department-health\">department of health</a> complained of a high number of scammers using the following emails:\r\n<ul>\r\n \t<li>@gautenghealth-gov.org.za</li>\r\n \t<li>treasury-gov.org.za</li>\r\n \t<li>[email protected]</li>\r\n \t<li>mphumalang-gov.org.za</li>\r\n \t<li>NDOH@nationalhealth</li>\r\n \t<li>@dh.gov.co.za</li>\r\n \t<li>org.za</li>\r\n \t<li>[email protected]</li>\r\n \t<li>[email protected]</li>\r\n</ul>\r\nThe official national department of health’s emails end with “@health.gov.za”.\r\n\r\nTo top it all, Sanetex Hygiene was not registered with the companies’ registrar and <a href=\"https://www.dropbox.com/s/55njbkxy4ewfmjk/200429_-_sanetexhygiene_com_1_of_2_-_redacted_LI.jpg?dl=0\">its website was created a day before lockdown</a> was implemented. When amaBhungane phoned the business to ask about its company registration, the operator dropped the call.\r\n\r\nSanetex Hygiene’s website has since been taken down after the businesswoman reported it to its domain registry, but you can see a cached version of it <a href=\"https://www.dropbox.com/s/tf8f187fmki6qin/200420%20Sanetex%20Hygiene%20-%20cached%20website%20%281%29.pdf?dl=0\">here</a>, and a screenshot of the website <a href=\"https://www.dropbox.com/s/ghfkq7vhd16gvxo/SanetexHygiene_Information.jpg?dl=0\">here</a>.\r\n\r\nIn August last year, the Treasury advertised a tender for the maintenance of the database and awarded the contract to local IT firm Gijima for three years, starting from 1 April 2020. The contract is valued at over R42 million.\r\n\r\nAccording to the tender document, Gijima will not only be expected to manage the database and prevent the duplication of suppliers, but in terms of cyber security, it will also be required to implement standardised electronic verification of supplier information to reduce fraud.\r\n\r\nIn the meantime, the Treasury has said that the key to avoid being scammed is for businesses to “reduce the number of sectors and commodities they register for, so that they recall these when the scam RFQ reaches them, that they are not registered for this particular item or commodity.\r\n\r\n“[Businesses need to] make sure they do not deviate from the services or commodities they registered for on the CSD, as most [business owners] who fall for scams do.\r\n\r\n“[They need to] be familiar with the institutions they do business with, and their mandates, amongst others. [They need to] protect their company information when sharing in what they refer to [as] ‘networking sessions’.” <strong>DM</strong>\r\n\r\n<i><span lang=\"EN-US\">The <u><a href=\"http://www.amabhungane.org/\" target=\"_blank\" rel=\"noopener noreferrer\" data-saferedirecturl=\"https://www.google.com/url?q=http://www.amabhungane.org&source=gmail&ust=1588839457860000&usg=AFQjCNHzqvDDuJ3aNGMCoO9wcxZIooleXw\">amaBhungane Centre for Investigative Journalism</a></u>, an independent non-profit, produced this story. Like it? Be an </span><span lang=\"EN-US\"><a href=\"https://amabhungane.org/be-an-amab-supporter/\" target=\"_blank\" rel=\"noopener noreferrer\" data-saferedirecturl=\"https://www.google.com/url?q=https://amabhungane.org/be-an-amab-supporter/&source=gmail&ust=1588839457860000&usg=AFQjCNEwjGNVecALBl2T6dPugEm0NM5RCw\">amaB Supporter</a> to help us do more. Sign up for our <a href=\"https://amabhungane.org/#signup\" target=\"_blank\" rel=\"noopener noreferrer\" data-saferedirecturl=\"https://www.google.com/url?q=https://amabhungane.org/%23signup&source=gmail&ust=1588839457860000&usg=AFQjCNGeIMv22gZngjCB8IupWvaUiTPkSA\">newsletter</a> to get more.</span> </i>",
"teaser": "Gone phishing: Business owner almost scammed by fake Covid-19 tender",
"externalUrl": "",
"sponsor": null,
"authors": [
{
"id": "47768",
"name": "Gemma Ritchie for amaBhungane",
"image": "",
"url": "https://staging.dailymaverick.co.za/author/gemma-ritchie-for-amabhungane/",
"editorialName": "gemma-ritchie-for-amabhungane",
"department": "",
"name_latin": ""
}
],
"description": "",
"keywords": [
{
"type": "Keyword",
"data": {
"keywordId": "54794",
"name": "Phishing",
"url": "https://staging.dailymaverick.co.za/keyword/phishing/",
"slug": "phishing",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Phishing",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "131252",
"name": "cyber-crime",
"url": "https://staging.dailymaverick.co.za/keyword/cybercrime/",
"slug": "cybercrime",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "cyber-crime",
"translations": null
}
}
],
"short_summary": null,
"source": null,
"related": [],
"options": [],
"attachments": [
{
"id": "23165",
"name": "",
"description": "",
"focal": "50% 50%",
"width": 0,
"height": 0,
"url": "https://dmcdn.whitebeard.net/dailymaverick/wp-content/uploads/AMAB-part2-phishing-main-option-1.jpg",
"transforms": [
{
"x": "200",
"y": "100",
"url": "https://dmcdn.whitebeard.net/i/vgEFG_2HGnjvZ53wyL6dNRbAbO0=/200x100/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/AMAB-part2-phishing-main-option-1.jpg"
},
{
"x": "450",
"y": "0",
"url": "https://dmcdn.whitebeard.net/i/EqAJrHA7kG4KV-dK7hhS9910u8o=/450x0/smart/file/dailymaverick/wp-content/uploads/AMAB-part2-phishing-main-option-1.jpg"
},
{
"x": "800",
"y": "0",
"url": "https://dmcdn.whitebeard.net/i/9NKzXLxnmfI6e7aa4cBSgBZVPTQ=/800x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/AMAB-part2-phishing-main-option-1.jpg"
},
{
"x": "1200",
"y": "0",
"url": "https://dmcdn.whitebeard.net/i/7Eql8s8aO4mfvK7KaqDj6lktJ0s=/1200x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/AMAB-part2-phishing-main-option-1.jpg"
},
{
"x": "1600",
"y": "0",
"url": "https://dmcdn.whitebeard.net/i/zIUuha-8a7tOldEzBacs-qwlp7w=/1600x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/AMAB-part2-phishing-main-option-1.jpg"
}
],
"url_thumbnail": "https://dmcdn.whitebeard.net/i/vgEFG_2HGnjvZ53wyL6dNRbAbO0=/200x100/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/AMAB-part2-phishing-main-option-1.jpg",
"url_medium": "https://dmcdn.whitebeard.net/i/EqAJrHA7kG4KV-dK7hhS9910u8o=/450x0/smart/file/dailymaverick/wp-content/uploads/AMAB-part2-phishing-main-option-1.jpg",
"url_large": "https://dmcdn.whitebeard.net/i/9NKzXLxnmfI6e7aa4cBSgBZVPTQ=/800x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/AMAB-part2-phishing-main-option-1.jpg",
"url_xl": "https://dmcdn.whitebeard.net/i/7Eql8s8aO4mfvK7KaqDj6lktJ0s=/1200x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/AMAB-part2-phishing-main-option-1.jpg",
"url_xxl": "https://dmcdn.whitebeard.net/i/zIUuha-8a7tOldEzBacs-qwlp7w=/1600x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/AMAB-part2-phishing-main-option-1.jpg",
"type": "image"
}
],
"summary": "Fraudsters claiming to be health department officials are peddling tenders for a non-existent sanitiser machine.",
"template_type": null,
"dm_custom_section_label": null,
"elements": [],
"seo": {
"search_title": "Gone phishing: Business owner almost scammed by fake Covid-19 tender",
"search_description": "<a style=\"width: 160px; float: left; margin-right: 10px;\" href=\"https://amabhungane.org\" target=\"_blank\" rel=\"noopener noreferrer\"><img class=\"ctx-nodefs\" src=\"https://amab-analytics-img.sourcery.info",
"social_title": "Gone phishing: Business owner almost scammed by fake Covid-19 tender",
"social_description": "<a style=\"width: 160px; float: left; margin-right: 10px;\" href=\"https://amabhungane.org\" target=\"_blank\" rel=\"noopener noreferrer\"><img class=\"ctx-nodefs\" src=\"https://amab-analytics-img.sourcery.info",
"social_image": ""
},
"cached": true,
"access_allowed": true
}