Case Library / Phishing / MacEwan University BEC Fraud
Phishing Confirmed

MacEwan University BEC Fraud

A spoofed-email scheme impersonating MacEwan University's trusted general contractor, Clark Builders, tricked staff into redirecting $11.8 million CAD in construction payments to fraudulent bank accounts in Montreal and Hong Kong, one of the largest publicly documented BEC losses at a North American university.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In August 2017, fraudsters impersonating MacEwan University's general contractor, Clark Builders, sent spoofed emails requesting a change to the banking details used for payments on the Allard Hall construction project. MacEwan accounts-payable staff acted on the request without an independent verification call and processed three wire transfers to the fraudulent account: $1.9 million on Aug. 10, $22,000 on Aug. 17, and $9.9 million on Aug. 19, a total of $11.8 million CAD. The fraud came to light on Aug. 23, 2017, when Clark Builders itself called MacEwan to ask why several expected payments, including the $9.9M project holdback, had not arrived. MacEwan publicly disclosed the incident on Aug. 31, 2017. The university said the same attackers had set up fake look-alike domains impersonating about 14 Edmonton-area construction firms, indicating a wider vendor-impersonation campaign. Roughly $11.4M of the stolen funds was traced to bank accounts in Montreal and Hong Kong; MacEwan pursued civil freezing and recovery action, ultimately recovering $10.92M by April 2018 and permanently losing $880,000 of principal plus about $250,000 in legal/banking fees.

How the Attack Worked

Attackers spoofed the email identity of Clark Builders, the Edmonton-based general contractor MacEwan had worked with since 2003 on multiple projects including the new Allard Hall arts building. Posing as the contractor, they sent MacEwan accounts-payable staff a request to change the banking/wire details on file for upcoming project payments. Believing the request was legitimate given the long-standing vendor relationship, staff updated the payment information and processed three transfers over nine days without placing a verification phone call to Clark Builders using an independently known number. MacEwan later disclosed the same actors had registered fake look-alike domains impersonating roughly 14 Edmonton-area construction firms, suggesting a broader vendor-impersonation campaign rather than a one-off attempt against MacEwan alone.

The Lure & the Tell

The lure was a routine-looking vendor email requesting an update to banking/wire details for an established, trusted contractor (Clark Builders) mid-way through a real, active, high-dollar construction project (Allard Hall), exploiting the fact that a change-of-bank-details request is unremarkable in a long commercial relationship. The tell that ultimately surfaced the fraud was not a technical detection but a business one: Clark Builders' own accounts team noticed they hadn't received three expected payments, including a $9.9M final holdback, and called MacEwan on Aug. 23, 2017 to ask why: "we found it quite odd that we weren't receiving payment for the invoices," said Clark Builders president Paul Verhesen. That single reconciliation call, from the real vendor rather than the university, unraveled the scheme.

Outcome

Of the $11.8M CAD stolen, roughly $11.4M was traced to bank accounts in Montreal and Hong Kong; MacEwan pursued civil freezing/recovery action in those jurisdictions (and reportedly London), securing seizure of $6.3M from the Montreal account and a freeze on the Hong Kong funds. By April 4, 2018, the university reported $10.92 million recovered, an $880,000 permanent principal loss, and roughly $250,000 in additional legal/banking fees. Edmonton Police Service and other law-enforcement/bank-security teams investigated; no criminal charges had been publicly announced as of April 2018. Separately, in September 2021 the U.S. Secret Service and DOJ announced the sentencing of Ghaleb Alaumary, a dual Canadian-U.S. national money launderer, to 140 months in federal prison (Southern District of Georgia) for laundering proceeds from multiple BEC and bank-cyberheist schemes; the DOJ release described laundering the proceeds of a 2017 spoofed-email scheme against "a university in Canada" that produced an $11.8M CAD wire, matching this incident's facts closely, though the release does not name MacEwan directly. Alaumary was ordered to pay more than $30 million in restitution across all his victims combined.

Why It Matters

This remains one of the largest and most-cited BEC/vendor-impersonation losses at a North American university, and it illustrates how a single missed verification step, one uncalled phone number, can expose an organization to eight-figure fraud even without any network intrusion or malware. It also shows the value of vendor-side diligence: it was the contractor, not the university, whose own accounts-receivable reconciliation caught the fraud, days after the largest transfer had already gone out. The eventual 2021 U.S. sentencing of a money launderer for a closely matching "university in Canada" scheme underscores that these BEC frauds are often run by organized, transnational laundering networks capable of moving and hiding tens of millions of dollars across multiple countries within days.

Defenses

MacEwan's own post-incident framing (via spokesperson David Beharry) was that staff "failed to call one vendor to verify if emails requesting a change in banking information were legitimate," meaning a callback/verification step existed as policy but was not followed for these transactions. Standard defenses that would have stopped this: mandatory out-of-band voice verification (using a known phone number, not one in the email) for any bank-detail change request, dual sign-off for large wire changes, DMARC/domain-monitoring to catch look-alike contractor domains, and treating "change of banking details" emails as a distinct high-risk workflow regardless of how routine the underlying invoice is. Clark Builders' president publicly noted the case reinforced why "policies and procedures" for verifying payment changes exist.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Vendor and project reconnaissance: The attackers likely identified that Clark Builders was MacEwan's active general contractor on a large, real, high-dollar project (Allard Hall), consistent with information that would have been visible through public tender records, construction-industry trade press, or the contractor's own marketing of the relationship, since university capital projects and their contractors are typically a matter of public record.
Countering Stage 1: Public tender and capital-project records are hard to hide and generally shouldn't be, since transparency in public-sector procurement is itself a policy goal; the realistic control sits downstream, at the point where a payment-change request references that project, rather than at limiting what's publicly known about it.
2
Look-alike infrastructure setup: The operators registered fake domains and built spoofed email identities impersonating Clark Builders and, per MacEwan's own disclosure, roughly 14 other Edmonton-area construction firms, indicating a look-alike-domain campaign built at scale against the local construction-vendor ecosystem rather than a single custom job against MacEwan.
Countering Stage 2: Monitor domain registrars and certificate-transparency logs for newly registered look-alike domains combining known vendor names with generic business terms, and share threat intelligence across an industry or region, construction firms and their institutional clients included, so a look-alike campaign against one target is flagged before it reaches the next.
3
Pretext email delivery to accounts-payable staff: Posing as Clark Builders, the attackers sent MacEwan's accounts-payable team a request to change the bank/wire details on file for upcoming Allard Hall payments, using a domain and branding designed to look authentic, per MacEwan spokesperson David Beharry's description of a spoofed site carrying the contractor's real logo.
Countering Stage 3: Treat unsolicited emails requesting a change to banking or wire details as a distinct, high-risk category regardless of how authentic the branding looks, and route them to a separate verification workflow before any accounts-payable action is taken.
4
Skipped out-of-band verification: MacEwan staff updated the banking details without placing an independent verification call to Clark Builders using a phone number obtained outside the email thread, the single procedural gap that let the fraud proceed; the university later attributed this to human error rather than technical compromise.
Countering Stage 4: Make out-of-band voice verification, calling a phone number independently on file, not one in the email, mandatory and non-optional for any change to vendor banking details, with the transaction blocked until that call is completed and logged.
5
Fraudulent wire execution: MacEwan processed three wire transfers to the attacker-controlled account over a nine-day window: $1.9M on Aug. 10, 2017, $22,000 on Aug. 17, 2017, and $9.9M (the project's final holdback payment) on Aug. 19, 2017, totaling $11.8M CAD.
Countering Stage 5: Require dual sign-off from a second, independent staff member (ideally a supervisor or director) for large wire transfers or any payment following a recent banking-detail change, so a single employee's error cannot complete an eight-figure transfer alone.
6
Cross-border layering and cash-out: Stolen funds were rapidly moved into accounts in Montreal and Hong Kong, consistent with the layering and cash-out infrastructure that U.S. prosecutors later attributed, in a closely matching case, to a transnational money-laundering network built around mule accounts and rapid onward transfers.
Countering Stage 6: Once funds have left the country, recovery depends on rapid law-enforcement and cross-border legal action (as MacEwan pursued in Montreal, Hong Kong, and London); banks' own transaction-monitoring and freeze capabilities on receiving accounts are the main realistic control at this stage, since the sending institution has little further leverage once a wire has settled.
Quick Facts
Victim
MacEwan University
Location
Edmonton, Alberta, Canada
Date
August 2017 (fraudulent transfers Aug. 10, Aug. 17, and Aug. 19, 2017; discovered Aug. 23, 2017; publicly disclosed Aug. 31, 2017)
Impact
$11.8 million CAD total redirected across three fraudulent wire transfers tied to the Allard Hall construction project: Aug. 10, 2017 ($1.9M), Aug. 17, 2017 ($22,000), and Aug. 19, 2017 ($9.9M, the final holdback payment owed to contractor Clark Builders). Roughly $11.4M was traced to bank accounts in Montreal and Hong Kong; $6.3M was seized from the Montreal account and the Hong Kong funds were frozen pending civil recovery action. By April 4, 2018, MacEwan reported it had recovered $10.92 million, leaving $880,000 of principal permanently unrecovered, plus an estimated $250,000 in legal and banking fees incurred during recovery, a net cash impact of roughly $1.13 million against the original $11.8M exposure. (MacEwan's 2017/18 annual report rounded the recovery figure to $10.8M; this is a rounding/reporting-date difference, not a contradiction of the underlying facts.)
Status
Confirmed
Case Type
Real-World Incident
Sector
Education, Financial Services & Insurance, Government & Public Sector
Related

Related Cases

Save the Children Federation $1M Charity BEC via Employee Email Compromise (2017)

Attackers hijacked a staff email account and used fake solar-panel invoices to trick the US charity into wiring $997,400 to…

Incident 2017Read →

Unatrac Holding (Caterpillar Export Office) $11M CFO Business Email Compromise

A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page; the attacker then…

Incident 2018Read →

Tecnimont SpA (India) $18.6M BEC / CEO Fraud with Staged Fake Conference Calls

Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…

Incident 2018Read →