A spoofed-email scheme impersonating MacEwan University's trusted general contractor, Clark Builders, tricked staff into redirecting $11.8 million CAD in construction payments to fraudulent bank accounts in Montreal and Hong Kong, one of the largest publicly documented BEC losses at a North American university.
Reviewed by the Social Engineering Examples team.
In August 2017, fraudsters impersonating MacEwan University's general contractor, Clark Builders, sent spoofed emails requesting a change to the banking details used for payments on the Allard Hall construction project. MacEwan accounts-payable staff acted on the request without an independent verification call and processed three wire transfers to the fraudulent account: $1.9 million on Aug. 10, $22,000 on Aug. 17, and $9.9 million on Aug. 19, a total of $11.8 million CAD. The fraud came to light on Aug. 23, 2017, when Clark Builders itself called MacEwan to ask why several expected payments, including the $9.9M project holdback, had not arrived. MacEwan publicly disclosed the incident on Aug. 31, 2017. The university said the same attackers had set up fake look-alike domains impersonating about 14 Edmonton-area construction firms, indicating a wider vendor-impersonation campaign. Roughly $11.4M of the stolen funds was traced to bank accounts in Montreal and Hong Kong; MacEwan pursued civil freezing and recovery action, ultimately recovering $10.92M by April 2018 and permanently losing $880,000 of principal plus about $250,000 in legal/banking fees.
Attackers spoofed the email identity of Clark Builders, the Edmonton-based general contractor MacEwan had worked with since 2003 on multiple projects including the new Allard Hall arts building. Posing as the contractor, they sent MacEwan accounts-payable staff a request to change the banking/wire details on file for upcoming project payments. Believing the request was legitimate given the long-standing vendor relationship, staff updated the payment information and processed three transfers over nine days without placing a verification phone call to Clark Builders using an independently known number. MacEwan later disclosed the same actors had registered fake look-alike domains impersonating roughly 14 Edmonton-area construction firms, suggesting a broader vendor-impersonation campaign rather than a one-off attempt against MacEwan alone.
The lure was a routine-looking vendor email requesting an update to banking/wire details for an established, trusted contractor (Clark Builders) mid-way through a real, active, high-dollar construction project (Allard Hall), exploiting the fact that a change-of-bank-details request is unremarkable in a long commercial relationship. The tell that ultimately surfaced the fraud was not a technical detection but a business one: Clark Builders' own accounts team noticed they hadn't received three expected payments, including a $9.9M final holdback, and called MacEwan on Aug. 23, 2017 to ask why: "we found it quite odd that we weren't receiving payment for the invoices," said Clark Builders president Paul Verhesen. That single reconciliation call, from the real vendor rather than the university, unraveled the scheme.
Of the $11.8M CAD stolen, roughly $11.4M was traced to bank accounts in Montreal and Hong Kong; MacEwan pursued civil freezing/recovery action in those jurisdictions (and reportedly London), securing seizure of $6.3M from the Montreal account and a freeze on the Hong Kong funds. By April 4, 2018, the university reported $10.92 million recovered, an $880,000 permanent principal loss, and roughly $250,000 in additional legal/banking fees. Edmonton Police Service and other law-enforcement/bank-security teams investigated; no criminal charges had been publicly announced as of April 2018. Separately, in September 2021 the U.S. Secret Service and DOJ announced the sentencing of Ghaleb Alaumary, a dual Canadian-U.S. national money launderer, to 140 months in federal prison (Southern District of Georgia) for laundering proceeds from multiple BEC and bank-cyberheist schemes; the DOJ release described laundering the proceeds of a 2017 spoofed-email scheme against "a university in Canada" that produced an $11.8M CAD wire, matching this incident's facts closely, though the release does not name MacEwan directly. Alaumary was ordered to pay more than $30 million in restitution across all his victims combined.
This remains one of the largest and most-cited BEC/vendor-impersonation losses at a North American university, and it illustrates how a single missed verification step, one uncalled phone number, can expose an organization to eight-figure fraud even without any network intrusion or malware. It also shows the value of vendor-side diligence: it was the contractor, not the university, whose own accounts-receivable reconciliation caught the fraud, days after the largest transfer had already gone out. The eventual 2021 U.S. sentencing of a money launderer for a closely matching "university in Canada" scheme underscores that these BEC frauds are often run by organized, transnational laundering networks capable of moving and hiding tens of millions of dollars across multiple countries within days.
MacEwan's own post-incident framing (via spokesperson David Beharry) was that staff "failed to call one vendor to verify if emails requesting a change in banking information were legitimate," meaning a callback/verification step existed as policy but was not followed for these transactions. Standard defenses that would have stopped this: mandatory out-of-band voice verification (using a known phone number, not one in the email) for any bank-detail change request, dual sign-off for large wire changes, DMARC/domain-monitoring to catch look-alike contractor domains, and treating "change of banking details" emails as a distinct high-risk workflow regardless of how routine the underlying invoice is. Clark Builders' president publicly noted the case reinforced why "policies and procedures" for verifying payment changes exist.
Attackers hijacked a staff email account and used fake solar-panel invoices to trick the US charity into wiring $997,400 to…
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page; the attacker then…
Fraudsters posing as Tecnimont's group CEO, other executives, and a fictitious Swiss lawyer used spoofed emails and a staged series…