Forum Discussion

JoB913's avatar
JoB913
User
8 months ago

Hacker accessed my account

On Tuesday I came to work to discover there was a hold on my bank account due suspicious activity. It turns out somebody has hacked into our MYOB account and updated employee & supplier bank account details so the payments going to these employees & suppliers are diverted to the scammers. How does this happen? These payments were uploaded to the bank via electronic payment. How can we trust MYOB is secure, obviously it is not? Luckily we only lost a few thousand it could have been disastrous on another day when I make a way larger amount in payments!

8 Replies

Replies have been turned off for this discussion
  • Our MYOB account has been hacked in the same way 4 times so far and MYOB has been VERY unresponsive. We have alerted the WA Police, our bank and insurers.

    The first time we were hacked a supplier card was hacked the bank details changed and monies diverted. This happened to the same card twice in the matter of 10 days and only came to our attention when the supplier contacted us to say the payments showing our remittance advices had not reached them... on having a closer look the remittance advices showed the hacked bank details. No reponse from MYOB.

    The third time a supplier card was hacked but we noticed this before making payment.

    The fourth hack (I won't say last as MYOB are showing no signs of fixing or acknowledging the issue) was on the 6/9 when I paid a group of suppliers after double checking the bank details against their invoices, exported the ABA file and uploaded it to the bank. One of the 12 supplier I had paid contacted me on 9/9 to say he had not received a payment. The card file was not hacked this time but the ABA file extracted has been hacked and bank details for that 1 supplier (the largest amount paid of course) had been altered. 

    We have again alerted the bank, WA and Victoria Police and our insurers. 

    We have had our IT go over our systems and they are secure - MYOB is the issue - is it someone within MYOB is our next thought????

    MYOB have chosen to remain silent and are not reponding at all. 

     

    • TS14's avatar
      TS14
      User

      Anonymous2024 

       

      The card file was not hacked this time but the ABA file extracted has been hacked and bank details for that 1 supplier (the largest amount paid of course) had been altered. Have a think about that statement - where are bank files saved? I'll help with the steps:

      1. click on Bank file>>bank details are pulled from the supplier/employee card

      2. Save As window opens and you select where you want to save the bank file on your computer 

      3. go to internet banking and browse your computer for the file you want to upload

       

      The bank file is not saved in the software so your situation doesn't point to MYOB being hacked but your computer.

      • The ABA file I extracted from MYOB was uploaded to the bank less than a minute later - no time for any hacker to alter the file.

    • PriyaSelvaraj's avatar
      PriyaSelvaraj
      MYOB Moderator

      Hi Anonymous2024 ,

       

      We take security and data protection extremely seriously. I'm sorry to hear that your security reports were left unresponsive. While we are actively working on security measures, fraudulent activities like this are distressing and we appreciate you reaching out to the relevant authorities.

       

      If you believe that there may be malicious activity or cybercrime affecting MYOB’s solutions, please report this to us. Please follow this link https://www.myob.com/.../report-security-vulnerability to get detailed instructions.

       

      Additionally, I'm reaching out to you via private message requesting some detailed information so that we can investigate further.

       

      Thanks

      Priya Selvaraj 

  • Hi JoB913 ,

     

    Thanks for flagging this. We take security very seriously for our clients. As a precautionary action to protect our client’s security, we monitor activity on accounts and send notifications when we see anything suspicious. This is to ensure you are aware of all changes and anything that may be impacting your security.

     

    This sounds like an unlikely occurrence and we'd like to know more details. I have reached out via private message requesting additional information so that we can escalate to our security teams to take a deeper look at your concern.

    Thanks

    Priya Selvaraj