Former CPA Sentenced for Laundering $5.3M Stolen from Children’s Healthcare of Atlanta in BEC Attack
In June 2023, a business email compromise (BEC) attack targeted a vendor supplying furniture and supplies to Children’s Healthcare of Atlanta, resulting in the theft of $5.3 million. The hacker compromised the vendor’s email account and impersonated them to request a change in payment instructions, diverting funds to an account controlled by Ronald Deabler, a 66-year-old former certified public accountant and Atlanta business owner.
Deabler conspired with the hacker to launder the stolen funds in exchange for a commission. He opened a second account and attempted to transfer the money, but the bank blocked most of the transaction, allowing only $1 million to go through. The remaining $3.5 million was converted into cashier’s checks and distributed to various entities at the hacker’s direction.
The fraud was detected within days when the vendor alerted Children’s Healthcare of Atlanta about the missing payment. Authorities traced the funds to Deabler, leading to his conviction by a federal jury in February. In June 2024, he was sentenced to four years in prison, followed by two years of supervised release, and ordered to pay $682,000 in restitution. Approximately $4 million of the stolen funds was recovered from Deabler’s accounts and those that received the cashier’s checks.
U.S. Attorney Theodore S. Hertzberg emphasized that those targeting healthcare institutions and laundering stolen funds would face severe consequences. The incident highlights the growing threat of BEC scams, which the FBI’s Internet Crime Complaint Center (IC3) reported as the second-costliest cybercrime in 2023, with losses exceeding $3 billion that year alone. Over the past three years, BEC attacks have resulted in $8.5 billion in losses.
Source: https://www.hipaajournal.com/former-cpa-sentenced-laundering-childrens-healthcare-atlanta-funds/
Children's Healthcare of Atlanta cybersecurity rating report: https://www.rankiteo.com/company/children's-healthcare-of-atlanta
"id": "CHI1785349621",
"linkid": "children's-healthcare-of-atlanta",
"type": "Cyber Attack",
"date": "6/2023",
"severity": "75",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'industry': 'Healthcare',
'location': 'Atlanta, Georgia, USA',
'name': 'Children’s Healthcare of Atlanta',
'type': 'Healthcare provider'},
{'industry': 'Supply chain',
'name': 'Vendor supplying furniture and supplies',
'type': 'Vendor'}],
'attack_vector': 'Email account compromise, social engineering',
'date_detected': '2023-06',
'date_publicly_disclosed': '2024-06',
'description': 'In June 2023, a business email compromise (BEC) attack '
'targeted a vendor supplying furniture and supplies to '
'Children’s Healthcare of Atlanta, resulting in the theft of '
'$5.3 million. The hacker compromised the vendor’s email '
'account and impersonated them to request a change in payment '
'instructions, diverting funds to an account controlled by '
'Ronald Deabler, a 66-year-old former certified public '
'accountant and Atlanta business owner. Deabler conspired with '
'the hacker to launder the stolen funds in exchange for a '
'commission. The fraud was detected within days when the '
'vendor alerted Children’s Healthcare of Atlanta about the '
'missing payment.',
'impact': {'brand_reputation_impact': 'Potential reputational damage to '
'Children’s Healthcare of Atlanta',
'financial_loss': '$5.3 million',
'legal_liabilities': 'Restitution of $682,000 imposed on Ronald '
'Deabler',
'operational_impact': 'Payment disruption to vendor'},
'initial_access_broker': {'entry_point': 'Vendor’s email account',
'high_value_targets': 'Children’s Healthcare of '
'Atlanta'},
'investigation_status': 'Closed (conviction and sentencing completed)',
'lessons_learned': 'Importance of verifying payment instruction changes, '
'heightened scrutiny of BEC attacks targeting healthcare '
'institutions',
'motivation': 'Financial gain',
'post_incident_analysis': {'corrective_actions': 'Funds recovery, legal '
'action, potential '
'improvements in payment '
'verification processes',
'root_causes': 'Email account compromise, lack of '
'payment verification, insider '
'collusion (Ronald Deabler)'},
'recommendations': 'Implement multi-factor authentication for email accounts, '
'establish strict payment verification protocols, enhance '
'employee training on BEC scams',
'references': [{'source': 'U.S. Attorney’s Office, Northern District of '
'Georgia'},
{'source': 'FBI’s Internet Crime Complaint Center (IC3)'}],
'regulatory_compliance': {'legal_actions': 'Federal conviction of Ronald '
'Deabler'},
'response': {'containment_measures': 'Bank blocked transactions, funds traced '
'by authorities',
'law_enforcement_notified': 'Yes',
'recovery_measures': 'Approximately $4 million recovered',
'remediation_measures': 'Funds recovery, legal action against '
'Ronald Deabler'},
'threat_actor': 'Unknown hacker, Ronald Deabler (money launderer)',
'title': 'Former CPA Sentenced for Laundering $5.3M Stolen from Children’s '
'Healthcare of Atlanta in BEC Attack',
'type': 'Business Email Compromise (BEC)',
'vulnerability_exploited': 'Email account takeover, lack of payment '
'verification'}