Showing posts with label Cyber Crime. Show all posts
Showing posts with label Cyber Crime. Show all posts
Friday, August 25, 2017
Russian hackers feel the heat as Trump seeks warmer Moscow ties
* President Trump is seeking better ties with Moscow
* Russia denies meddling in election won by Trump
* Number of Russians arrested by U.S. has surged
* Arrests have shaken Russian hacker community
MOSCOW/SAN FRANCISCO - When Alexander Vinnik was arrested on money-laundering charges at a Greek hotel in late July, the status of his Jabber secure online messaging account was set to "away".
"He often takes some time to reply, so at first I didn't think anything of it," said one person who knew the Russian as an administrator of a digital currency exchange which U.S. prosecutors say was used to launder criminal funds.
"Then when I saw his picture on the news, I knew he would be 'away' for a long time," said the person, who spoke on condition of anonymity.
The U.S. Justice Department says Vinnik facilitated crimes including computer hacking, fraud and drug trafficking by laundering at least $4 billion through BTC-e -- an exchange used to trade bitcoin and other digital currencies -- since 2011.
The 37-year-old faces up to 55 years in prison if extradited to the United States. He denies the allegations against him, according to Greek media reports, and BTC-e has said he never worked for the exchange. Reuters was unable to reach BTC-e or a lawyer representing Vinnik for comment.
Vinnik is now one of seven Russians arrested or indicted on U.S. cyber crime charges this year. On average, just two Russian cyber criminals were extradited to the United States each year between 2010 and the start of this year, according to a Reuters review of U.S. Justice Department filings, Russian government statements and sources briefed on the matter.
The increase to a record level shows that although President Donald Trump is trying to improve relations with Moscow, the United States has not shied away from pursuing Russians suspected of cyber crime.
The prosecutions coincide with intensified scrutiny of Russian hackers since U.S. intelligence officials determined that Russia interfered in the 2016 U.S. presidential election using cyber warfare methods to help Trump.
Russia tried to hack US voting systems for months: report
http://news.abs-cbn.com/overseas/06/06/17/russia-tried-to-hack-us-voting-systems-for-months-report
The Kremlin has denied accusations it interfered in elections in the United States or elsewhere.
But U.S. opposition lawmakers have questioned whether Trump is willing to respond forcefully to Moscow over its actions in cyberspace, and the White House has avoided publicly accusing Russia over recent politically-motivated hacking attacks. .
Alarmed by Trump's proposal to create a joint U.S.-Russia cyber security unit, U.S. lawmakers have also drawn up a draft bill that would require him to notify lawmakers before he does so.
Four U.S. federal law enforcement officials, who discussed the recent arrests with Reuters on condition of anonymity, said there had been no centralized effort to step up action against Russian cyber criminals under Trump.
The increase in the number of arrests stemmed from breakthroughs made in investigations before last year's election, two of them said.
The FBI referred all questions to the U.S. Justice Department. The Justice Department said it did not track arrests or indictments by nationality and declined further comment.
RUSSIAN HACKERS RATTLED
Some U.S. officials, however, acknowledged that individual agents may now be more motivated to move against Russian cyber criminals following the election hacking scandal.
Russian hackers are active at all levels of cyber crime, from small-time thefts of online banking details, to taking down the computer networks of multi-national companies and government departments.
John Carlin, who until last October ran the national security division of the U.S. Justice Department as assistant attorney general, said resources had already been moving towards pursuing Russian nationals before the 2016 election.
But he added: "Their outrageous activity to undermine the integrity of our election, like they did in western Europe before and have done since, can only have added fuel to the fire."
According to interviews with five people who knew the men arrested this year -- all of whom declined to be named for fear of prosecution -- the arrests have shaken the Russian cyber crime community.
"Now they are arresting even those who had a super indirect, not even direct connection to what they call influencing their election," said one who knew Vinnik by his online moniker WME.
Used to operating across borders with relative impunity, Russian cyber criminals are now worried the prosecutions will lead to further arrests or harm their operations.
They are cutting back on trips abroad that were once seen as a calculated risk because of the risk of arrest and extradition, but are now viewed as increasingly foolhardy.
"We have monitored criminals discussing the aftermath (of the arrests) ... and it is clear they are concerned about two things," said Ilya Sachkov, head of cyber security firm Group-IB, whose Threat Intelligence unit specialises in monitoring and tracking the Russian-speaking cyber crime community.
"First, what the arrested members potentially know about them, but second and more importantly, a disruption in their ability to make money."
One of those arrested this year was Peter Levashov, charged by U.S. prosecutors with operating one of the world's largest botnets, or networks, of infected computers used by cyber criminals. He denies the charges.
Levashov allegedly used the botnet to pump out spam emails for a multitude of criminal schemes, such as stock fraud, online credential phishing attempts and the distribution of malware, including ransomware.
A person who knew Levashov by his online identity Severa said his arrest in particular had rattled underground cyber criminal circles because he was so well known.
"People read the news of course and see guys they know getting busted," the person said. "Once is bad, this many times is scary."
source: news.abs-cbn.com
Wednesday, July 26, 2017
6 billion records hacked so far this year: researchers
WASHINGTON - A surge in computer hacking has led to the breach of more than six billion records so far this year, topping the total for 2016, security researchers said Tuesday.
Virginia-based Risk Based Security said in its mid-year report that it identified 2,227 publicly disclosed data compromise events through June 30 affecting business, government, medical and educational data.
"It is stunning to see the steady increase in the number of breaches impacting one million or more records," said Inga Goddijn, Executive Vice President for Risk Based Security.
The report said hackers are increasingly targeting employment and tax records. Some attacks successfully used "phishing" or spoofing or emails to obtain tax information from US citizens. Other targets included human resources departments, employment agencies and aggregators of employment data.
"While news of politically motivated foreign interference in election systems continues to dominate the headlines, the breach activity we are tracking this year is a stark reminder of just how many data compromise incidents are motivated by financial gain," Goddijn said.
"As long as information can be quickly monetized and systems remain vulnerable to attack, we should not expect to see any slowdown in breach activity.”
source: news.abs-cbn.com
Monday, May 15, 2017
More disruptions feared from cyber attack; Microsoft slams US govt secrecy
WASHINGTON/FRANKFURT - Officials across the globe scrambled over the weekend to catch the culprits behind a massive ransomware worm that disrupted operations at car factories, hospitals, shops and schools, while Microsoft on Sunday pinned blame on the US government for not disclosing more software vulnerabilities.
Cyber security experts said the spread of the worm dubbed WannaCry - "ransomware" that locked up more than 200,000 computers in more than 150 countries - had slowed but that the respite might only be brief amid fears new versions of the worm will strike.
In a blog post on Sunday, Microsoft President Brad Smith appeared to tacitly acknowledge what researchers had already widely concluded: The ransomware attack leveraged a hacking tool, built by the US National Security Agency, that leaked online in April.
"This is an emerging pattern in 2017," Smith wrote. "We have seen vulnerabilities stored by the CIA show up on WikiLeaks, and now this vulnerability stolen from the NSA has affected customers around the world."
He also poured fuel on a long-running debate over how government intelligence services should balance their desire to keep software flaws secret - in order to conduct espionage and cyber warfare - against sharing those flaws with technology companies to better secure the internet.
"This attack provides yet another example of why the stockpiling of vulnerabilities by governments is such a problem," Smith wrote. He added that governments around the world should "treat this attack as a wake-up call" and "consider the damage to civilians that comes from hoarding these vulnerabilities and the use of these exploits."
The NSA and White House did not immediately respond to requests for comment about the Microsoft statement.
Economic experts offered differing views on how much the attack, and associated computer outages, would cost businesses and governments.
The non-profit US Cyber Consequences Unit research institute estimated that total losses would range in the hundreds of millions of dollars, but not exceed $1 billion.
Most victims were quickly able to recover infected systems with backups, said the group's chief economist, Scott Borg.
California-based cyber risk modeling firm Cyence put the total economic damage at $4 billion, citing costs associated with businesses interruption.
US President Donald Trump on Friday night ordered his homeland security adviser, Tom Bossert, to convene an "emergency meeting" to assess the threat posed by the global attack, a senior administration official told Reuters.
Senior US security officials held another meeting in the White House Situation Room on Saturday, and the FBI and the NSA were working to help mitigate damage and identify the perpetrators of the massive cyber attack, said the official, who spoke on condition of anonymity to discuss internal deliberations.
The investigations into the attack were in the early stages, however, and attribution for cyber attacks is notoriously difficult.
The original attack lost momentum late on Friday after a security researcher took control of a server connected to the outbreak, which crippled a feature that caused the malware to rapidly spread across infected networks.
Infected computers appear to largely be out-of-date devices that organizations deemed not worth the price of upgrading or, in some cases, machines involved in manufacturing or hospital functions that proved too difficult to patch without possibly disrupting crucial operations, security experts said.
Microsoft released patches last month and on Friday to fix a vulnerability that allowed the worm to spread across networks, a rare and powerful feature that caused infections to surge on Friday.
Code for exploiting that bug, which is known as "Eternal Blue," was released on the internet last month by a hacking group known as the Shadow Brokers.
The head of the European Union police agency said on Sunday the cyber assault hit 200,000 victims in at least 150 countries and that number would grow when people return to work on Monday.
MONDAY MORNING RUSH?
Monday was expected to be a busy day, especially in Asia, which may not have seen the worst of the impact yet, as companies and organizations turned on their computers.
"Expect to hear a lot more about this tomorrow morning when users are back in their offices and might fall for phishing emails" or other as yet unconfirmed ways the worm may propagate, said Christian Karam, a Singapore-based security researcher.
The attack hit organizations of all sizes.
Renault said it halted manufacturing at plants in France and Romania to prevent the spread of ransomware.
Other victims include is a Nissan manufacturing plant in Sunderland, northeast England, hundreds of hospitals and clinics in the British National Health Service, German rail operator Deutsche Bahn and international shipper FedEx Corp
A Jakarta hospital said on Sunday that the cyber attack had infected 400 computers, disrupting the registration of patients and finding records.
Account addresses hard-coded into the malicious WannaCry virus appear to show the attackers had received just under $32,500 in anonymous bitcoin currency as of (1100 GMT) 7 a.m. EDT on Sunday, but that amount could rise as more victims rush to pay ransoms of $300 or more.
The threat receded over the weekend after a British-based researcher, who declined to give his name but tweets under the profile @MalwareTechBlog, said he stumbled on a way to at least temporarily limit the worm's spread by registering a web address to which he noticed the malware was trying to connect.
Security experts said his move bought precious time for organizations seeking to block the attacks.
(Additional reporting by Jim Finkle, Neil Jerome Morales, Masayuki Kitano, Kiyoshi Takenaka, Jose Rodriguez, Elizabeth Piper, Emmanuel Jarry, Orathai Sriring, Jemima Kelly, Alistair Smout, Andrea Shalal, Jack Stubbs, Antonella Cinelli, Kate Holton, Andy Bruce, Michael Holden, David Milliken, Tim Hepher, Luiza Ilie, Patricia Rua, Axel Bugge, Sabine Siebold, Eric Walsh, Engen Tham, Fransiska Nangoy, Soyoung Kim, Mai Nguyen and Nick Zieminski; Editing by Mark Heinrich and Peter Cooney)
source: news.abs-cbn.com
Friday, May 20, 2016
Cyber thieves exploit banks' faith in SWIFT transfer network
LONDON/CHICAGO - Shortly after 7 p.m. on January 12, 2015, a message from a secure computer terminal at Banco del Austro (BDA) in Ecuador instructed San Francisco-based Wells Fargo to transfer money to bank accounts in Hong Kong.
Wells Fargo complied. Over 10 days, Wells approved a total of at least 12 transfers of BDA funds requested over the secure SWIFT system.
The SWIFT network - which allows banks to process billions of dollars in transfers each day - is considered the backbone of international banking. In all, Wells Fargo transferred $12 million of BDA's money to accounts across the globe.
Both banks now believe those funds were stolen by unidentified hackers, according to documents in a BDA lawsuit filed against Wells Fargo in New York this year. The two banks declined requests for comment from Reuters.
BDA is suing Wells Fargo on the basis that the U.S. bank should have flagged the transactions as suspicious.
Wells Fargo has countered that security lapses in BDA's own operations caused the Ecuadorean bank's losses. Hackers had secured a BDA employee's SWIFT logon credentials, Wells Fargo said in a February court filing.
SWIFT, an acronym for the Society for Worldwide Interbank Financial Telecommunication, is not a party to the lawsuit.
Neither bank reported the theft to SWIFT, which said it first learned about the cyber attack from a Reuters inquiry.
"We were not aware," SWIFT said in a statement responding to Reuters inquiries. "We need to be informed by customers of such frauds if they relate to our products and services, so that we can inform and support the wider community. We have been in touch with the bank concerned to get more information, and are reminding customers of their obligations to share such information with us."
SWIFT says it requires customer to notify SWIFT of problems that can affect the "confidentiality, integrity, or availability of SWIFT service."
SWIFT, however, has no rule specifically requiring client banks to report hacking thefts. Banks often do not report such attacks out of concern they make the institution appear vulnerable, former SWIFT employees and cyber security experts told Reuters.
The Ecuador case illuminates a central problem with preventing such fraudulent transfers: Neither SWIFT nor its client banks have a full picture of the frequency or the details of cyber thefts made through the network, according to more than dozen former SWIFT executives, users and cyber security experts interviewed by Reuters.
The case - details of which have not been previously reported - raises new questions about the oversight of the SWIFT network and its communications with member banks about cyber thefts and risks. The network has faced intense scrutiny since cyber thieves stole $81 million in February from a Bangladesh central bank account at the Federal Reserve Bank of New York.
It's unclear what SWIFT tells its member banks when it does find out about cyber thefts, which are typically first discovered by the bank that has been defrauded. SWIFT spokeswoman Natasha de TerĂ¡n said that the organization "was transparent with its users" but declined to elaborate. SWIFT declined to answer specific questions about its policies for disclosing breaches.
Reuters was unable to determine the number or frequency of cyber attacks involving the SWIFT system, or how often the banks report them to SWIFT officials.
The lack of disclosure may foster overconfidence in SWIFT network security by banks, which routinely approve transfer requests made through the messaging network without additional verification, former SWIFT employees and cyber security experts said.
The criminals behind such heists are exploiting banks' willingness to approve SWIFT requests at face value, rather than making additional manual or automated checks, said John Doyle, who held a variety of senior roles at SWIFT between 1980 and 2005.
"SWIFT doesn't replace prudent banking practice" he said, noting that banks should verify the authenticity of withdrawal or transfer requests, as they would for money transfers outside the SWIFT system.
SWIFT commits to checking the codes on messages sent into its system, to ensure the message has originated from a client's terminal, and to send it to the intended recipient quickly and securely, former SWIFT executives and cyber security experts said. But once cyber-thieves obtain legitimate codes and credentials, they said, SWIFT has no way of knowing they are not the true account holders.
The Bank for International Settlements, a trade body for central banks, said in a November report that increased information sharing on cyber attacks is crucial to helping financial institutions manage the risk.
"The more they share the better," said Leo Taddeo, chief security officer at Cryptzone and a former special agent in charge with the FBI's cyber crime division in New York.
SYSTEMIC RISK
SWIFT, a cooperative owned and governed by representatives of the banks it serves, was founded in 1973 and operates a secure messaging network that has been considered reliable for four decades. But recent attacks involving the Belgium-based cooperative have underscored how the network's central role in global finance also presents systemic risk.
SWIFT is not regulated, but a group of ten central banks from developed nations, led by the National Bank of Belgium, oversee the organization. Among its stated guidelines is a requirement to provide clients with enough information to enable them "to manage adequately the risks related to their use of SWIFT."
However, some former SWIFT employees said that the cooperative struggles to keep banks informed on risks of cyber fraud because of a lack of cooperation from the banks themselves. SWIFT's 25-member board of directors is filled with representatives of larger banks.
"The banks are not going to tell us too much," said Doyle, the former SWIFT executive. "They wouldn't like to destabilize confidence in their institution."
Banks also fear notifying SWIFT or law enforcement of security breaches because that could lead to regulatory investigations that highlight failures of risk management or compliance that could embarrass top managers, said Hugh Cumberland, a former SWIFT marketing executive who is now a senior associate with cyber security firm Post-Quantum.
Cases of unauthorized money transfers rarely become public, in part because disagreements are usually settled bilaterally or through arbitration, which is typically private, said Salvatore Scanio, a lawyer at Washington, D.C.-based Ludwig & Robinson. Scanio said he consulted on a dispute involving millions of dollars of stolen funds and the sending of fraudulent SWIFT messages similar to the BDA attack. He declined to name the parties or provide other details.
Theoretically, SWIFT could require its customers, mainly banks, to inform it of any attacks - given that no bank could risk the threat of exclusion from the network, said Lieven Lambrecht, the head of human resources at SWIFT for a year-and-a-half through May 2015.
But such a rule would require the agreement of its board, which is mainly made up of senior executives from the back office divisions of the largest western banks, who would be unlikely to approve such a policy, Lambrecht said.
FIGHT OVER LIABILITY
This week, Vietnam's Tien Phong Bank said its SWIFT account, too, was used in an attempted hack last year. That effort failed, but it is another sign that cyber-criminals are increasingly targeting the messaging network.
In the Ecuadorean case, Wells Fargo denies any liability for the fraudulent transfers from BDA accounts. Wells Fargo said in court records that it did not verify the authenticity of the BDA transfer requests because they came through SWIFT, which Wells called "among the most widely used and secure" systems for money transfers.
BDA is seeking recovery of the money, plus interest. Wells Fargo is attempting to have the case thrown out.
New York-based Citibank also transferred $1.8 million in response to fraudulent requests made through BDA's SWIFT terminal, according to the BDA lawsuit against Wells Fargo.
Citibank repaid the $1.8 million to BDA, according to a BDA court filing in April. Citibank did not respond to a request for comment.
For its part, Wells Fargo refunded to BDA $958,700 out of the $1,486,230 it transferred to an account in the name of a Jose Mariano Castillo at Wells Fargo in Los Angeles, according to the lawsuit. Reuters could not locate Castillo or verify his existence.
ANATOMY OF A CYBER HEIST
The BDA-Wells Fargo case is unusual in that one bank took its correspondent bank to court, thus making the details public, said Scanio, the Washington attorney. BDA acknowledged in a January court filing that it took more than a week after the first fraudulent transfer request for BDA to discover the missing money.
After obtaining a BDA employee's SWIFT logon, the thieves then fished out previously canceled or rejected payment requests that remained in BDA's SWIFT outbox.
They then altered the amounts and destinations on the transfer requests and reissued them, both banks said in filings.
While Wells Fargo has claimed in court filings that failures of security at BDA are to blame for the breach, BDA has alleged that Wells could easily have spotted and rejected the unusual transfers. BDA noted that the payment requests were made outside of its normal business hours and involved unusually large amounts.
The BDA theft and others underscore the need for banks on both sides of such transactions - often for massive sums - to rely less on SWIFT for security and strengthen their own verification protocols, Cumberland said.
"This image of the SWIFT network and the surrounding ecosystem being secure and impenetrable has encouraged complacency," he said. (Additional reporting by Jim Finkle in Boston and Alexandra Valencia in Quito; Editing by David Greising and Brian Thevenot)
source: www.abs-cbnnews.com
Thursday, May 19, 2016
Milwaukee Bucks fall for e-mail scam, reveal financial data
CHICAGO - A Milwaukee Bucks employee was tricked by an e-mail scam and handed over financial data of players and other employees to a hacker, the NBA club admitted Thursday.
In a statement, the Bucks revealed that they learned Monday that Internal Revenue Service (IRS) tax forms were provided to an unknown person who faked being team president Peter Feigin.
"On May 16, 2016, we discovered our company was the victim of an e-mail spoofing attack that occurred when a request was recently made by an unknown impersonator of our president for 2015 employee W-2s," the Bucks statement said.
"Unfortunately, that information was provided by an employee before it was determined that the request was made from a spoofed e-mail address."
Reports said the scam was successful on April 26, meaning almost three weeks lapsed before the breach of security was uncovered.
The Bucks told the IRS and FBI about the breach and vowed to work with authorities on their investigations.
But the financial details for such Bucks players as Greek forward Giannis Antetokounmpo and Venezuelan forward Greivis Vazquez as well as employees in other areas of the club were revealed, including names, addresses, US Social Security numbers, birth dates and total compensation packages.
"We take this incident, and the privacy and security of our employees, very seriously," the Bucks said. "We immediately launched an investigation, which is aggressive and ongoing.
"We quickly notified impacted individuals and are arranging for these individuals to have access to three years of credit monitoring and non-expiring identity restoration services.
"We believe this incident arose as a result of human error and are providing additional privacy training to our staff and implementing additional preventative measures."
js/rcw
source: www.abs-cbnnews.com
Friday, April 22, 2016
Bangladesh Bank exposed to hackers by cheap switches, no firewall: police
DHAKA -- Bangladesh's central bank was vulnerable to hackers because it did not have a firewall and used second-hand, $10 switches to network computers connected to the SWIFT global payment network, an investigator into one of the world's biggest cyber heists said.
The shortcomings made it easier for hackers to break into the Bangladesh Bank system earlier this year and attempt to siphon off nearly $1 billion using the bank's SWIFT credentials, said Mohammad Shah Alam, head of the Forensic Training Institute of the Bangladesh police's criminal investigation department.
"It could be difficult to hack if there was a firewall," Alam said in an interview.
The lack of sophisticated switches, which can cost several hundred dollars or more, also means it is difficult for investigators to figure out what the hackers did and where they might have been based, he added.
Experts in bank security said that the findings described by Alam were disturbing.
"You are talking about an organization that has access to billions of dollars and they are not taking even the most basic security precautions," said Jeff Wichman, a consultant with cyber firm Optiv.
Tom Kellermann, a former member of the World Bank security team, said that the security shortcomings described by Alam were "egregious," and that he believed there were "a handful" of central banks in developing countries that were equally insecure.
Kellermann, now chief executive of investment firm Strategic Cyber Ventures LLC, said that some banks fail to adequately protect their networks because they focus security budgets on physically defending their facilities.
POLICE BLAME BANK, SWIFT
Cyber criminals broke into Bangladesh Bank's system and in early February tried to make fraudulent transfers totalling $951 million from its account at the Federal Reserve Bank of New York.
Most of the payments were blocked, but $81 million was routed to accounts in the Philippines and diverted to casinos there. Most of those funds remain missing.
The police believe that both the bank and SWIFT should take the blame for the oversight, Alam said in an interview.
"It was their responsibility to point it out but we haven't found any evidence that they advised before the heist," he said, referring to SWIFT.
A spokeswoman for Brussels-based SWIFT declined comment.
SWIFT has previously said the attack was related to an internal operational issue at Bangladesh Bank and that SWIFT's core messaging services were not compromised.
A spokesman for Bangladesh Bank said SWIFT officials advised the bank to upgrade the switches only when their system engineers from Malaysia visited after the heist.
"There might have been a deficiency in the system in the SWIFT room," said the spokesman, Subhankar Saha, confirming that the switch was old and needed to be upgraded.
"Two (SWIFT) engineers came and visited the bank after the heist and suggested to upgrade the system," Saha said.
GLOBAL WHODUNIT
The heist's masterminds have yet to be identified.
Bangladesh police said earlier this week they had identified 20 foreigners involved in the heist but they appear to be people who received some of the payments, rather than those who initially stole the money.
Bangladesh Bank has about 5,000 computers used by officials in different departments, Alam said.
The SWIFT room is roughly 12 feet by 8 feet, a window-less office located on the eight floor of the bank's annex building in Dhaka. There are four servers and four monitors in the room.
All transactions from the previous day are automatically printed on a printer in the room.
The SWIFT facility should have been walled off from the rest of the network. That could have been done if the bank had used the more expensive, "managed" switches, which allow engineers to create separate networks, said Alam, whose institute includes a cyber-crime division.
Moreover, considering the importance of the room, the bank should have deployed staff to monitor activity round the clock, including weekends and holidays, he said.
source: www.abs-cbnnews.com
Thursday, March 17, 2016
Faulty printer implicated in $81-M bank heist
DHAKA, Bangladesh - A printer fault at Bangladesh's central bank meant that overseas queries about suspicious transactions went unanswered, according to a report seen by AFP Wednesday on the $81 million cyber heist that sent shockwaves through the banking world.
The report, filed to police on Tuesday, recounts the events leading to the discovery of the dramatic theft from an overseas account of Bangladesh Bank.
It says that because of a printer and software problem, it took the Bangladesh central bank nearly four days to ask banks across the globe to halt payments to the hackers.
They tried to steal around $1 billion and got away with $81 million from the impoverished country's coffers.
How a hacker's typo helped stop a billion dollar bank heist
Central bank governor Atiur Rahman and two of the deputy governors have lost their jobs over the scandal, which has hugely embarrassed the government and raised alarm over the security of the country's foreign exchange reserves of over $27 billion.
On Wednesday the government, which has said it was kept in the dark about the losses for weeks, also removed its most senior banking official M. Aslam Alam from his position.
The hackers managed to transfer $81 million on February 5 -- a Friday, when Bangladesh Bank is closed -- from its account with the Federal Reserve Bank of New York, transferring the cash electronically to accounts in the Philippines.
In the report seen by AFP, the bank's joint director Zubair bin Huda said engineers were unable to fix the printers until February 6, a day after the New York bank sent queries about four separate transactions.
"Since such glitches happened before, we thought it was a common problem just like any other day," Huda said in the report.
Bangladesh Bank tried to contact New York on February 6 by email, fax and phone to ask that the transactions be suspended when it realized that the SWIFT interbank messaging system which it normally used was not working properly, Huda said.
"We realized that the SWIFT system being ineffective was an important issue, and therefore we sent an email to Federal Reserve Bank of New York at 1:30pm on February 6 to halt all types of payment processing," he said.
But they were unable to get through as the US bank was closed for the weekend.
It was not until Monday afternoon that the central bank's main server was again working properly and officials were able to send the formal requests to stop the payments to six banks across the globe.
But by that time $81 million had been transferred from Bangladesh Bank's New York account to a bank in the Philippines.
PHILIPPINES ACCOUNT
The money was later transferred to an account belonging to ethnic Chinese businessman William So Go, a Philippine Senate committee heard this week.
The money was then transferred to Philippine casinos, Julia Bacay-Abad from the Philippines' anti-money laundering council told the hearing on Tuesday.
Go's lawyer said the businessman's signatures for his now-frozen RCBC account, which were used to transfer the money, had been forged.
'Money trail in laundering scam ends with casinos'
Casino junket operator got $30-M in cash
Another transfer of $20 million was halted by a bank in Sri Lanka at Bangladesh Bank's request.
As details of the scandal emerged last week, Bangladesh Finance Minister A.M.A. Muhith threatened to sue the New York Fed.
The US-based bank said in a statement on its website that the payment instructions "were fully authenticated by the SWIFT messaging system in accordance with standard authentication protocols".
LACK OF TRANSPARENCY
Meanwhile, the $81 million heist has also put a spotlight on the Philippines' strict bank secrecy law. Finance Secretary Cesar Purisima earlier said the Philippines along with Lebanon are some of the only countries in the world left with a bank secrecy law.
Even Switzeland, which is known for its strict banking system, has been open to relax the law.
PH one of few countries with bank secrecy law
According to a law enacted in 1955, all bank deposits in the Philippines are absolutely confidential and may not be examined "except upon written permission of the depositor, or in cases of impeachment, or upon order of a competent court in cases of bribery or dereliction of duty of public officials, or in cases where the money deposited or invested is the subject matter of the litigation."
Last year, Internal Revenue Commissioner Kim Henares said the government is preparing a draft bill that would lift or ease the bank secrecy law to strengthen government's tax collection efforts. Congress, however, thumbed it down.
Makati Business Club chairman Ramon del Rosario said he found it "uncomfortable" that the bank secrecy law was invoked during the Senate investigation on the $81 million heist.
Senator Sergio Osmena III said the international financial community has already taken notice of loopholes in Philippine laws.
"As far as I am concerned, sunlight is the best medicine. Transparency in a democratic setting is the best safeguard against corruption and against bad public officials," he said.
“Despite all the warnings from the FATF (Financial Action Task Force), we still don’t have the political will to plug those loopholes. I hope that this will teach us a lesson because the international financial community has just taken notice of how big our loopholes are and it’s become an international incident because [81 million] dollars was hacked from the account of Bangladesh Central Bank and laundered through the Philippine financial system." With Agence France-Presse
Osmena: Political will needed to plug laundering loopholes
source: www.abs-cbnnews.com
Tuesday, March 15, 2016
Chinese hackers behind U.S. ransomware attacks - security firms
Hackers using tactics and tools previously associated with Chinese government-supported computer network intrusions have joined the booming cyber crime industry of ransomware, four security firms that investigated attacks on U.S. companies said.
Ransomware, which involves encrypting a target's computer files and then demanding payment to unlock them, has generally been considered the domain of run-of-the-mill cyber criminals.
But executives of the security firms have seen a level of sophistication in at least a half dozen cases over the last three months akin to those used in state-sponsored attacks, including techniques to gain entry and move around the networks, as well as the software used to manage intrusions.
"It is obviously a group of skilled of operators that have some amount of experience conducting intrusions," said Phil Burdette, who heads an incident response team at Dell SecureWorks.
Burdette said his team was called in on three cases in as many months where hackers spread ransomware after exploiting known vulnerabilities in application servers. From there, the hackers tricked more than 100 computers in each of the companies into installing the malicious programs.
The victims included a transportation company and a technology firm that had 30 percent of its machines captured.
Security firms Attack Research, InGuardians and G-C Partners, said they had separately investigated three other similar ransomware attacks since December.
Although they cannot be positive, the companies concluded that all were the work of a known advanced threat group from China, Attack Research Chief Executive Val Smith told Reuters.
The ransomware attacks have not previously been reported. None of the companies that were victims of the hackers agreed to be identified publicly.
The security companies investigating the advanced ransomware intrusions have various theories about what is behind them, but they do not have proof and they have not come to any firm conclusions.
Most of the theories flow from the possibility that the Chinese government has reduced its support for economic espionage, which it pledged to oppose in an agreement with the United States late last year. Some U.S. companies have reported a decline in Chinese hacking since the agreement.
Smith said some government hackers or contractors could be out of work or with reduced work and looking to supplement their income via ransomware.
It is also possible, Burdette said, that companies which had been penetrated for trade secrets or other reasons in the past were now being abandoned as China backs away, and that spies or their associates were taking as much as they could on the way out. In one of Dell's cases, the means of access by the team spreading ransomware was established in 2013.
The cyber security experts could not completely rule out more prosaic explanations, such as the possibility that ordinary criminals had improved their skills and bought tools previously used only by governments.
Dell said that some of the malicious software had been associated by other security firms with a group dubbed Codoso, which has a record of years of attacks of interest to the Chinese government, including those on U.S. defense companies and sites that draw Chinese minorities.
PAYMENT IN BITCOIN
Ransomware has been around for years, spread by some of the same people that previously installed fake antivirus programs on home computers and badgered the victims into paying to remove imaginary threats.
In the past two years, better encryption techniques have often made it impossible for victims to regain access to their files without cooperation from the hackers. Many ransomware payments are made in the virtual currency Bitcoin and remain secret, but institutions including a Los Angeles hospital have gone public about ransomware attacks.
Ransomware operators generally set modest prices that many victims are willing to pay, and they usually do decrypt the files, which ensures that victims will post positively online about the transaction, making the next victims who research their predicament more willing to pay.
Security software companies have warned that because the aggregate payoffs for ransomware gangs are increasing, more criminals will shift to it from credit card theft and other complicated scams.
The involvement of more sophisticated hackers also promises to intensify the threat.
InGuardians CEO Jimmy Alderson said one of the cases his company investigated appeared to have been launched with online credentials stolen six months earlier in a suspected espionage hack of the sort typically called an Advanced Persistent Threat, or APT.
"The tactics of getting access to these networks are APT tactics, but instead of going further in to sit and listen stealthily, they are used for smash-and-grab," Alderson said.
source: www.abs-cbnnews.com
Subscribe to:
Posts (Atom)







