Showing posts with label New York Federal Reserve Bank. Show all posts
Showing posts with label New York Federal Reserve Bank. Show all posts
Wednesday, February 13, 2019
US household debt in 2018 jumps $400 bn
Total debt held by US households surged by nearly $400 billion in 2018 to more than $13.5 trillion, marking the sixth straight annual increase, even as home mortgages declined, according to data released Tuesday.
That puts total debt $869 billion higher than the previous peak, just before the start of the global financial crisis in late 2008, the New York Federal Reserve Bank said in its quarterly report.
A decade after the crisis, mortgage debt increased $242 billion to $9.1 trillion, but new home loans originated last year fell $131 billion to the lowest point in four years, the data showed.
But auto loans and student debt continued to rise.
"Auto loan originations for 2018 reached an all-time high," said Joelle Scally, Administrator of the Center for Microeconomic Data at the New York Fed.
Auto loans jumped $53 billion to $1.3 trillion -- the highest in the 19-year history of the data -- and despite a rise in loans going to more creditworthy borrower "its performance has been slowly worsening."
"Growing delinquencies among subprime borrowers are responsible for this deteriorating performance and younger borrowers are struggling most acutely to afford their auto loans," Scally said in a statement.
Student debt jumped $79 billion compared to 2017, to $1.5 trillion, according to the report.
Many economists see the rising student debt burden crimping the economy, preventing college graduates from buying homes.
Credit card debt also jumped $36 billion in the year and, though it has yet to break the $1 trillion level, it was the first time it hit the 2008 peak, the report said.
Delinquency rates for debt more than 90 days past due worsened for credit cards and auto loans but was about flat for mortgages and student debt.
source: news.abs-cbn.com
Friday, May 13, 2016
SWIFT says second bank hit by malware attack
SWIFT, the global financial messaging network that banks use to move billions of dollars every day, warned on Thursday of a second malware attack similar to the one that led to February's $81 million cyber heist at the Bangladesh central bank.
The second case targeted a commercial bank, SWIFT spokeswoman Natasha de Teran said, without naming it. It was not immediately clear how much money, if any, was stolen in the second attack.
While SWIFT had previously warned that the Bangladesh heist was not an isolated incident, and said its core messaging system remained intact, confirmation of a second attack on a bank will likely increase scrutiny on the security of a network that is a linchpin of the global financial system.
SWIFT said in a statement that the attackers exhibited a "deep and sophisticated knowledge of specific operational controls" at targeted banks and may have been aided by "malicious insiders or cyber attacks, or a combination of both."
The organization, a Belgian co-operative owned by member banks and used by 11,000 financial institutions globally, said that forensic experts believe the second case showed that the Bangladesh heist "was not a single occurrence, but part of a wider and highly adaptive campaign targeting banks."
News of a second case comes as authorities in Bangladesh and elsewhere investigate the February cyber theft from the Bangladesh central bank account at the New York Federal Reserve Bank. SWIFT has acknowledged that that scheme involved altering SWIFT software to hide evidence of fraudulent transfers, but that the messaging system it controls was not compromised.
In both cases SWIFT said insiders or cyber attackers had succeeded in penetrating the targeted banks' systems, obtaining user credentials and submitting fraudulent SWIFT messages that correspond with transfers of money.
In the second case SWIFT said attackers had also used a kind of malware called a "Trojan PDF reader" to manipulate PDF reports confirming the messages in order to hide their tracks.
source: www.abs-cbnnews.com
Tuesday, April 26, 2016
SWIFT network says aware of multiple cyber fraud incidents
SWIFT, the global financial network that banks use to transfer billions of dollars every day, warned its customers on Monday that it was aware of "a number of recent cyber incidents" where attackers had sent fraudulent messages over its system.
The disclosure came as law enforcement authorities in Bangladesh and elsewhere investigated the February cyber theft of $81 million from the Bangladesh central bank account at the New York Federal Reserve Bank. SWIFT has acknowledged that the scheme involved altering SWIFT software on Bangladesh Bank's computers to hide evidence of fraudulent transfers.
Monday's statement from SWIFT marked the first acknowledgement that the Bangladesh Bank attack was not an isolated incident but one of several recent criminal schemes that aimed to take advantage of the global messaging platform used by some 11,000 financial institutions.
"SWIFT is aware of a number of recent cyber incidents in which malicious insiders or external attackers have managed to submit SWIFT messages from financial institutions' back-offices, PCs or workstations connected to their local interface to the SWIFT network," the group warned customers on Monday in a notice seen by Reuters.
The warning, which SWIFT issued in a confidential alert sent over its network, did not name any victims or disclose the value of any losses from the previously undisclosed attacks. SWIFT confirmed to Reuters the authenticity of the notice.
SWIFT, or the Society for Worldwide Interbank Financial Telecommunication, is a cooperative owned by 3,000 financial institutions.
Also on Monday, SWIFT released a security update to the software that banks use to access its network to thwart malware that security researchers with British defense contractor BAE Systems said was probably used by hackers in the Bangladesh Bank heist.
BAE's evidence suggested that hackers manipulated SWIFT's Alliance Access server software, which banks use to interface with SWIFT's messaging platform, to cover their tracks.
BAE said it could not explain how the fraudulent orders were created and pushed through the system.
But SWIFT provided some evidence about how that happened in its note to customers, saying that in most cases the modus operandi was similar.
It said the attackers obtained valid credentials for operators authorized to create and approve SWIFT messages, then submitted fraudulent messages by impersonating those people.
FireEye, the internet security company whose Mandiant unit was hired by Bangladesh Bank to help investigate the heist, said the same group behind that hack had probably attacked other financial targets.
"FireEye has observed activity in other financial services organizations that is likely by the same threat actor behind the cyber attack on the Bank of Bangladesh," Vivek Chudgar, Mandiant's senior director for the Asia Pacific said in a statement emailed to Reuters.
FireEye declined to go into detail.
Rakesh Asthana, the World Informatix Cyber Security CEO, who is overseeing Bangladesh Bank's probe into the hack, declined to discuss the other attacks that SWIFT referred to.
But he urged banks to conduct independent security assessments to make sure their networks are secure and prevent future attacks.
“SWIFT builds on security practices established by the customer itself and therefore it is imperative that in the wake of this attack, customers using SWIFT Alliance Access must strengthen their cyber security posture,” Asthana said
FOLLOWING THE MONEY
Cyber security experts said more attacks could surface as SWIFT's banking clients look to see if their SWIFT access has been compromised.
Shane Shook, a banking security consultant who investigates large financial crime, said hackers were turning to SWIFT and other private financial messaging platforms because such attacks can generate more revenue than going after consumers or small businesses.
"These hacks specifically target financial institutions because smaller efforts result in much larger thefts," he said. "It's much more efficient than stealing from consumers."
Justin Harvey, chief security officer with Fidelis Cybersecurity, said hackers followed the money and would be drawn into such schemes in hopes of emulating a big heist like the one on Bangladesh Bank.
"After the Bangladesh Bank heist became public, every other attacker out there is looking to see if they can do the same," he said.
SWIFT spokeswoman Natasha Deteran told Reuters that the commonality in these cases was that internal or external attackers compromised the banks’ own environments to obtain valid operator credentials.
"Customers should do their utmost to protect against this," she said in an email to Reuters.
SWIFT told customers that the security update must be installed by May 12.
"We have made the Alliance interface software update mandatory as it is designed to help banks identify situations in which attackers have attempted to hide their traces - whether these actions have been executed manually or through malware," she said.
source: www.abs-cbnnews.com
Subscribe to:
Posts (Atom)


