Showing posts with label SWIFT Interbank. Show all posts
Showing posts with label SWIFT Interbank. Show all posts

Monday, December 12, 2016

SWIFT confirms new cyber thefts, hacking tactics


LONDON/BOSTON - Cyber attacks on the global banking system have continued - and succeeded - since February’s heist of $81 million from the Bangladesh central bank, underscoring the continuing vulnerability of the SWIFT messaging network, a SWIFT official told Reuters.

The network, which handles trillions of dollars in transfers daily, has warned banks of the escalating threat to their systems, according to a SWIFT letter obtained by Reuters.

"The threat is very persistent, adaptive and sophisticated – and it is here to stay," SWIFT said last month in a letter to client banks, which has not been previously reported.

Client banks been have been hit with a "meaningful" number of attacks - about a fifth of them resulting in stolen funds, said Stephen Gilderdale, Head of SWIFT’s Customer Security Programme. Gilderdale's comments are the first confirmation of new thefts involving the SWIFT network since the February heist.

The revelations provide fresh evidence that SWIFT remains at risk of copycat attacks nearly a year after the massive theft from a Bangladesh Bank account at the New York Fed. The unprecedented cyber heist prompted regulators around the globe to tighten bank security requirements.

SWIFT'S letter to customers warned that hackers have refined their methods for compromising local bank systems. One new tactic, the letter said, involved using software that allows technicians to access computers to provide technical support.

"We unfortunately continue to see cases in which some of our customers’ environments are being compromised" by thieves who then send fraudulent payment instructions through the SWIFT network - the same kind of messages used to steal Bangladesh Bank funds.

On Monday, a top investigator in Dhaka told Reuters that some Bangladesh central bank officials deliberately exposed its computer systems and enabled the theft. The comments by Mohammad Shah Alam of the Dhaka police are the first sign that investigators have got a firm lead in one of the world's biggest cyber heists. Arrests are likely soon, he said.

SWIFT's Gilderdale declined to provide further details about more recent attacks or to name victims or amounts stolen. Asked how many heists had been attempted, he said only that it was "a meaningful number of cases.”

The intrusions had been detected in a variety of ways, Gilderdale said. In some cases, anti-virus software had identified malware. In one case, a financial supervisory body had notified SWIFT of an attempted attack.

The additional attacks SWIFT disclosed to Reuters do not include others that have already come to light since the Bangladesh Bank heist.

Thieves stole $250,000 from Bangladesh's Sonali bank in 2013. More than $12 million was stolen from Ecuador's Banco del Austro in 2015. Vietnam's Tien Phong Bank said in May that it foiled an attempt to steal money via SWIFT.

(Reporting by Tom Bergin and Jim Finkle; Editing by Brian Thevenot)

source: news.abs-cbn.com

Friday, May 20, 2016

Cyber thieves exploit banks' faith in SWIFT transfer network


LONDON/CHICAGO - Shortly after 7 p.m. on January 12, 2015, a message from a secure computer terminal at Banco del Austro (BDA) in Ecuador instructed San Francisco-based Wells Fargo to transfer money to bank accounts in Hong Kong.

Wells Fargo complied. Over 10 days, Wells approved a total of at least 12 transfers of BDA funds requested over the secure SWIFT system.

The SWIFT network - which allows banks to process billions of dollars in transfers each day - is considered the backbone of international banking. In all, Wells Fargo transferred $12 million of BDA's money to accounts across the globe.

Both banks now believe those funds were stolen by unidentified hackers, according to documents in a BDA lawsuit filed against Wells Fargo in New York this year. The two banks declined requests for comment from Reuters.

BDA is suing Wells Fargo on the basis that the U.S. bank should have flagged the transactions as suspicious.

Wells Fargo has countered that security lapses in BDA's own operations caused the Ecuadorean bank's losses. Hackers had secured a BDA employee's SWIFT logon credentials, Wells Fargo said in a February court filing.

SWIFT, an acronym for the Society for Worldwide Interbank Financial Telecommunication, is not a party to the lawsuit.

Neither bank reported the theft to SWIFT, which said it first learned about the cyber attack from a Reuters inquiry.

"We were not aware," SWIFT said in a statement responding to Reuters inquiries. "We need to be informed by customers of such frauds if they relate to our products and services, so that we can inform and support the wider community. We have been in touch with the bank concerned to get more information, and are reminding customers of their obligations to share such information with us."

SWIFT says it requires customer to notify SWIFT of problems that can affect the "confidentiality, integrity, or availability of SWIFT service."

SWIFT, however, has no rule specifically requiring client banks to report hacking thefts. Banks often do not report such attacks out of concern they make the institution appear vulnerable, former SWIFT employees and cyber security experts told Reuters.

The Ecuador case illuminates a central problem with preventing such fraudulent transfers: Neither SWIFT nor its client banks have a full picture of the frequency or the details of cyber thefts made through the network, according to more than dozen former SWIFT executives, users and cyber security experts interviewed by Reuters.

The case - details of which have not been previously reported - raises new questions about the oversight of the SWIFT network and its communications with member banks about cyber thefts and risks. The network has faced intense scrutiny since cyber thieves stole $81 million in February from a Bangladesh central bank account at the Federal Reserve Bank of New York.

It's unclear what SWIFT tells its member banks when it does find out about cyber thefts, which are typically first discovered by the bank that has been defrauded. SWIFT spokeswoman Natasha de TerĂ¡n said that the organization "was transparent with its users" but declined to elaborate. SWIFT declined to answer specific questions about its policies for disclosing breaches.

Reuters was unable to determine the number or frequency of cyber attacks involving the SWIFT system, or how often the banks report them to SWIFT officials.

The lack of disclosure may foster overconfidence in SWIFT network security by banks, which routinely approve transfer requests made through the messaging network without additional verification, former SWIFT employees and cyber security experts said.

The criminals behind such heists are exploiting banks' willingness to approve SWIFT requests at face value, rather than making additional manual or automated checks, said John Doyle, who held a variety of senior roles at SWIFT between 1980 and 2005.

"SWIFT doesn't replace prudent banking practice" he said, noting that banks should verify the authenticity of withdrawal or transfer requests, as they would for money transfers outside the SWIFT system.

SWIFT commits to checking the codes on messages sent into its system, to ensure the message has originated from a client's terminal, and to send it to the intended recipient quickly and securely, former SWIFT executives and cyber security experts said. But once cyber-thieves obtain legitimate codes and credentials, they said, SWIFT has no way of knowing they are not the true account holders.

The Bank for International Settlements, a trade body for central banks, said in a November report that increased information sharing on cyber attacks is crucial to helping financial institutions manage the risk.

"The more they share the better," said Leo Taddeo, chief security officer at Cryptzone and a former special agent in charge with the FBI's cyber crime division in New York.

SYSTEMIC RISK

SWIFT, a cooperative owned and governed by representatives of the banks it serves, was founded in 1973 and operates a secure messaging network that has been considered reliable for four decades. But recent attacks involving the Belgium-based cooperative have underscored how the network's central role in global finance also presents systemic risk.

SWIFT is not regulated, but a group of ten central banks from developed nations, led by the National Bank of Belgium, oversee the organization. Among its stated guidelines is a requirement to provide clients with enough information to enable them "to manage adequately the risks related to their use of SWIFT."

However, some former SWIFT employees said that the cooperative struggles to keep banks informed on risks of cyber fraud because of a lack of cooperation from the banks themselves. SWIFT's 25-member board of directors is filled with representatives of larger banks.

"The banks are not going to tell us too much," said Doyle, the former SWIFT executive. "They wouldn't like to destabilize confidence in their institution."

Banks also fear notifying SWIFT or law enforcement of security breaches because that could lead to regulatory investigations that highlight failures of risk management or compliance that could embarrass top managers, said Hugh Cumberland, a former SWIFT marketing executive who is now a senior associate with cyber security firm Post-Quantum.

Cases of unauthorized money transfers rarely become public, in part because disagreements are usually settled bilaterally or through arbitration, which is typically private, said Salvatore Scanio, a lawyer at Washington, D.C.-based Ludwig & Robinson. Scanio said he consulted on a dispute involving millions of dollars of stolen funds and the sending of fraudulent SWIFT messages similar to the BDA attack. He declined to name the parties or provide other details.

Theoretically, SWIFT could require its customers, mainly banks, to inform it of any attacks - given that no bank could risk the threat of exclusion from the network, said Lieven Lambrecht, the head of human resources at SWIFT for a year-and-a-half through May 2015.

But such a rule would require the agreement of its board, which is mainly made up of senior executives from the back office divisions of the largest western banks, who would be unlikely to approve such a policy, Lambrecht said.

FIGHT OVER LIABILITY

This week, Vietnam's Tien Phong Bank said its SWIFT account, too, was used in an attempted hack last year. That effort failed, but it is another sign that cyber-criminals are increasingly targeting the messaging network.

In the Ecuadorean case, Wells Fargo denies any liability for the fraudulent transfers from BDA accounts. Wells Fargo said in court records that it did not verify the authenticity of the BDA transfer requests because they came through SWIFT, which Wells called "among the most widely used and secure" systems for money transfers.

BDA is seeking recovery of the money, plus interest. Wells Fargo is attempting to have the case thrown out.

New York-based Citibank also transferred $1.8 million in response to fraudulent requests made through BDA's SWIFT terminal, according to the BDA lawsuit against Wells Fargo.

Citibank repaid the $1.8 million to BDA, according to a BDA court filing in April. Citibank did not respond to a request for comment.

For its part, Wells Fargo refunded to BDA $958,700 out of the $1,486,230 it transferred to an account in the name of a Jose Mariano Castillo at Wells Fargo in Los Angeles, according to the lawsuit. Reuters could not locate Castillo or verify his existence.

ANATOMY OF A CYBER HEIST


The BDA-Wells Fargo case is unusual in that one bank took its correspondent bank to court, thus making the details public, said Scanio, the Washington attorney. BDA acknowledged in a January court filing that it took more than a week after the first fraudulent transfer request for BDA to discover the missing money.

After obtaining a BDA employee's SWIFT logon, the thieves then fished out previously canceled or rejected payment requests that remained in BDA's SWIFT outbox.

They then altered the amounts and destinations on the transfer requests and reissued them, both banks said in filings.

While Wells Fargo has claimed in court filings that failures of security at BDA are to blame for the breach, BDA has alleged that Wells could easily have spotted and rejected the unusual transfers. BDA noted that the payment requests were made outside of its normal business hours and involved unusually large amounts.

The BDA theft and others underscore the need for banks on both sides of such transactions - often for massive sums - to rely less on SWIFT for security and strengthen their own verification protocols, Cumberland said.

"This image of the SWIFT network and the surrounding ecosystem being secure and impenetrable has encouraged complacency," he said. (Additional reporting by Jim Finkle in Boston and Alexandra Valencia in Quito; Editing by David Greising and Brian Thevenot)

source: www.abs-cbnnews.com

Thursday, March 17, 2016

Faulty printer implicated in $81-M bank heist


DHAKA, Bangladesh - A printer fault at Bangladesh's central bank meant that overseas queries about suspicious transactions went unanswered, according to a report seen by AFP Wednesday on the $81 million cyber heist that sent shockwaves through the banking world.

The report, filed to police on Tuesday, recounts the events leading to the discovery of the dramatic theft from an overseas account of Bangladesh Bank.

It says that because of a printer and software problem, it took the Bangladesh central bank nearly four days to ask banks across the globe to halt payments to the hackers.

They tried to steal around $1 billion and got away with $81 million from the impoverished country's coffers.

How a hacker's typo helped stop a billion dollar bank heist

Central bank governor Atiur Rahman and two of the deputy governors have lost their jobs over the scandal, which has hugely embarrassed the government and raised alarm over the security of the country's foreign exchange reserves of over $27 billion.

On Wednesday the government, which has said it was kept in the dark about the losses for weeks, also removed its most senior banking official M. Aslam Alam from his position.

The hackers managed to transfer $81 million on February 5 -- a Friday, when Bangladesh Bank is closed -- from its account with the Federal Reserve Bank of New York, transferring the cash electronically to accounts in the Philippines.

In the report seen by AFP, the bank's joint director Zubair bin Huda said engineers were unable to fix the printers until February 6, a day after the New York bank sent queries about four separate transactions.

"Since such glitches happened before, we thought it was a common problem just like any other day," Huda said in the report.

Bangladesh Bank tried to contact New York on February 6 by email, fax and phone to ask that the transactions be suspended when it realized that the SWIFT interbank messaging system which it normally used was not working properly, Huda said.

"We realized that the SWIFT system being ineffective was an important issue, and therefore we sent an email to Federal Reserve Bank of New York at 1:30pm on February 6 to halt all types of payment processing," he said.

But they were unable to get through as the US bank was closed for the weekend.

It was not until Monday afternoon that the central bank's main server was again working properly and officials were able to send the formal requests to stop the payments to six banks across the globe.

But by that time $81 million had been transferred from Bangladesh Bank's New York account to a bank in the Philippines.

PHILIPPINES ACCOUNT

The money was later transferred to an account belonging to ethnic Chinese businessman William So Go, a Philippine Senate committee heard this week.

The money was then transferred to Philippine casinos, Julia Bacay-Abad from the Philippines' anti-money laundering council told the hearing on Tuesday.

Go's lawyer said the businessman's signatures for his now-frozen RCBC account, which were used to transfer the money, had been forged.

'Money trail in laundering scam ends with casinos'

Casino junket operator got $30-M in cash

Another transfer of $20 million was halted by a bank in Sri Lanka at Bangladesh Bank's request.

As details of the scandal emerged last week, Bangladesh Finance Minister A.M.A. Muhith threatened to sue the New York Fed.

The US-based bank said in a statement on its website that the payment instructions "were fully authenticated by the SWIFT messaging system in accordance with standard authentication protocols".

LACK OF TRANSPARENCY

Meanwhile, the $81 million heist has also put a spotlight on the Philippines' strict bank secrecy law. Finance Secretary Cesar Purisima earlier said the Philippines along with Lebanon are some of the only countries in the world left with a bank secrecy law.

Even Switzeland, which is known for its strict banking system, has been open to relax the law.

PH one of few countries with bank secrecy law

According to a law enacted in 1955, all bank deposits in the Philippines are absolutely confidential and may not be examined "except upon written permission of the depositor, or in cases of impeachment, or upon order of a competent court in cases of bribery or dereliction of duty of public officials, or in cases where the money deposited or invested is the subject matter of the litigation."

Last year, Internal Revenue Commissioner Kim Henares said the government is preparing a draft bill that would lift or ease the bank secrecy law to strengthen government's tax collection efforts. Congress, however, thumbed it down.

Makati Business Club chairman Ramon del Rosario said he found it "uncomfortable" that the bank secrecy law was invoked during the Senate investigation on the $81 million heist.

Senator Sergio Osmena III said the international financial community has already taken notice of loopholes in Philippine laws.

"As far as I am concerned, sunlight is the best medicine. Transparency in a democratic setting is the best safeguard against corruption and against bad public officials," he said.

“Despite all the warnings from the FATF (Financial Action Task Force), we still don’t have the political will to plug those loopholes. I hope that this will teach us a lesson because the international financial community has just taken notice of how big our loopholes are and it’s become an international incident because [81 million] dollars was hacked from the account of Bangladesh Central Bank and laundered through the Philippine financial system." With Agence France-Presse

Osmena: Political will needed to plug laundering loopholes

source: www.abs-cbnnews.com