UPDATED 10:21 EDT / JUNE 27 2012

NEWS

75 Million Dollar Cyber Bank Robbery

Breaking this morning from Sky News is a report that a massive cyber fraud scheme has been uncovered on over 60 banking institutions around the world.  The scheme has pilfered an estimated 75 million dollars from a number of high balance accounts from the various institutions.  Automated software has infiltrated server systems and utilized a system of mule accounts in staged events.   Apparently the system was enabled by “an insider level of understanding” and was able to avert detection methods built in place for suspicious actions.  The attack is suspected to be infiltrating North and South American banking institutions.

The study by McAfee and Guardian Analytics traces many of the source servers used in the attack back to Russia.  These attacks are reportedly still continuing today.   As the video states, it is being reported as the biggest cyber bank robbery in history.   Having started in Italy, it has spread throughout European institutions, targeting corporate bank accounts in a sophisticated and reportedly ongoing operation.  Loading hacker tools known as Zeus and SpyEye, the attack has been utilizing servers worldwide, switching its points of attack to avoid detection.  Much of the discovery of this scheme has been uncovered through forensic evidence from log files, which is telling of the ongoing sophistication and difficulty of detection of the ongoing attacks.

The report comes on the heels of a warning from the head of MI5 on the “astonishing” amount of cyber espionage, particularly from nation states.   In that warning, there was reference to threats to the financial sector.

The attack raises questions of practice in security.  Beyond technical means, there are a number of significant practice elements that factor in to the present and future of securing financial institutions.  Managing administrative access is a factor that is constantly in focus.  That means tiered access to systems, accounts, design and so on.  It also encompasses lifecycle management of accounts and passwords in addition to ongoing auditing and technical control of access.

 


Since you’re here …

… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.

If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.