Money
Hackers’ US$81m sneak attack on world banking
Hacking is a big security concern with a Russian gang reportedly making off with a staggering 1.2 billion passwords. u00e2u20acu201d Reuters pic

NEW YORK, May 1 — Tens of millions of dollars siphoned from the Federal Reserve Bank of New York. A shadowy set of casinos in the Philippines. A large bank in Bangladesh with creaky technology. An unknown — and perhaps uncatchable — group of anonymous thieves with sophisticated hacking skills.

What unites this curious cast of characters and enabled one of the most brazen digital bank heists ever is a ubiquitous and highly trusted international bank messaging system called SWIFT.

SWIFT — the Society for Worldwide Interbank Financial Telecommunication — is billed as a super-secure system that banks use to authorise payments from one account to another. “The Rolls-Royce of payments networks,” one financial analyst said.

But last week, for the first time since hackers captured US$81 million (RM317 million) from Bangladesh’s central bank in February, SWIFT acknowledged that the thieves have tried to carry out similar heists at other banks on its network by sneaking into the beating heart of the global banking system.

“There are many banks out there right now saying, ‘There but for the grace of God go us,’” said Gareth Lodge, a payments analyst at Celent, a financial consulting firm.

The admission that the attack was not a one-time event in a developing country but perhaps part of a broader threat has thrust SWIFT into a spotlight, raising questions about how securely money is being moved around the world. Some financial security experts point out the SWIFT system is only as safe as its weakest link.

The attack also reflects a growing sophistication among digital criminals, who for years have been breaching personal bank accounts and stealing credit card credentials. The thieves in Bangladesh may have spent months lurking inside the central bank’s computers, studying how to steal the necessary credentials to gain access to SWIFT.

It is the digital version of the heist depicted in the movie Ocean’s Eleven, said Adrian Nish, head of the cyberthreat intelligence team at BAE Systems, a defence and security company.

“The trend is moving from opportunistic crime to Hollywood-scale attacks,” said Nish, whose firm has analysed the malware believed to have been used in the Bangladesh breach.

In the United States, most banks take special precautions with their SWIFT computers, building multiple firewalls to isolate the system from the bank’s other networks and keeping the machines physically isolated in a separate locked room.

But elsewhere, some banks take far fewer precautions. And security experts who have analysed the SWIFT breach said they had concluded that the Bangladesh bank may have been particularly vulnerable to an attack.

“SWIFT is a great organisation,” said Chris Larsen, the founder of Ripple, a financial technology company that aims to speed up global money transmissions. “But the system is fractured and antiquated. The way it is set up, you cannot totally isolate problems in a place like Bangladesh from the whole network.”


About half of the data breaches at financial institutions are made via the institutions’ web applications, according to Verizon’s 2016 Data Breach Investigations Report. — Graphic by The New York Times

SWIFT’s growth in recent years — it set a record for messages in March — reflects the increasingly global and interconnected nature of finance. But it also shows the risk of so many financial instructions running through a single system made up of a patchwork of banks and companies with varying levels of online protection.

Each bank on the SWIFT network is identified by a set of codes. And it was the codes assigned to the Bank of Bangladesh that were recognised — correctly — by the Federal Reserve Bank of New York when it transferred US$81 million of the Bangladesh bank’s money to the Philippines, not knowing that someone, somewhere, had stolen the credentials of the Bangladesh bank and installed malware to cover his or her tracks.

Initially, the thieves requested the transfer of US$951 million into a handful of bank accounts in Sri Lanka and the Philippines — a number that prompted the New York Fed to ask the Bangladesh bank to reconfirm that it indeed wanted to move the money.

In the end, the Fed processed only five of the 35 fraudulent payment requests, after it could not reconfirm with officials in Bangladesh.

The hackers seemed to time the attack perfectly: When officials from the Fed tried to reach out to Bangladesh, it was a weekend there and no one was working. By the time central bankers in Bangladesh discovered the fraud, it was the weekend in New York and the Fed offices were closed.

To conceal the crime, the malware disabled a printer in the Bangladesh bank to prevent officials from reviewing a log of the fraudulent transfers.

The money was transferred to accounts in the Philippines and then into the Philippine casino system, which is exempt from many of the country’s anti-money-laundering requirements.

The New York Fed has been criticised for letting the US$81 million slip out. Rep. Carolyn B. Maloney, D-NY and member of the Financial Services Committee, has called for an investigation, warning that the breach “threatens to undermine the confidence that foreign central banks have in the Federal Reserve, and in the safety and soundness of international monetary transactions.”

The New York Fed said in a statement that “there is no evidence that any Fed systems were compromised” and that the transfer of the money had been “fully authenticated” by SWIFT. — The New York Times

Related Articles

 

You May Also Like