Symantec Says SWIFT Malware Is Linked to Cyber Attack in the Philippines
by Reuters MAY 26, 2016, 2:08 PM EDT
Symantec suggests recent success could prompt more attacks
The malware that was used to steal $81 million from Bangladesh’s central bank has been linked to another cyber attack, this time on a bank in the Philippines, cyber security company Symantec said in a blog post on Thursday.
The company said it had identified three pieces of malware that were used in limited targeted attacks against financial institutions in South-East Asia.
The initial success of the group that attacked the Bangladesh Central Bank and the Philippines bank could prompt more attacks, Symantec SYMC -0.23% said in the post.
In February, thieves hacked into the Society for Worldwide Interbank Financial Telecommunication (SWIFT) payments system of the Bangladesh central bank, sending messages to the Federal Reserve Bank of New York allowing them to steal $81 million.
The emergence of new possible instances of compromise is not entirely surprising as banks conduct more reviews, SWIFT spokeswoman Natasha de Teran told Reuters.
“Many may turn out to be false positives, and or have nothing to do with SWIFT messages, but it is key that these reviews take place and banks’ environments are secured,” she added.
- wong chee tat :)
Showing posts with label swift. Show all posts
Showing posts with label swift. Show all posts
Monday, May 30, 2016
Friday, May 20, 2016
No impact on SWIFT network, core messaging services or software
No impact on SWIFT network, core messaging services or software
Brussels 13 May 2016 – SWIFT
SWIFT has issued a notice to all its customers about a newly identified malware found in a customer’s environment. The notice is set out below:
Dear SWIFT User,
As we notified you in our earlier communications, we are aware of a small number of recent cases of fraud at customer firms. First and foremost we would like to reassure you again that the SWIFT network, core messaging services and software have not been compromised. We have however now learnt more about a second instance in which malware was used – again directed at banks’ secondary controls, but which in this instance targets a PDF Reader used by the customer to check its statement messages.
Forensic experts believe this new discovery evidences that the malware used in the earlier reported customer incident was not a single occurrence, but part of a wider and highly adaptive campaign targeting banks.
In both instances, the attackers have exploited vulnerabilities in banks funds’ transfer initiation environments, prior to messages being sent over SWIFT. The attackers have been able to bypass whatever primary risk controls the victims have in place, thereby being able to initiate the irrevocable funds transfer process. In a second step, they have found ways to tamper with the statements and confirmations that banks would sometimes use as secondary controls, thereby delaying the victims’ ability to recognise the fraud.
The attackers clearly exhibit a deep and sophisticated knowledge of specific operational controls within the targeted banks – knowledge that may have been gained from malicious insiders or cyber attacks, or a combination of both.
Preventative Controls
As a matter of urgency we remind all customers again to urgently review controls in their payments environments, to all their messaging, payments and ebanking channels. This includes everything from employee checks to password protection to cyber defences. We recommend that customers consider third party assurance reviews and, where necessary, ask your correspondent banks and service bureaux to work with you on enhanced arrangements.
We also urge all customers to be forthcoming when these issues occur so that the fraudsters can be tracked by the authorities, and SWIFT can inform the rest of community about any findings that may have a bearing on wider security issues.
In the meantime we would like to reassure you that the SWIFT network, SWIFT messaging systems and software have not been compromised. The security and integrity of our messaging services are not in question as a result of the incidents. We will continue with our security awareness campaign, bilaterally with users and through industry forums and other appropriate channels. We will also continue working with our overseers, with law enforcement agencies, and third party experts, and we will continue to inform you of any further information we believe that can help you detect or avert such attacks.
Latest Findings
In the earlier case we reported to you, and this particular case we can confirm that: malicious insiders or external attackers have managed to submit SWIFT messages from financial institutions’ back-offices, PCs or workstations connected to their local interface to the SWIFT network. The modus operandi of the attackers is similar in both cases:
1. Attackers compromise the bank’s environment
2. Attackers obtain valid operator credentials that have the authority to create, approve and submit SWIFT messages from customers’ back-offices or from their local interfaces to the SWIFT network.
3. Attackers submit fraudulent messages by impersonating the operators from whom they stole the credentials.
4. Attackers hide evidence by removing some of the traces of the fraudulent messages.
In this new case we have now learnt that a piece of malware was used to target the PDF reader application used by the customer to read user generated PDF reports of payment confirmations. The main purpose of the malware is again to manipulate an affected customer’s local records of SWIFT messages – i.e. step 4 in the above modus operandi.
Once installed on an infected local machine, the Trojan PDF reader gains an icon and file description that matches legitimate software. When opening PDF files containing local reports of customer specific SWIFT confirmation messages, the Trojan will manipulate the PDF reports to remove traces of the fraudulent instructions.
There is no evidence that the malware creates or injects new messages or alters the content of legitimate outgoing messages. This malware only targets the PDF reader in affected institutions’ local environments and has no impact on SWIFT’s network, interface software or core messaging services.
Customers that use PDF reader applications to check their confirmation messages should take particular care.
Your Security
As we stated earlier, this is clearly a highly adaptive campaign targeting banks’ payment endpoints. Above all therefore your first priority should be to ensure that you have all preventative and detective measures in place to secure your environment. This latest evidence adds further urgency to this work. Such measures are the best defence against such malware being installed on your local systems, and against fraudulent actions on your local infrastructure to connect to the SWIFT network.
Please remember that as a SWIFT user you are responsible for the security of your own systems interfacing with the SWIFT network and your related environment – starting with basic password protection practices – in much the same way as you are responsible for your other security considerations. Whilst we issue, and have recently reminded you about, security best practice recommendations, these are just a baseline and general advice.
We will continue to update you on these issues as more information becomes available to us. We would ask you to ensure that these communications reach your security officers.
About SWIFT
SWIFT is a global member-owned cooperative and the world’s leading provider of secure financial messaging services.
We provide our community with a platform for messaging and standards for communicating, and we offer products and services to facilitate access and integration, identification, analysis and financial crime compliance.
Our messaging platform, products and services connect more than 11,000 banking and securities organisations, market infrastructures and corporate customers in more than 200 countries and territories, enabling them to communicate securely and exchange standardised financial messages in a reliable way. As their trusted provider, we facilitate global and local financial flows, support trade and commerce all around the world; we relentlessly pursue operational excellence and continually seek ways to lower costs, reduce risks and eliminate operational inefficiencies.
Headquartered in Belgium, SWIFT’s international governance and oversight reinforces the neutral, global character of its cooperative structure. SWIFT’s global office network ensures an active presence in all the major financial centres.
For more information, visit www.swift.com or follow us on Twitter: @swiftcommunity and LinkedIn: SWIFT
Contacts:
Brunswick Group LLP
swift@brunswickgroup.com
Tel: +44 (0)20 7404 5959
- wong chee tat :)
Brussels 13 May 2016 – SWIFT
SWIFT has issued a notice to all its customers about a newly identified malware found in a customer’s environment. The notice is set out below:
Dear SWIFT User,
As we notified you in our earlier communications, we are aware of a small number of recent cases of fraud at customer firms. First and foremost we would like to reassure you again that the SWIFT network, core messaging services and software have not been compromised. We have however now learnt more about a second instance in which malware was used – again directed at banks’ secondary controls, but which in this instance targets a PDF Reader used by the customer to check its statement messages.
Forensic experts believe this new discovery evidences that the malware used in the earlier reported customer incident was not a single occurrence, but part of a wider and highly adaptive campaign targeting banks.
In both instances, the attackers have exploited vulnerabilities in banks funds’ transfer initiation environments, prior to messages being sent over SWIFT. The attackers have been able to bypass whatever primary risk controls the victims have in place, thereby being able to initiate the irrevocable funds transfer process. In a second step, they have found ways to tamper with the statements and confirmations that banks would sometimes use as secondary controls, thereby delaying the victims’ ability to recognise the fraud.
The attackers clearly exhibit a deep and sophisticated knowledge of specific operational controls within the targeted banks – knowledge that may have been gained from malicious insiders or cyber attacks, or a combination of both.
Preventative Controls
As a matter of urgency we remind all customers again to urgently review controls in their payments environments, to all their messaging, payments and ebanking channels. This includes everything from employee checks to password protection to cyber defences. We recommend that customers consider third party assurance reviews and, where necessary, ask your correspondent banks and service bureaux to work with you on enhanced arrangements.
We also urge all customers to be forthcoming when these issues occur so that the fraudsters can be tracked by the authorities, and SWIFT can inform the rest of community about any findings that may have a bearing on wider security issues.
In the meantime we would like to reassure you that the SWIFT network, SWIFT messaging systems and software have not been compromised. The security and integrity of our messaging services are not in question as a result of the incidents. We will continue with our security awareness campaign, bilaterally with users and through industry forums and other appropriate channels. We will also continue working with our overseers, with law enforcement agencies, and third party experts, and we will continue to inform you of any further information we believe that can help you detect or avert such attacks.
Latest Findings
In the earlier case we reported to you, and this particular case we can confirm that: malicious insiders or external attackers have managed to submit SWIFT messages from financial institutions’ back-offices, PCs or workstations connected to their local interface to the SWIFT network. The modus operandi of the attackers is similar in both cases:
1. Attackers compromise the bank’s environment
2. Attackers obtain valid operator credentials that have the authority to create, approve and submit SWIFT messages from customers’ back-offices or from their local interfaces to the SWIFT network.
3. Attackers submit fraudulent messages by impersonating the operators from whom they stole the credentials.
4. Attackers hide evidence by removing some of the traces of the fraudulent messages.
In this new case we have now learnt that a piece of malware was used to target the PDF reader application used by the customer to read user generated PDF reports of payment confirmations. The main purpose of the malware is again to manipulate an affected customer’s local records of SWIFT messages – i.e. step 4 in the above modus operandi.
Once installed on an infected local machine, the Trojan PDF reader gains an icon and file description that matches legitimate software. When opening PDF files containing local reports of customer specific SWIFT confirmation messages, the Trojan will manipulate the PDF reports to remove traces of the fraudulent instructions.
There is no evidence that the malware creates or injects new messages or alters the content of legitimate outgoing messages. This malware only targets the PDF reader in affected institutions’ local environments and has no impact on SWIFT’s network, interface software or core messaging services.
Customers that use PDF reader applications to check their confirmation messages should take particular care.
Your Security
As we stated earlier, this is clearly a highly adaptive campaign targeting banks’ payment endpoints. Above all therefore your first priority should be to ensure that you have all preventative and detective measures in place to secure your environment. This latest evidence adds further urgency to this work. Such measures are the best defence against such malware being installed on your local systems, and against fraudulent actions on your local infrastructure to connect to the SWIFT network.
Please remember that as a SWIFT user you are responsible for the security of your own systems interfacing with the SWIFT network and your related environment – starting with basic password protection practices – in much the same way as you are responsible for your other security considerations. Whilst we issue, and have recently reminded you about, security best practice recommendations, these are just a baseline and general advice.
We will continue to update you on these issues as more information becomes available to us. We would ask you to ensure that these communications reach your security officers.
About SWIFT
SWIFT is a global member-owned cooperative and the world’s leading provider of secure financial messaging services.
We provide our community with a platform for messaging and standards for communicating, and we offer products and services to facilitate access and integration, identification, analysis and financial crime compliance.
Our messaging platform, products and services connect more than 11,000 banking and securities organisations, market infrastructures and corporate customers in more than 200 countries and territories, enabling them to communicate securely and exchange standardised financial messages in a reliable way. As their trusted provider, we facilitate global and local financial flows, support trade and commerce all around the world; we relentlessly pursue operational excellence and continually seek ways to lower costs, reduce risks and eliminate operational inefficiencies.
Headquartered in Belgium, SWIFT’s international governance and oversight reinforces the neutral, global character of its cooperative structure. SWIFT’s global office network ensures an active presence in all the major financial centres.
For more information, visit www.swift.com or follow us on Twitter: @swiftcommunity and LinkedIn: SWIFT
Contacts:
Brunswick Group LLP
swift@brunswickgroup.com
Tel: +44 (0)20 7404 5959
- wong chee tat :)
Labels:
2016,
anti virus,
computer network,
computer networking,
computer virus,
cyber security,
cyberspace,
finance,
investors,
malware,
may,
network,
pdf,
swift
Financial institutions need 'strong IT controls' following SWIFT attacks: MAS
Financial institutions need 'strong IT controls' following SWIFT attacks: MAS
After a series of cyber attacks on financial institutions worldwide, the Monetary Authority of Singapore says that it will continue to monitor the security landscape and provide guidance where necessary.
By Melissa Zhu
Posted 16 May 2016 17:22 Updated 16 May 2016 23:07
SINGAPORE: The Monetary Authority of Singapore (MAS) "expects financial institutions to implement strong controls in their IT systems", after recent cyber attacks using the Society for Worldwide Interbank Financial Telecommunication (SWIFT) financial messaging system.
The regulator told Channel NewsAsia on Monday (May 16) that these controls included maintaining a high level of security for critical IT systems such as SWIFT. "MAS will continue to monitor the security landscape and threats faced by the financial industry and provide guidance where necessary," a spokesperson said.
MAS' comments come in the wake of a number of cyber attacks on banks worldwide through SWIFT's system - a network that allows institutions to carry out financial transactions by sending out messages through a secured global communications network.
In February, hackers broke into the computer systems of the Bangladesh Central Bank, stealing credentials for payment transfers worth US$81 million out of a Federal Reserve Bank of New York account held by the Central Bank using fraudulent SWIFT messages. Last Thursday, SWIFT announced that a second bank had been hit by a similar malware attack. A spokesperson said it was not immediately clear how much money, if any, was stolen from the unnamed commercial bank.
After this case, SWIFT confirmed that malicious attackers had submitted SWIFT messages from financial institutions' back-offices, PCs or workstations connected to their local interface to the SWIFT network.
It added that after hackers submitted fraudulent instructions on SWIFT by impersonating the banks' operators, they used malware to target a PDF reader application used for reports of payment confirmations, to remove traces of the fraudulent messages.
"This malware only targets the PDF reader in affected institutions’ local environments and has no impact on SWIFT’s network, interface software or core messaging services," it said.
On Sunday, Vietnam's Tien Phong Bank said it interrupted an attempted cyber heist using SWIFT messages to transfer more than 1 million euros (US$1.1 million) in funds.
SWIFT, a Belgian co-operative owned by member banks and used by 11,000 financial institutions globally, had said forensic experts believe the second case showed that the Bangladesh heist "was not a single occurrence, but part of a wider and highly adaptive campaign targeting banks".
The chain of related attacks has put the linchpin for the financial messaging industry under intense scrutiny. The organisation has said that banks are responsible for securing computers used to send messages over its network, but a Bangladeshi-government appointed panel later blamed the cyber theft on "a number of errors" committed by the messaging network.
In a statement last Friday, SWIFT also said that "the SWIFT network, core messaging services and software have not been compromised".
"The security and integrity of our messaging services are not in question as a result of the incidents," it reiterated.
CYBER THREATS TAKEN "VERY SERIOUSLY": LOCAL BANKS
While there are no known cases of related attacks on banks in Singapore so far, financial institutions told Channel NewsAsia that they are taking cyber security "very seriously".
United Overseas Bank's managing director and head of group technology, Susan Hwee, said the bank deploys "multiple layers of security, and constantly monitors developments and enhances our systems to ensure that we manage technology risks in a systematic and consistent manner".
"The bank adheres to strict security standards which are aligned to industry best practices and regulatory guidelines to maintain a secure banking environment for all our customers,” added Ms Hwee.
Mr Patrick Chew, head of operational risk management at Oversea-Chinese Banking Corporation (OCBC), likewise said the bank took a serious view on cyber threats.
"The modus operandi of cybercriminals morphs frequently. We therefore maintain a high level of vigilance over new or emerging cyber threats," he said, adding that this entails adopting a "proactive and multi-dimensional approach" that includes close monitoring, investing in IT infrastructure, regular reviews of operation processes, employee training and the issuance of advisories to customers.
OCBC also has a cyber security operations centre that monitors the bank’s IT and cyber security systems round the clock, and works closely with national agencies and industry bodies to safeguard the bank against increasingly sophisticated cyber threats, said Mr Chew.
"These collaborations allow us to constantly keep abreast of cyber security developments while facilitating collective efforts by the industry to confront and mitigate against such risks," he elaborated.
As lenders globally step up efforts to step up cybersecurity, Standard Chartered said it hired a new chief information security officer, former Symantec executive Cheri McGuire, on Wednesday. The bank's Singapore branch said that it has not been targeted by such cyber attacks so far.
- CNA/mz
- wong chee tat :)
After a series of cyber attacks on financial institutions worldwide, the Monetary Authority of Singapore says that it will continue to monitor the security landscape and provide guidance where necessary.
By Melissa Zhu
Posted 16 May 2016 17:22 Updated 16 May 2016 23:07
SINGAPORE: The Monetary Authority of Singapore (MAS) "expects financial institutions to implement strong controls in their IT systems", after recent cyber attacks using the Society for Worldwide Interbank Financial Telecommunication (SWIFT) financial messaging system.
The regulator told Channel NewsAsia on Monday (May 16) that these controls included maintaining a high level of security for critical IT systems such as SWIFT. "MAS will continue to monitor the security landscape and threats faced by the financial industry and provide guidance where necessary," a spokesperson said.
MAS' comments come in the wake of a number of cyber attacks on banks worldwide through SWIFT's system - a network that allows institutions to carry out financial transactions by sending out messages through a secured global communications network.
In February, hackers broke into the computer systems of the Bangladesh Central Bank, stealing credentials for payment transfers worth US$81 million out of a Federal Reserve Bank of New York account held by the Central Bank using fraudulent SWIFT messages. Last Thursday, SWIFT announced that a second bank had been hit by a similar malware attack. A spokesperson said it was not immediately clear how much money, if any, was stolen from the unnamed commercial bank.
After this case, SWIFT confirmed that malicious attackers had submitted SWIFT messages from financial institutions' back-offices, PCs or workstations connected to their local interface to the SWIFT network.
It added that after hackers submitted fraudulent instructions on SWIFT by impersonating the banks' operators, they used malware to target a PDF reader application used for reports of payment confirmations, to remove traces of the fraudulent messages.
"This malware only targets the PDF reader in affected institutions’ local environments and has no impact on SWIFT’s network, interface software or core messaging services," it said.
On Sunday, Vietnam's Tien Phong Bank said it interrupted an attempted cyber heist using SWIFT messages to transfer more than 1 million euros (US$1.1 million) in funds.
SWIFT, a Belgian co-operative owned by member banks and used by 11,000 financial institutions globally, had said forensic experts believe the second case showed that the Bangladesh heist "was not a single occurrence, but part of a wider and highly adaptive campaign targeting banks".
The chain of related attacks has put the linchpin for the financial messaging industry under intense scrutiny. The organisation has said that banks are responsible for securing computers used to send messages over its network, but a Bangladeshi-government appointed panel later blamed the cyber theft on "a number of errors" committed by the messaging network.
In a statement last Friday, SWIFT also said that "the SWIFT network, core messaging services and software have not been compromised".
"The security and integrity of our messaging services are not in question as a result of the incidents," it reiterated.
CYBER THREATS TAKEN "VERY SERIOUSLY": LOCAL BANKS
While there are no known cases of related attacks on banks in Singapore so far, financial institutions told Channel NewsAsia that they are taking cyber security "very seriously".
United Overseas Bank's managing director and head of group technology, Susan Hwee, said the bank deploys "multiple layers of security, and constantly monitors developments and enhances our systems to ensure that we manage technology risks in a systematic and consistent manner".
"The bank adheres to strict security standards which are aligned to industry best practices and regulatory guidelines to maintain a secure banking environment for all our customers,” added Ms Hwee.
Mr Patrick Chew, head of operational risk management at Oversea-Chinese Banking Corporation (OCBC), likewise said the bank took a serious view on cyber threats.
"The modus operandi of cybercriminals morphs frequently. We therefore maintain a high level of vigilance over new or emerging cyber threats," he said, adding that this entails adopting a "proactive and multi-dimensional approach" that includes close monitoring, investing in IT infrastructure, regular reviews of operation processes, employee training and the issuance of advisories to customers.
OCBC also has a cyber security operations centre that monitors the bank’s IT and cyber security systems round the clock, and works closely with national agencies and industry bodies to safeguard the bank against increasingly sophisticated cyber threats, said Mr Chew.
"These collaborations allow us to constantly keep abreast of cyber security developments while facilitating collective efforts by the industry to confront and mitigate against such risks," he elaborated.
As lenders globally step up efforts to step up cybersecurity, Standard Chartered said it hired a new chief information security officer, former Symantec executive Cheri McGuire, on Wednesday. The bank's Singapore branch said that it has not been targeted by such cyber attacks so far.
- CNA/mz
- wong chee tat :)
Friday, May 13, 2016
SWIFT rejects Bangladeshi claims in cyber heist, police stand firm
SWIFT rejects Bangladeshi claims in cyber heist, police stand firm
Posted 10 May 2016 19:05
REUTERS: SWIFT has rejected allegations by officials in Bangladesh that technicians with the global messaging system made the nation's central bank more vulnerable to hacking before an US$81 million cyber heist in February.
The comments were in response to a Reuters story that cited Bangladeshi police and a central bank official as saying that SWIFT technicians introduced security holes into the bank's network while connecting SWIFT to Bangladesh's first real-time gross settlement (RTGS) system.
"SWIFT was not responsible for any of the issues cited by the officials, or party to the related decisions," the Brussels-based bank-owned cooperative said in a statement posted on its website on Monday.
"As a SWIFT user like any other, Bangladesh Bank is responsible for the security of its own systems interfacing with the SWIFT network and their related environment – starting with basic password protection practices – in much the same way as they are responsible for their other internal security considerations," the statement said.
But Bangladesh's main police investigator maintained there were loopholes in the way SWIFT carried out the integration of its network with the RTGS platform that left the central bank's computer systems vulnerable to hackers.
Mohammad Shah Alam, the head of the criminal investigation department of the Bangladesh police, said the probe had identified specific deviations from set procedures that compromised Bangladesh Bank's security.
"We stand by our investigation," he said in response to the comments by SWIFT. But he added he did not want to engage in a debate and urged greater international cooperation to identify the culprits behind one of the world's biggest cyber thefts.
Reuters has not been able to independently verify the allegations by Bangladeshi officials about the SWIFT technicians.
U.S. investigators suspect the involvement of employees of the Bangladesh Bank in helping the hackers breach the systems, the Wall Street Journal said, quoting people familiar with the matter.
It said the Federal Bureau of Investigation had found evidence that at least one bank employee acted as an accomplice but there could be more who assisted the hackers in navigating around Bangladesh Bank's computer systems.
NO SHARING OF EVIDENCE
Bangladesh police said they have been looking for inside involvement in the heist from the beginning of the probe, but no evidence has turned up against anyone.
Investigators say they think there was some level of local facilitation in the attack on the central bank's computers but haven't identified it as yet.
"If the FBI has uncovered evidence, they should share with us," a police officer said.
The revelations came ahead of a meeting on Tuesday in Basel, Switzerland, where Bangladesh Bank officials have said their governor and a lawyer appointed by the bank would discuss recovery of about US$81 million stolen by hackers with the head of the Federal Reserve Bank of New York and a senior executive from SWIFT.
The money was stolen from Bangladesh Bank's account at the New York Fed through fraudulent transfer orders sent on the SWIFT system.
SWIFT's statement said it "looks forward to the meeting with Bangladesh Bank and New York Federal Reserve Bank officials in Basel on 10th May, when the bank’s security issues and these baseless allegations will be discussed."
Bangladesh Bank officials have said they believed SWIFT, and the New York Fed, bear some responsibility for the February cyber heist.
(Additional reporting by Serajul Quadir in DHAKA; Editing by Toni Reinhold and Raju Gopalakrishnan)
- Reuters
- wong chee tat :)
Posted 10 May 2016 19:05
REUTERS: SWIFT has rejected allegations by officials in Bangladesh that technicians with the global messaging system made the nation's central bank more vulnerable to hacking before an US$81 million cyber heist in February.
The comments were in response to a Reuters story that cited Bangladeshi police and a central bank official as saying that SWIFT technicians introduced security holes into the bank's network while connecting SWIFT to Bangladesh's first real-time gross settlement (RTGS) system.
"SWIFT was not responsible for any of the issues cited by the officials, or party to the related decisions," the Brussels-based bank-owned cooperative said in a statement posted on its website on Monday.
"As a SWIFT user like any other, Bangladesh Bank is responsible for the security of its own systems interfacing with the SWIFT network and their related environment – starting with basic password protection practices – in much the same way as they are responsible for their other internal security considerations," the statement said.
But Bangladesh's main police investigator maintained there were loopholes in the way SWIFT carried out the integration of its network with the RTGS platform that left the central bank's computer systems vulnerable to hackers.
Mohammad Shah Alam, the head of the criminal investigation department of the Bangladesh police, said the probe had identified specific deviations from set procedures that compromised Bangladesh Bank's security.
"We stand by our investigation," he said in response to the comments by SWIFT. But he added he did not want to engage in a debate and urged greater international cooperation to identify the culprits behind one of the world's biggest cyber thefts.
Reuters has not been able to independently verify the allegations by Bangladeshi officials about the SWIFT technicians.
U.S. investigators suspect the involvement of employees of the Bangladesh Bank in helping the hackers breach the systems, the Wall Street Journal said, quoting people familiar with the matter.
It said the Federal Bureau of Investigation had found evidence that at least one bank employee acted as an accomplice but there could be more who assisted the hackers in navigating around Bangladesh Bank's computer systems.
NO SHARING OF EVIDENCE
Bangladesh police said they have been looking for inside involvement in the heist from the beginning of the probe, but no evidence has turned up against anyone.
Investigators say they think there was some level of local facilitation in the attack on the central bank's computers but haven't identified it as yet.
"If the FBI has uncovered evidence, they should share with us," a police officer said.
The revelations came ahead of a meeting on Tuesday in Basel, Switzerland, where Bangladesh Bank officials have said their governor and a lawyer appointed by the bank would discuss recovery of about US$81 million stolen by hackers with the head of the Federal Reserve Bank of New York and a senior executive from SWIFT.
The money was stolen from Bangladesh Bank's account at the New York Fed through fraudulent transfer orders sent on the SWIFT system.
SWIFT's statement said it "looks forward to the meeting with Bangladesh Bank and New York Federal Reserve Bank officials in Basel on 10th May, when the bank’s security issues and these baseless allegations will be discussed."
Bangladesh Bank officials have said they believed SWIFT, and the New York Fed, bear some responsibility for the February cyber heist.
(Additional reporting by Serajul Quadir in DHAKA; Editing by Toni Reinhold and Raju Gopalakrishnan)
- Reuters
- wong chee tat :)
Tuesday, April 26, 2016
Exclusive: SWIFT warns customers of multiple cyber fraud cases
Exclusive: SWIFT warns customers of multiple cyber fraud cases
SWIFT, the global financial network that banks use to transfer billions of dollars every day, warned its customers on Monday that it was aware of "a number of recent cyber incidents" where attackers had sent fraudulent messages over its system.
Posted 26 Apr 2016 05:55 Updated 26 Apr 2016 18:30
REUTERS: SWIFT, the global financial network that banks use to transfer billions of dollars every day, warned its customers on Monday that it was aware of "a number of recent cyber incidents" where attackers had sent fraudulent messages over its system.
The disclosure came as law enforcement authorities in Bangladesh and elsewhere investigated the February cyber theft of US$81 million from the Bangladesh central bank account at the New York Federal Reserve Bank. SWIFT has acknowledged that the scheme involved altering SWIFT software on Bangladesh Bank's computers to hide evidence of fraudulent transfers.
Monday's statement from SWIFT marked the first acknowledgement that the Bangladesh Bank attack was not an isolated incident but one of several recent criminal schemes that aimed to take advantage of the global messaging platform used by some 11,000 financial institutions.
"SWIFT is aware of a number of recent cyber incidents in which malicious insiders or external attackers have managed to submit SWIFT messages from financial institutions' back-offices, PCs or workstations connected to their local interface to the SWIFT network," the group warned customers on Monday in a notice seen by Reuters.
The warning, which SWIFT issued in a confidential alert sent over its network, did not name any victims or disclose the value of any losses from the previously undisclosed attacks. SWIFT confirmed to Reuters the authenticity of the notice.
SWIFT, or the Society for Worldwide Interbank Financial
Telecommunication, is a cooperative owned by 3,000 financial institutions.
Also on Monday, SWIFT released a security update to the software that banks use to access its network to thwart malware that security researchers with British defense contractor BAE Systems said was probably used by hackers in the Bangladesh Bank heist.
BAE's evidence suggested that hackers manipulated SWIFT's Alliance Access server software, which banks use to interface with SWIFT's messaging platform, to cover their tracks.
BAE said it could not explain how the fraudulent orders were created and pushed through the system.
But SWIFT provided some evidence about how that happened in its note to customers, saying that in most cases the modus operandi was similar.
It said the attackers obtained valid credentials for operators authorized to create and approve SWIFT messages, then submitted fraudulent messages by impersonating those people.
FireEye, the internet security company whose Mandiant unit was hired by Bangladesh Bank to help investigate the heist, said the same group behind that hack had probably attacked other financial targets.
"FireEye has observed activity in other financial services organizations that is likely by the same threat actor behind the cyber attack on the Bank of Bangladesh," Vivek Chudgar, Mandiant's senior director for the Asia Pacific said in a statement emailed to Reuters.
FireEye declined to go into detail.
Rakesh Asthana, the World Informatix Cyber Security CEO, who is overseeing Bangladesh Bank's probe into the hack, declined to discuss the other attacks that SWIFT referred to.
He did, though, urge banks to conduct independent security assessments to make sure their networks are secure and prevent future attacks.
“SWIFT builds on security practices established by the customer itself and therefore it is imperative that in the wake of this attack, customers using SWIFT Alliance Access must strengthen their cyber security posture,” Asthana said
FOLLOWING THE MONEY
Cyber security experts said more attacks could surface as SWIFT's banking clients look to see if their SWIFT access has been compromised.
Shane Shook, a banking security consultant who investigates large financial crime, said hackers were turning to SWIFT and other private financial messaging platforms because such attacks can generate more revenue than going after consumers or small businesses.
"These hacks specifically target financial institutions because smaller efforts result in much larger thefts," he said. "It's much more efficient than stealing from consumers."
Justin Harvey, chief security officer with Fidelis Cybersecurity, said hackers followed the money and would be drawn into such schemes in hopes of emulating a big heist like the one on Bangladesh Bank.
"After the Bangladesh Bank heist became public, every other attacker out there is looking to see if they can do the same," he said.
SWIFT spokeswoman Natasha Deteran told Reuters that the commonality in these cases was that internal or external attackers compromised the banks’ own environments to obtain valid operator credentials.
"Customers should do their utmost to protect against this," she said in an email to Reuters.
SWIFT told customers that the security update must be installed by May 12.
"We have made the Alliance interface software update mandatory as it is designed to help banks identify situations in which attackers have attempted to hide their traces - whether these actions have been executed manually or through malware," she said.
(Reporting by Jim Finkle in Boston; Additional reporting by Serajul Quadir in Dhaka; Editing by Jonathan Weber, Martin Howell and Peter Cooney)
- Reuters
- wong chee tat :)
SWIFT, the global financial network that banks use to transfer billions of dollars every day, warned its customers on Monday that it was aware of "a number of recent cyber incidents" where attackers had sent fraudulent messages over its system.
Posted 26 Apr 2016 05:55 Updated 26 Apr 2016 18:30
REUTERS: SWIFT, the global financial network that banks use to transfer billions of dollars every day, warned its customers on Monday that it was aware of "a number of recent cyber incidents" where attackers had sent fraudulent messages over its system.
The disclosure came as law enforcement authorities in Bangladesh and elsewhere investigated the February cyber theft of US$81 million from the Bangladesh central bank account at the New York Federal Reserve Bank. SWIFT has acknowledged that the scheme involved altering SWIFT software on Bangladesh Bank's computers to hide evidence of fraudulent transfers.
Monday's statement from SWIFT marked the first acknowledgement that the Bangladesh Bank attack was not an isolated incident but one of several recent criminal schemes that aimed to take advantage of the global messaging platform used by some 11,000 financial institutions.
"SWIFT is aware of a number of recent cyber incidents in which malicious insiders or external attackers have managed to submit SWIFT messages from financial institutions' back-offices, PCs or workstations connected to their local interface to the SWIFT network," the group warned customers on Monday in a notice seen by Reuters.
The warning, which SWIFT issued in a confidential alert sent over its network, did not name any victims or disclose the value of any losses from the previously undisclosed attacks. SWIFT confirmed to Reuters the authenticity of the notice.
SWIFT, or the Society for Worldwide Interbank Financial
Telecommunication, is a cooperative owned by 3,000 financial institutions.
Also on Monday, SWIFT released a security update to the software that banks use to access its network to thwart malware that security researchers with British defense contractor BAE Systems said was probably used by hackers in the Bangladesh Bank heist.
BAE's evidence suggested that hackers manipulated SWIFT's Alliance Access server software, which banks use to interface with SWIFT's messaging platform, to cover their tracks.
BAE said it could not explain how the fraudulent orders were created and pushed through the system.
But SWIFT provided some evidence about how that happened in its note to customers, saying that in most cases the modus operandi was similar.
It said the attackers obtained valid credentials for operators authorized to create and approve SWIFT messages, then submitted fraudulent messages by impersonating those people.
FireEye, the internet security company whose Mandiant unit was hired by Bangladesh Bank to help investigate the heist, said the same group behind that hack had probably attacked other financial targets.
"FireEye has observed activity in other financial services organizations that is likely by the same threat actor behind the cyber attack on the Bank of Bangladesh," Vivek Chudgar, Mandiant's senior director for the Asia Pacific said in a statement emailed to Reuters.
FireEye declined to go into detail.
Rakesh Asthana, the World Informatix Cyber Security CEO, who is overseeing Bangladesh Bank's probe into the hack, declined to discuss the other attacks that SWIFT referred to.
He did, though, urge banks to conduct independent security assessments to make sure their networks are secure and prevent future attacks.
“SWIFT builds on security practices established by the customer itself and therefore it is imperative that in the wake of this attack, customers using SWIFT Alliance Access must strengthen their cyber security posture,” Asthana said
FOLLOWING THE MONEY
Cyber security experts said more attacks could surface as SWIFT's banking clients look to see if their SWIFT access has been compromised.
Shane Shook, a banking security consultant who investigates large financial crime, said hackers were turning to SWIFT and other private financial messaging platforms because such attacks can generate more revenue than going after consumers or small businesses.
"These hacks specifically target financial institutions because smaller efforts result in much larger thefts," he said. "It's much more efficient than stealing from consumers."
Justin Harvey, chief security officer with Fidelis Cybersecurity, said hackers followed the money and would be drawn into such schemes in hopes of emulating a big heist like the one on Bangladesh Bank.
"After the Bangladesh Bank heist became public, every other attacker out there is looking to see if they can do the same," he said.
SWIFT spokeswoman Natasha Deteran told Reuters that the commonality in these cases was that internal or external attackers compromised the banks’ own environments to obtain valid operator credentials.
"Customers should do their utmost to protect against this," she said in an email to Reuters.
SWIFT told customers that the security update must be installed by May 12.
"We have made the Alliance interface software update mandatory as it is designed to help banks identify situations in which attackers have attempted to hide their traces - whether these actions have been executed manually or through malware," she said.
(Reporting by Jim Finkle in Boston; Additional reporting by Serajul Quadir in Dhaka; Editing by Jonathan Weber, Martin Howell and Peter Cooney)
- Reuters
- wong chee tat :)
Labels:
2016,
apr,
April,
Bank,
banking,
cash,
cashflow,
computer network,
computer networking,
cyberspace,
fireeye,
firewall,
money,
network,
swift
Subscribe to:
Posts (Atom)