Get 40% Off
These stocks are up over 10% post earnings. Did you spot the buying opportunity? Our AI did.Read how

SWIFT warns banks on cyber heists as hack sophistication grows

Published 11/28/2017, 07:14 PM
Updated 11/28/2017, 07:20 PM
© Reuters. FILE PHOTO - A man using a mobile phone passes the logo of global secure financial messaging services cooperative SWIFT at the SIBOS banking and financial conference in Toronto

By Jim Finkle

(Reuters) - SWIFT, the global messaging system used to move trillions of dollars each day, warned banks on Wednesday that the threat of digital heists is on the rise as hackers use increasingly sophisticated tools and techniques to launch new attacks.

Brussels-based SWIFT has been urging banks to bolster security of computers used to transfer money since Bangladesh Bank lost $81 million in a February 2016 cyber heist that targeted central bank computers used to move funds. The new warning provided detail on some new techniques being used by the hackers.

"Adversaries have advanced their knowledge," SWIFT said in a 16-page report co-written with BAE Systems Plc's (L:BAES) cyber security division. "No system can be assumed to be totally infallible, or immune to attack."

SWIFT has declined to disclose the number of attacks, identify victims or say how much money has been stolen. Still, details on some cases have become public.

Taiwan's Central News Agency last month reported that Far Eastern International Bank (TW:2845) lost $500,000 in a cyber heist. BAE later said that attack was launched by a North Korean hacking group known as Lazarus, which many cyber-security firms believe was behind the Bangladesh case.

Nepal's NIC Asia Bank lost $580,000 in a cyber heist, two Nepali officials told Reuters earlier this month.

The new report described an attack on an unidentified bank. Hackers spent several months inside the network of one customer, preparing for the eventual attack by stealing user credentials and monitoring the bank's operations using software that recorded computer keystrokes and screenshots, the report said.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

When they launched the attack in the middle of the night, the hackers installed additional malware that let them modify messaging software so they could bypass protocols for confirming the identity of the computer's operator, according to the report.

The hackers then ordered payments sent to banks in other countries by copying pre-formatted payment requests into the messaging software, according to the report.

After the hackers ended the three-hour operation, they sought to hide their tracks by deleting records of their activity. They also tried to distract the bank's security team by infecting dozens of other computers with ransomware that locked documents with an encryption key, the report said.

While SWIFT did not say how much money was taken, it said the bank quickly identified the fraudulent payments and arranged for the stolen funds to be frozen.

Latest comments

Probably buyed bitcoin with the stolen funds...the authority need to step up against this..
Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.