When Mobsters Meet Hackers: The New, Improved Bank Heist

Advertisement
By Reuters | Updated: 31 March 2016 12:25 IST
The unprecedented heist of $81 million from the US account of Bangladesh's central bank is the latest among increasingly large thefts by criminals who have leveraged the speed and anonymity of hacking to revolutionise burgling banks.

Hundreds of millions of dollars, and perhaps much more, have been stolen from banks and financial services companies in recent years because of this alliance of traditional and digital criminals, with many victims not reporting the thefts for fear of reputational damage.

Typically, security and cybercrime experts say, hackers break into the computer systems of financial institutions and make, or incite others to make, fraudulent transactions to pliant accounts. Organised crime then uses techniques developed over decades to launder the money, giving the alliance much higher rewards than a hold-up or bank vault robbery, with much less risk.

Advertisement

"The Internet has made it easier for criminals to get inside banks," said Shane Shook, an independent security consultant. "Criminals are moving away from consumer-targeted attacks to much more substantial bank hacks because it takes less effort to get more money."

There's no evidence that old-fashioned bank robberies are in the decline. But there are increasing instances of the cyber-variety of the crime.

Advertisement

Last year, researchers at Russian security software maker Kaspersky Lab publicised the activities of the prolific Carbanak gang, which it says hacked into banks, then ordered fraudulent money transfers and also forced ATMs to spit out cash. Kaspersky estimates the group hit as many as 100 banks, with losses averaging from $2.5 million to $10 million (roughly Rs. 16 crores to Rs. 66 crores) per heist.

A Turkish computer hacker pleaded guilty in a US court in March to one of the most astonishing crimes in this category: "Cashing crews" pulled $40 million (roughly Rs. 265 crores) out of automated teller machines in 24 countries over a 10-hour period. The 2013 heist was accomplished with the precision of a Hollywood drama, thanks to hackers who breached financial networks, then inflated balances on prepaid debit cards.

Advertisement

In another case, Russian banks lost more than $25 million (roughly Rs. 165 crores) over the past six months to a hacker group infecting their computers using tainted phishing emails, according to Russian security firm Group IB.

The malware gave the hackers access to the bank's inner network, allowing them to craft seemingly authentic transfer requests via networks including the same SWIFT messaging system used in the Bangladesh Bank attack.

Advertisement

"It (the malware) provides remote access to the attacker. Then the attacker manually orders fraudulent transfers over SWIFT or other payment systems," said Dmitry Volkov, head of cyber-intelligence for Group IB.

In the Bangladesh case, the bank says unknown hackers used malware to access the central bank's computers and spoof messages to the US Federal Reserve Bank. They transferred $81 million from the central bank's account at the New York Fed to Philippine banks.

(Also see:  Bangladesh Bank Says Hackers Tried to Steal $951 Million)

The funds were then passed on to casinos and handed over in cash to a junket operator in Manila, according to testimony at a senate hearing in the Philippines.

A transfer of $20 million to an entity in Sri Lanka was reported as suspicious because of a spelling mistake in its name and reversed.

Unreported heists
Cyber-fraud experts say they expect more big heists because the industry has yet to properly defend itself.

"The fact is that most of the breaches that happen don't get reported," said Bryce Boland, chief Asia Pacific security officer of computer security company FireEye.

(Also see:  FireEye Hired to Help Probe Bangladesh Bank Heist)

One senior banking security executive, who declined to be identified because he was not authorised to speak to the media, said he had worked on three cases of cyber-thefts that his bank clients had not reported to regulatory authorities. He said the largest involved about $20 million (roughly Rs. 132 crores).

In many jurisdictions, banks and financial services companies were not required to report breaches unless there's a material impact, Boland said. The definition is left vague enough so that many are not reported at all.

Boland said that while 20 percent of his banking customers had been targeted in the second half of last year, FireEye had also found cases of financial services companies not realising they had been breached, in one case leaving the attackers inside their computers for five years.

An ongoing Senate hearing in the Philippines is still struggling to determine how the stolen money was laundered, with another hearing scheduled for next week. In most cases the heists go unpunished and the perpetrators remain a mystery.

FireEye's Boland said the company has compiled detailed dossiers on six of the groups behind attacks on financial services companies, but he said he had less complete data on 600 other groups.

Not all focus on extracting money, he added. Hackers aimed at specific institutions, often at specific individuals, and often for financially useful data - inside information on mergers and acquisitions, for example, or data that could be used to create fake credit cards.

© Thomson Reuters 2016

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Sony Xperia 1 VIII Leak Shows Colourways and Revamped Camera Layout
  2. Vivo T5 Pro 5G Will Launch in India in These Colour Options
  3. Apple's Foldable iPhone May Pack a Bigger Battery Than the Galaxy Z Fold 8
  4. Early Leak Suggests CMF Phone 3 Pro Could Ditch MediaTek for Snapdragon
  5. OTT Releases This Week: O'Romeo, Tu Yaa Main, Main Wo Aur Fuji, Thaai Kizhavi, and More
  6. Google Bug Leaks Gemini AI Data in Google Pay, Oyo; Millions at Risk
  7. Motorola Edge 70 Pro Series Could Launch Soon in India in These Colours
  8. Motorola Edge 70 Pro Leak Hints at These Two Additional Colour Options
  9. Apple Could Shrink Dynamic Island on iPhone 18 Pro, Claims Tipster
  10. Oppo A6s Pro Confirmed to Launch on This Date
  1. Vivo T5 Pro 5G Price Range Revealed; Snapdragon 7s Gen 4 Chipset Confirmed
  2. MediaTek Dimensity 9600 Pro Leak Suggests 'Nearly' 5GHz Peak Clock Speed, New CPU Architecture
  3. Motorola Edge 70 Pro Seen in New Leaked Renders That Hint at Two Additional Colour Options
  4. Apple's Foldable iPhone's Design Leaked Again; Battery Capacity Said to Surpass Samsung Galaxy Z Fold 8
  5. Bitcoin and Ethereum Remain Range-Bound as ETF Outflows and Macroeconomic Pressure Limit Upside
  6. Valve Reportedly Working on SteamGPT, an AI-Powered Tool for Steam Support and Counter-Strike 2 Anti-Cheat
  7. Oppo Find X9s Pro Design, Camera Configuration and Other Key Details Revealed as Launch Date Approaches
  8. Oppo A6s Pro China Launch Date Announced: Expected Price, Specifications and Features
  9. Samsung Galaxy A57 5G, Galaxy A37 5G Go on Sale in India: Price, Offers
  10. Oppo Find X9 Ultra Camera Specifications Confirmed as Regulatory Listing Reveals Other Key Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.