Cyber Firms Say Bangladesh Hackers Have Attacked Other Asian Banks

Advertisement
By Reuters | Updated: 27 May 2016 18:51 IST

Hackers who stole $81 million from Bangladesh's central bank have been linked to an attack on a bank in the Philippines, in addition to the 2014 hack on Sony Pictures, cybersecurity company Symantec said in a blog post.

The U.S. Federal Bureau of Investigation has blamed North Korea for the attack on Sony's Hollywood studio.

A senior executive at Mandiant, the cyber-security company investigating the Bank Bangladesh heist, also told Reuters the hackers had recently penetrated banks in Southeast Asia.

Advertisement

In the blog post published on Thursday, Symantec did not name the Philippines bank or say whether any money was stolen, but said the attacks could be traced back to October last year. It did not identify the hackers.

Advertisement

The Philippines central bank's deputy governor, Nestor Espenilla, told Reuters that no bank in the country had lost money to hackers, although he did not rule out the possibility of cyber attacks.

"We are checking if there are similar attacks on Philippine banks," Espenilla said. "However, no reported losses so far."

Advertisement

He added: "It is one thing to be attacked. It is another to lose money."

Marshall Heilman, vice president for Mandiant, a part of U.S.-based FireEye, said it was not known whether any money was lost in the other attacks he described or whether the hackers had been successfully blocked.

Advertisement

"There is a group operating in Southeast Asia that definitely understands the bank industry and is at more than one location," he said.

Heilman declined to identify the country or countries, or the institutions attacked. He said it was the same group as the one involved in the Bank Bangladesh theft and that the attacks were recent, but declined to be more specific.

Central banks elsewhere in Southeast Asia - Singapore, Indonesia, Brunei, Myanmar, Laos, Cambodia, Vietnam, Thailand and East Timor - have declined comment or denied knowledge of any other breaches.

There have been at least four known cyber attacks against a bank involving fraudulent messages on the Swift payments network, one dating back to 2013. Swift, the Society for Worldwide Interbank Financial Telecommunication, urged banks this week to bolster their security, saying it was aware of multiple attacks.

Banks around the world use secure Swift messages for issuing payment instructions to each other.

"Hard connection"
Swift said earlier this week that February's Bangladesh Bank hack was a "watershed event for the banking industry" and that it was "not an isolated incident."

Spokeswoman Natasha de Teran said on Thursday that Swift was "actively looking into other possible instances of such fraud," but would not comment on individual entities.

Symantec said it had identified three pieces of malware that were used in limited targeted attacks against financial institutions in Southeast Asia.

One of the malicious programs has been previously associated with a hacking group known as Lazarus, which has been linked to the devastating attack on Sony's Hollywood studio in 2014.

"There is a pretty hard connection now to the Sony attacks and the actor behind them" and the Bangladesh heist, Eric Chien, technical director at Symantec, said in an interview.

Another cyber-security firm, BAE Systems, said this month that the distinctive computer code used to erase the tracks of hackers in the Bangladesh Bank heist was similar to code used to attack Sony.

Chien said that if North Korea was responsible for the hacks on banks via the Swift messaging network it would represent the first known episode of a nation-state stealing money in a cyber-attack.

Policymakers, regulators and financial institutions around the world are stepping up scrutiny of the cyber-security of the Swift payments system after hackers used it to make fraudulent transfers totalling $81 million out of Bank Bangladesh's account at the Federal Reserve Bank of New York.

Symantec and other researchers have also linked the hack to a failed attempt to use fraudulent Swift messages to steal from a commercial bank in Vietnam.

In addition, Reuters reported last week that Ecuador's Banco del Austro had more than $12 million stolen from a Wells Fargo account due to fraudulent transfers over the Swift network.

Bangladesh police are also reviewing a nearly-forgotten 2013 cyber-heist at the nation's largest commercial bank, Sonali Bank, for connections to the central bank heist, a senior law enforcement official told Reuters. The unsolved theft of $250,000 at Sonali Bank also involved fraudulent transfer requests sent over the Swift network.

© Thomson Reuters 2016

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Cloudflare Is Down Again For the Second Time in Weeks: See Affected Sites
  2. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  3. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  4. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  5. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  6. Nothing Phone 3a Lite Goes on Sale in India at This Price
  7. Airtel Discontinues These Prepaid Recharge Packs in India
  8. Instamart to Provide 10-Minute Delivery of Samsung Galaxy Devices
  9. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  1. Google’s Year in Search 2025: Top Trending Topics in India—From Gemini to Squid Games
  2. Cloudflare Outage Blocks Access to Several Websites Including BookMyShow, SpaceX, Coinbase
  3. Samsung Galaxy S26 Series to Offer Built-In Support for Company's 25W Magnetic Qi2 Charger: Report
  4. Airtel Discontinues Two Prepaid Recharge Packs in India With Data Benefits, Free Airtel Xtreme Play Subscription
  5. Samsung Galaxy Phones, Devices Are Now Available via Instamart With 10-Minute Instant Delivery
  6. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
  7. HMD 101 Launched in India With 1,000mAh Battery, Auto Call Recording Alongside HMD 100: Price, Features
  8. Crypto Traders Await US Fed Signals as Bitcoin Price Drops to $91,900
  9. Nothing Phone 3a Lite Goes on Sale in India: See Price, Offers, Availability
  10. Realme Narzo Phones Confirmed to Launch in India Soon via Amazon
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.