Showing posts with label Theft. Show all posts
Showing posts with label Theft. Show all posts

Thursday, March 17, 2016

How a hacker's typo helped stop a billion dollar bank heist

How a hacker's typo helped stop a billion dollar bank heist

DHAKA | BY SERAJUL QUADIR

A spelling mistake in an online bank transfer instruction helped prevent a nearly $1 billion heist last month involving the Bangladesh central bank and the New York Federal Reserve, banking officials said.
Unknown hackers still managed to get away with about $80 million, one of the largest known bank thefts in history.
The hackers breached Bangladesh Bank's systems and stole its credentials for payment transfers, two senior officials at the bank said. They then bombarded the Federal Reserve Bank of New York with nearly three dozen requests to move money from the Bangladesh Bank's account there to entities in the Philippines and Sri Lanka, the officials said.
Four requests to transfer a total of about $81 million to the Philippines went through, but a fifth, for $20 million, to a Sri Lankan non-profit organization was held up because the hackers misspelled the name of the NGO, Shalika Foundation.
Hackers misspelled "foundation" in the NGO's name as "fandation", prompting a routing bank, Deutsche Bank, to seek clarification from the Bangladesh central bank, which stopped the transaction, one of the officials said.
There is no NGO under the name of Shalika Foundation in the list of registered Sri Lankan non-profits. Reuters could not immediately find contact information for the organization.
Deutsche Bank declined to comment.
At the same time, the unusually large number of payment instructions and the transfer requests to private entities - as opposed to other banks - raised suspicions at the Fed, which also alerted the Bangladeshis, the officials said.
The details of how the hacking came to light and was stopped before it did more damage have not been previously reported. Bangladesh Bank has billions of dollars in a current account with the Fed, which it uses for international settlements.
The transactions that were stopped totaled $850-$870 million, one of the officials said.
Last year, Russian computer security company Kaspersky Lab said a multinational gang of cyber criminals had stolen as much as $1 billion from as many as 100 financial institutions around the world in about two years.
Iraqi dictator Saddam Hussein's son Qusay took $1 billion from Iraq's central bank on the orders of his father on the day before coalition forces began bombing the country in 2003, American and Iraqi officials have said. In 2007, guards at the Dar Es Salaam bank in Baghdad made off with $282 million.
MONEY RECOVERED
Bangladesh Bank has said it has recovered some of the money that was stolen, and is working with anti-money laundering authorities in the Philippines to try to recover the rest.
A bank spokesman could not be reached for comment late on Thursday.
The recovered funds refer to the Sri Lanka transfer, which was stopped, one of the officials said.
Initially, the Sri Lankan transaction reached Pan Asia Banking Corp PABC.CM, which went back to Deutsche Bank for more verification because of the unusually large size of the payment, a Pan Asia official said. "The transaction was too large for a country like us," the official said. "Then (Deutsche) came back and said it was a suspect transaction." A Pan Asia spokesman could not immediately be reached for comment.
The dizzying, global reach of the heist underscores the growing threat of cyber crime and how hackers can find weak links in even the most secure computer networks.
More than a month after the attack, Bangladeshi officials are scrambling to trace the money, shore up security and identify weaknesses in their systems. They said there is little hope of ever catching the hackers, and it could take months before the money is recovered, if at all.
FireEye Inc's (FEYE.O) Mandiant forensics division is helping investigate the heist, people familiar with the matter told Reuters on Thursday.
The sources said Silicon Valley-based FireEye, which has investigated some of the biggest cyber thefts on record, was brought in by World Informatix, a smaller firm that is advising Bangladesh Bank on the investigation.
Security experts said the perpetrators had deep knowledge of the Bangladeshi institution's internal workings, likely gained by spying on bank workers.
The Bangladesh government, meanwhile, is blaming the Fed for not stopping the transactions earlier. Finance Minister Abul Maal Abdul Muhith told reporters on Tuesday that the country may resort to suing the Fed to recover the money. 
"The Fed must take responsibility," he said.
The New York Fed has said its systems were not breached, and it has been working with the Bangladesh central bank since the incident occurred.
The hacking of Bangladesh Bank happened sometime between Feb. 4-5, over the Bangladeshi weekend, which falls on a Friday, the officials said. The bank's offices were shut.
Initially, the central bank was not sure if its system had been breached, but cyber security experts brought in to investigate found hacker "footprints" that suggested the system had been compromised, the officials said.
These experts could also tell that the attack originated from outside Bangladesh, they said, adding the bank is looking into how they got into the system and an internal investigation is ongoing.
The bank suspects money sent to the Philippines was further diverted to casinos there, the officials said. 
The Philippine Amusement and Gaming Corp, which oversees the gaming industry, said it has launched an investigation. The country's anti-money laundering authority is also working on the case.

(Additional reporting by Jim Finkle in BOSTON, Jonathan Spicer in NEW YORK, Farah Master in HONG KONG and Shihar Aneez in COLOMBO; Editing by Paritosh Bansal and Raju Gopalakrishnan)

Wednesday, April 4, 2012

Protect Your Phone's Data with a Passcode

Do you have a passcode on your iPhone or Android device? If not it is recommended as phones can easily be miss placed or stolen. A passcode to get into your device will help keep your information private and secure. Many personal and business phones have apps on them that hold a lot of important personal information. That information in the wrong hands can be dangerous and because of this we have three steps we recommend in helping protect your phone.
The first step is simple; decide to put a passcode on your phone. I know, it may be annoying to have to type something into your phone each time you use it but it is better for you in the long run.
The second step is to make the passcode something more than just four digits. Recently there was a software invented called Micro Systemation XRY app. This software can crack any four digit code in only a few minutes. Currently this software is only used by law enforcement agencies however the hackers are never to far behind in developing their own. We recommend you using the setting in your phone that lets you put in more than just four digits. Letters and numbers help to make the cracking process harder. Throw in a few other characters and it becomes even harder to break.
The third step in protecting your phone’s data is to put on the setting in which your data is wiped from the phone after so many failed attempts to login. I know it would be annoying to lose your data from your phone but hopefully you have it synced and backed up on your computer or in a cloud (plus is someone stole your phone you not only lose the data anyway but also the phone). By having the phone wiped after so many failed attempts you are preventing hackers and thieves form being able to use software to try and figure out your passcode.

Friday, March 2, 2012

Radio Frequency Indetification Thefts

Credit cards are gradually moving away from the swipe and process cards to the wireless transfer of financial data. This make shopping lines move quicker but it does create a new kind of theft. The technology is called Radio Frequency Identification (RFID). All you do is hold a card near a RFID scanner and the data is transferred. The problem with this is that computer savvy criminals can create scanners that steal your financial data right off your credit card, even if it is still in your wallet. Credit card companies are becoming aware of this issue and have worked to solve the problem with on off switches on the card that are triggered when a finger presses the chip that is imbedded in the card. One other way to prevent scanning theft is to purchase a RFID protected wallet. For example the HuMn Wallet has material that doesn’t allow RFID scanners to scan cards in the wallet.
So be sure to take precaution if your new credit card has the RFID chip imbedded inside. Ask if you can have a card that has the on/off switch and if not look into purchasing a RFID protected wallet.

Wednesday, February 22, 2012

Scheduling Special Items

Back in July we posted an article about special limits on homeowner policies for things such as guns, jewelry, coins, cash, silver and furs.  In the wake of a string of burglaries in our area (burglaries that are only focused on taking cash, coins and jewelry), we felt it was important to remind people of the homeowner limitations on these items.  It differs per policy and per item but usually there is only about $1000 to $2500 of coverage given on the homeowners for things such as guns, jewelry, coins, cash, silver and furs.  If you own more than that limitation in any of the mentioned categories you should schedule the items on a special policy.  Feel free to contact Fey Insurance to make sure you have things appropriately covered.

On a side note, the current criminals who have been robbing homes in the area are first placing calls asking if you have a security alarm.  As soon as you answer no they hang up and then know your home is unprotected.  Be sure to never answer no to such questions over the phone to a random phone call.

Wednesday, May 5, 2010

Safeguard Your Home from Burglary

In 2007, the last year with full statistics, there were an estimated 2.2 million burglaries, according to the Federal Bureau of Investigation. Burglaries represent more than 22 percent of property crimes committed in 2007, and of these burglaries, 61 percent involved forcible entry. Burglary offenses represented $4.3 billion in losses, an average of nearly $2,000 per burglary, and nearly 68 percent of burglaries were residential.



Surprising to many is that nearly 64 percent of burglaries occurred during the daytime. Below are some suggestions that should help you from becoming a statistic:



- Keep exterior views of your home unobstructed and trim landscaping back to expose windows and doors. This requires a burglar to work in full view and poses a serious risk of detection.



-Maintain adequate exterior lighting at access points to your home.



-Put your ladder away. Do not provide easy access for the burglar to gain entrance.



-Do not keep valuables, such as bicycles and tools, in the open.



-Keep your garage door closed and locked. An open garage door allows a crook to see valuables stored in your garage.



-Make sure your house number is prominently displayed and illuminated to help emergency responders find your home quickly.



-Do not leave notes on your door that might indicate your home is unoccupied.