Second bank cyber-attack detected after Bangladesh raid


London, May 13 (IANS): The Society for Worldwide Interbank Financial Telecommunication (SWIFT) has detected a cyber-attack that hit a bank, similar to one in which $81 million was stolen from Bangladesh's central bank.

SWIFT said the target was a commercial bank but did not name the organisation or reveal if any cash had been taken, BBC reported on Friday.

The attackers had a "deep and sophisticated knowledge of specific operational controls" at the targeted bank, and could have been aided in their theft by "malicious insiders", said the Belgium-based financial messaging network that underpins global money transfers.

The attack used techniques and tools resembling those used to steal cash from Bangladesh in February, it said.

In both attacks, the thieves sought to submit fraudulent messages to the SWIFT network to transfer large amounts of cash to accounts they controlled.

Analysis of February's attack suggested the gang aimed to steal about $1 billion by moving cash from an account held by Bangladesh's central bank at New York's Federal Reserve to other accounts.

A spelling mistake in one of the transfer orders alerted staff and stopped much of the money going astray.

An investigation into the attack revealed that the cyberthieves won access to the central bank network because of poor security controls.

The bank had no firewall, which is designed to block unauthorised access requests. It also used second-hand internet routers, which had cost $10, to connect to global financial networks.

  

Top Stories


Leave a Comment

Title: Second bank cyber-attack detected after Bangladesh raid



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.