Hackers steal $81 mn from Bangla account

Wednesday 23rd March 2016 06:17 EDT
 

In a recent update, the hackers who stole more than a $81 million on Feb 5, from Bangladesh's account in the Federal Reserve Bank of New York, were remotely monitoring activity of the bank for several weeks and may also have breached as many as 32 computers, as per private investigators.

In a clean and coordinated cyber crime, the criminals sent dozens of secure messages to the New York Fed, posing as Bangladeshi central bank officials, transferring funds from the account to several in the Philippines and Sri Lanka. Four requests to transfer a total of about $81 million to the Philippines went through, but a fifth, for $20 million, to a Sri Lankan non-profit organisation was held up because the hackers misspelled the name of the NGO, Shalika Foundation. Hackers misspelled “foundation” in the NGO's name as “fandation”, prompting a routing bank, Deutsche Bank, to seek clarification from the Bangladesh central bank, which stopped the transaction. Bangladesh Bank (BB) tried to contact New York on February 6 by email, fax and phone to ask that the transactions be suspended when it realised that the SWIFT interbank messaging system which it normally used was not working properly. But they were unable to get through as the US bank was closed for the weekend.

Introducing a code known as malware into the bank's server, they processed and authorised transactions, said the FireEye Inc., a cyber security firm hired by BB. Their report also said that the criminals deployed hacking tools, including keylogger software that monitors strokes on a keyboard, to steal the bank's credentials for the Swift system- a closed network used by financial institutions to authorise financial transactions through secure messages. Society for Worldwide Interbank Financial Telecommunication, a firm owned by around 3,000 global financial institutions, said it would ask customers to review their internal security amid the incident. “We reiterate that the SWIFT network itself was not breached. Our priority at this time is to investigate the interim findings and to encourage customers to review and, where necessary, to reinforce their local operating environments,” a Swift spokeswoman said.

While FireEye did not identify suspects, it blamed “an uncategorised threat group” saying such groups had been active “within other customer networks in the financial industry, where these threat actors appear to be financially motivated, and well organised.” The report also said, “The security breach of the Swift environment is part of a much larger breach that is currently under investigation.”

The hunt for the perpetrators has been joined by the Federal Bureau of Investigation who met with Bangladeshi police officials in Dhaka. The US investigators would assist the “transborder elements of the crime,” said a senior police official. The breach has resulted in the resignation of the central bank governor Atiur Rahman, who took “moral responsibility” of the incident. The money wired to Philippines were apparently used to buy gambling chips and ended up at least one local casino and two gambling junket operators, said the Philippine's Anti-Money Laundering Council. Dhaka officials said the money that went to Sri Lanka, went to the account of a newly formed non-governmental organisation.


comments powered by Disqus



to the free, weekly Asian Voice email newsletter