“In times of radical change, the learners inherit the earth, while the learned find themselves perfectly equipped for a world that no longer exists.” - Erik Hoffer
Showing posts with label online banking. Show all posts
Showing posts with label online banking. Show all posts

October 4, 2010

There's good news and bad news regarding U.S. eBanking thefts

These days, all you have to do is blink and you'll miss something on the Internet. I was off-line for a day or two and when I came back on "the net" I discovered that the FBI, working in concert with police officials in Great Britain and the Ukraine moved to break up one of the groups using the ZeuS worm to steal funds from individuals, businesses and government agencies. Brian Krebs, as usual, kept track of all the developments on his KrebsonSecurity blog. If you missed the details of the story in your local paper, you can follow the progress of the story using the links below:
Sep. 29, 2010  "19 Arrested in Multi-Million Dollar ZeuS Heists"   (UK)
Sep. 30, 2010  "11 Charged In ZeuS & Money Mule Ring"   (UK)
Sep. 30, 2010  "U.S. Charges 37 Alleged Money Mules"  
Oct.     2, 2010  "Ukraine Detains 5 Individuals Tied to $70 Million in U.S. eBanking Heists"

The above is indeed great news. According to Krebs, "Investigators say the Ukrainian gang used the software to break into computers belonging to at least 390 U.S. companies, transferring victim funds to more than 3,500 so-called “money mules,” individuals in the United States willingly or unwittingly recruited to receive the cash and forward it overseas to the attackers."

The bad news is that there are still other groups using ZeuS to obtain account and password information, then making fraudulent electronic fund transfers and money mules to move the money out of the country and into the hands of the thieves at the top of the organization. Law enforcement and banking officials need to do a better job of letting users know how these groups operate and how users can improve the security of their individual and commercial accounts to prevent these thefts in the first place.

Once again, if you don't have KrebsonSecurity on your RSS feed or your daily reading list, you're missing an important source of information about keeping your own computers or your company's computers secure.

April 26, 2010

These banking credentials thefts are getting too close to home!

Last Thursday, April 22nd, I read that the outbreak of online bank transfer thefts had hit western Arkansas at the First National Bank of Fort Smith and a local alarm company. I can't help but wonder why these stories are not starting to show up on TV news or local newspapers. It's difficult for business people to take proper actions on their own to protect their financial transactions unless they know about the nature of these crimes.

This morning, I learned from another KrebsonSecurity news story that Aaron Jacobson at  Authentify has posted the list of 43 business victims linked to a Google interactive map. As Krebs points out, these online banking thefts are clustered mostly in the Northeast and Midwest.

My own first thought on viewing the map was for the victims. These business people are trying to pay creditors and make payrolls only to find their bank accounts looted. The thefts are located far enough apart that it's easy for local political news and traffic accidents to push the stories off the front page. These thefts are just quiet, middle-of-the-night online banking transfers. The money moves from a business account to the accounts of several money mules who then forward the cash overseas in return for a small "commission."

There are no smoking guns or violent car chases, so there are no videos on the nightly news, no pictures and no front page stories. I can't help but wonder what the news media would say and what would be the FBI's reaction if the old Dillinger gang or Bonnie and Clyde had hit that many banks across the nation. But under the current banking law, the banks aren't the victims, their newly impoverished individual account holders are the victims!

So honest business people are still losing money with each new incident, bankers bemoan the criminal activity, declare the loss is the business owner's responsibility and the short-handed and short-sighted news media show cute pictures of children playing in the local park. I'll let the bankers, MBA's and lawyers among you sort out the details and the legalities of commercial bank accounts. There ARE ways to prevent this sort of scam and both sides involved in this type of transaction need to use them! See the update at Arkansas is NOT immune to cybercrime!

I'm just sorry that it will take many more local and regional victims before the risks of online banking becomes important enough to reach the front page.

March 23, 2010

Arkansas is NOT immune to cybercrime!

Brian Krebs, the former Washington Post reporter now writing at KrebsonSecurity.org, has confirmed that cyber-criminals struck an Arkansas regional water utility and a New Jersey town recently moving money from the government accounts by online transfers.
...On March 4, organized crooks stole roughly $130,000 from North Garland County Regional Water District, a public, nonprofit utility in Hot Springs, Ark. Again, thieves somehow broke into the utility’s online bank account and set up unauthorized transfers to more than a dozen individuals around the country that were not affiliated with the district.
The investigation continues and the public utility and bank have recovered about half of the losses. You can read the complete article at: http://www.krebsonsecurity.com/2010/03/organized-crooks-hit-nj-town-arizona-utility/#more-1918

Update: 3/30/10  I can't say it any better. "Online Thieves Take $205,000 Bite Out of Missouri Dental Practice." Brian drills down into the details (pun intended) at: http://www.krebsonsecurity.com/2010/03/online-thieves-take-205000-bite-out-of-missouri-dental-practice/

A public library in Florida, a school district in New York, a manufacturing firm in Texas, a water utility in Arkansas, and those are just a few recent cases. Keep in mind that commercial accounts are handled differently than consumer accounts. Brian reminds us, "Let me be clear: The advice was aimed not at consumers, but at small to mid-sized companies that may not have a full-time IT/security staff, and who rely on one or two people to handle their bank accounts and payroll online."

This type of online computer theft uses infected computers to make electronic transfers from uninsured commercial bank accounts. If a cyber-thief gains access to your login and password, the commercial account holder is on the hook - not the bank. The bank was following "your instructions." These crimes are happening from coast to coast, but you're not reading about the details in many daily newspapers or on national TV news programs. You can find more examples in Brian's earlier articles in the Washington Post at: http://voices.washingtonpost.com/securityfix/small_business_victims/

I haven't found any better articles regarding how small businesses, government agencies and non-profits can try to protect themselves than Brian's earlier articles on the topic. My suggestion is review all three of the articles and do what you think works best for your organization.
"Avoid Windows Malware: Bank on a Live CD," WashingtonPost.com, Oct. 12, 2009
http://voices.washingtonpost.com/securityfix/2009/10/avoid_windows_malware_bank_on.html
"E-Banking on a Locked Down (Non-Microsoft) PC," WashingtonPost.com, Oct. 12, 2009
http://voices.washingtonpost.com/securityfix/2009/10/e-banking_on_a_locked_down_non.html
"E-Banking on a Locked Down PC, Part II," WashingtonPost.com, Oct 20, 2009
http://voices.washingtonpost.com/securityfix/2009/10/e-banking_on_a_locked_down_pc.html