There may be a time and a place for frugality, but bank security is neither. $10 switches cost Bangladesh’s central bank a stunning $81 million in a hack that experts are attributing, to some degree, to stinginess. An investigation into one of the largest cyber heists in history has revealed that the bank was left exposed to attacks because it was completely devoid of a firewall, and worse yet, “used secondhand, $10 switches.”
Experts say that poor security and hardware both contributed to the massive money loss, and in particular, the $10 routers have made it more difficult for investigators like Mohammad Shah Alam, head of the Forensic Training Institute of the Bangladesh police’s criminal investigation department, to do their jobs. Alam notes that the switches “collected very little network data that could be used to pinpoint the hackers and shed light on their tactics.”
Back in February, hackers were able to gain access to the core network of the Bangladeshi bank, and took advantage of this opportunity to move cash to their accounts from Bangladesh’s accounts at the Federal Reserve Bank of New York. Apparently, the only reason that the attackers weren’t able to make off with more (think billions rather than millions of dollars) was a spelling mistake — bank staff noticed the typos and prevented any further damage (though $81 million is bad enough). Authorities say that the majority of the funds have yet to be found.
Security experts seem horrified by the blatant lack of protection measures the central bank took to guard against such attacks. “You are talking about an organisation that has access to billions of dollars and they are not taking even the most basic security precautions,” Jeff Wichman, a consultant with cyber firm Optiv, told Reuters. Worse yet, there may be other banks in the world that are similarly unprepared.
Related: New malware GozNym is stealing millions from U.S. bank account holders
Also taking some blame for the heist is global payment network SWIFT, to which the Bangladesh bank’s networks were connected. “It was their responsibility to point it out but we haven’t found any evidence that they advised before the heist,” Alam said of the payment network. SWIFT has only said that the attack was the result of “an internal operational issue at Bangladesh Bank,” and that its own core messaging services were not affected.
Regardless, the magnitude of this breach may finally convince other financial institutions to improve their own security practices, and not pinch pennies at the risk of losing millions.
- Here are all the places that support Apple Pay, including 2 million stores and Singapore
- Billion dollar bank heist foiled by one spelling mistake
- Home Depot agrees to pay customers $20M to settle that massive 2014 hack
from Planet GS via John Jason Fallows on Inoreader http://ift.tt/1VJYcdu
Lulu Chang
More Stories
‘My 401k Misses You’: Black Woman Pumped To Meet Donald Trump In Philadelphia – July 18, 2023 at 04:56PM
Energy Provider Warns of Impending ‘Crisis,’ ‘Blackout Conditions’ Driven By Biden Plans – July 18, 2023 at 04:20PM
Dog starts barking at cows crossing a bridge, so the cows stop to have a look. – July 17, 2023 at 02:27PM