Archive for the ‘Banking Industry’ Category


E-BANDITS HIT CA ESCROW COMPANY FOR NEARLY HALF A MILLION DOLLARS

Tuesday, July 27th, 2010

in-escrow-sign3

Redondo Beach-based firm Village View Escrow was recently hit for $465,000 by thieves who hijacked the company’s bank account electronically.

The cyber-thieves sent a fraudulent e-mail to the owner and to her assistant. Both women opened the e-mail, which secretly released a password-stealing virus onto their respective computers. Armed with the banking login information for both women, the hackers deactivated the customary advisory service and used the requisite two login credentials to issue electronic instructions to the escrow company’s bank to wire out various amounts of money to various other accounts. In total, 26 wire transfers were ordered, all of which were executed because of the two (apparently) legitimate login credentials. No confirming advisory messages for each transfer were sent to the escrow company because the cyber-thieves had disabled that notification feature using the stolen login credentials.

Some 20 individuals around the world received the wired money and re-transmitted it to the cyber-thieves after withholding a portion as payment for their services. Such intermediaries are known in the business as “mules”, and are often clueless about the criminal nature of their involvement in the scheme.

Working frantically after the theft was discovered, the escrow company owner managed to get $70,000 of the fraudulent wire transfers reversed. That left a $395,000 shortfall which the bank will not reimburse. The escrow owner had to take a loan to cover the shortfall at 12%, and can not even draw a salary as she tries to put the company back on its feet.

Several of the features built into InterComputer’s Trusted Banking solution would have stopped the illicit use of legitimate banking credentials before any wire transfers could have been ordered by the cyber-thieves.


THE OTHER SHOE DROPS: BRAZEN CYBER CRIMINALS ROB BANK

Wednesday, June 2nd, 2010

In most reported cyber crimes involving theft of funds, the victim is a small business or municipality. In a rare case, cyber thieves recently stole money directly from a credit union’s internal funds.

On May 20, Treasury Credit Union of Salt Lake City, Utah, became the victim of more than 70 unauthorized transfers from internal accounts. All the transfers were in amounts under $5000, but the total stolen was “in the low six figures”.

blogpic

The FBI is investigating the case, in which many of the transfers were actually executed by “money mules”, i.e., people recruited for that specific purpose. Some of the “mules” were apparently unwitting about the criminal nature of their activity. The “brains” behind this type of cyber crime are often located in Eastern Europe (in this case, Ukraine).

The key to the crime was the furtive planting of a “Trojan horse” program on the computer of one of the credit union’s employees. That malware program forwarded the employee’s on-line banking credentials (user name, password, etc.) to the criminals in the Ukraine, who used them in an orchestrated manner to steal as much money as possible before the crime was discovered and halted.

InterComputer’s Trusted Banking solution is designed expressly to prevent the compromise of electronic identities and communications in electronic banking and insure against losses from cyber crime of any kind.


CYBERTHIEVES HIT MISSOURI DENTAL PRACTICE FOR $200K

Thursday, April 1st, 2010

steve-martin-dentist

Yes, this IS going to hurt a bit.

On March 22, cyberthieves penetrated a computer at the Smile Zone dental practice in Springfield, MO, and transferred over $200,000 from the practice’s bank account in 11 different transfers.

The investigation is ongoing, but it appears likely the thieves used an application of ZeuS, Zbot, or SpyEye crimeware to hijack the computer and instigate the wire transfers. “Money mules”, people who knowingly or unknowingly serve as relay stations for money transfers, were also involved in this crime.

Banks reliably deny any liability when their customers’ online banking credentials are stolen or compromised. Unlike consumers, who enjoy legal limitations on cybercrime losses, businesses can only try to reverse the illegal transfers and hope for the best. If the illegal transfers are not undone within the first 24 hours, the likelihood of recovering the stolen money falls dramatically.

In this particular case, the bank only required a user name and password to conduct online banking transactions. That information was, apparently, easily hijacked by the thieves, who then posed as the dental practice and wired the money out.

InterComputer’s Trusted Banking solution is designed expressly to prevent the compromise of electronic identities and communications between banks and their clients, and insure against losses from cybercrime of any kind.


BANK SUES VICTIMIZED CUSTOMER OVER CYBERCRIME

Monday, March 29th, 2010

When cyberthieves stole more than $800,000 from the accounts of a machine equipment company in Texas, one might expect the victim to seek redress from their bank. To date, such compensation for electronic banking losses has been exceedingly rare as banks have carefully avoided setting such a precedent. A number of victims have sued their banks in an attempt to recover their losses, but in this case the bank has set a new precedent: it has preemptively sued the victim.

InterComputer’s Trusted Banking solution is designed to prevent cybercrimes such as this case.

For more on this story, click here.


ON-LINE BANKING SECURITY – HOW MANY FACTORS ARE ENOUGH?

Wednesday, March 3rd, 2010

On-line banking security is increasingly the subject of news reports of various types of cybercrime, usually involving electronic identity theft and the illegal transfer or diversion of funds from the victim’s bank account. As the problem grows in size, legal challenges are increasingly attempting to hold banks liable for losses from such crimes. Banks are, of course, very reluctant to accept such liabilities and are battling the problem with both legal and technological strategies.

Typically, banks are offering “two-factor authentication” as a de facto industry standard for on-line banking security. The following video, provided by ZD Net, clearly explains what two-factor security is and how it works:

The problem with two-factor security is that hackers have now discovered how to defeat it in real-time. The following article from the MIT Technology Review details an actual case where a construction company lost almost half a million dollars to such an attack:

http://www.technologyreview.com/computing/23488/?a=f

The authentication of a customer’s electronic identity and the correct application of the customer’s authority limits are the very reasons for on-line banking security. If either objective is not reached, the system has failed and the results can be disastrous.

InterComputer’s fully-insured InterOperating System (IOS) begins with a three-factor approach adding something the user is (a biometric measurement) in addition to something he knows and something he has. This approach, combined with many other design, architectural and procedural factors, combine to create an electronic “trusted path” and result in InterComputer’s IOS being the only underwritten electronic transaction system commercially available today.

To learn more about InterComputer’s Trusted Banking solution, click here.


ARE YOU HELPING YOUR HACKER?

Monday, February 8th, 2010

Password overlap is the practice of using one on-line password at more than one website. At first glance, it seems obvious that doing this would make it far easier for a hacker who steals the password at a less-secure website to turn around and use it to “walk in the front door” of a very secure website—like your bank, for example. But who would be dull enough to use their online-banking password for any other website?

It turns out that, according to a recent msnbc blog post by Bob Sullivan ( http://redtape.msnbc.com/2010/02/for-years-computer-security-experts-have-been-preaching-that-users-should-never-share-the-same-password-across-their-connecte.html), nearly 75% of 4 million people surveyed do exactly that. Worse, about half of all consumers use both their banking password and their banking user name at other sites. In such cases, any hacker who steals them from an unsecure site can have instant, unfettered access to the rest of your cyber-life as well as your real cash and personal information.

While most consumers are not willing to create and maintain a unique user name/password combination for every website they use, your on-line banking login information should be unique and used only for your banking website. Sullivan’s post wisely suggests that if unique logins are too much for you to handle, you should consider creating at least three unique logins: one for your financial sites, one for sites that store your personal information, and one for generic logins.

Fortunately, most financial institutions provide additional security layers for your on-line access. Nevertheless, increasingly sophisticated cybercriminals are successfully breaching on-line banking security to the tune of hundreds of millions of dollars per year. To date, banks have refused to reimburse their customers for losses due to cybercrime and have vigorously worked to prevent the establishment of any legal precedent requiring them to do so.

That is why InterComputer Corporation is working with the largest U.S. banks to implement an insured electronic transaction environment that covers all parties with complete underwritten loss recovery.


COURT ALLOWS LAWSUIT AGAINST BANK FOR ON-LINE THEFT

Monday, February 8th, 2010

The issue of who pays when a customer’s on-line access to bank accounts is compromised has been simmering ever since on-line banking began. Banks have, understandably, been exceedingly reluctant to accept liability when a customer’s electronic banking identity and password are compromised and money disappears from their accounts. Financial institutions have spent heavily to prevent the establishment of any precedent that would result in banks being on the hook for cybercrime losses. Until now, no court in the U.S. has actually found any financial institution liable in such a case.

However, recent news reported in Computerworld Security (http://www.computerworld.com/s/article/9137451/Court_allows_suit_against_bank_for_lax_security) chronicles a decision by an Illinois District Court to allow such a lawsuit against Citizens Financial Bank to proceed to trial.  You can see another view of this case at darkreading.com (http://www.darkreading.com/database_security/security/attacks/showArticle.jhtml?articleID=220100950).

This incident is a good example of how angry cybercrime victims are and how nervous banks are. In this case, someone acquired the customer’s account name and password and used them to steal $26,000 from the customer’s home equity line of credit.  Unless a pre-trial settlement is reached, the bank will obviously spend many times that amount to defend itself in court and avoid setting a costly precedent.

The victims in this case are not alleging that the bank violated its cyber security policies, or even that the bank was the source of the name/password leak. They are alleging that the bank was negligent for not providing stronger protection against cybercrime. Specifically, the victims assert that the bank should have offered “two-factor authentication”, which relies not only on what the user knows (ID and password) but what the user has (a security token).

Unfortunately, even two-factor security is no longer any guarantee that on-line access to bank accounts is secure, as reported in this ZD-Net article (http://blogs.zdnet.com/security/?p=4402.)

InterComputer’s solution utilizes three-factor authentication (plus an “out of band” protocol) as just one part of one of the seven layers of protection built into every application.  Nevertheless, the true value of InterComputer’s profound technological superiority to current industry practices is that it is insurable. Underwritten Insurance against financial loss, lost business, and third party liability from cybercrime will allow bank information security officers (and their customers) to sleep well at night.

If you were the bank’s chief security officer, which solution would you choose: one that promised tough security only, or one that delivered cutting-edge, patent-pending security along with an insured guarantee?


ON-LINE BANKING CYBERCRIME REACHES $100 MILLION MARK

Monday, February 8th, 2010

The Federal Bureau of Investigation recently announced that cybercrime attacks on banking transactions in the U.S. have the reached the $100 million level.

According to the Internet Crime Complaint Center (www.ic3.gov), which is jointly operated by the FBI, the National White Collar Crime Center, and the Bureau of Justice Assistance, malware and phishing schemes are largely responsible for the “significant increase” in cybercrime against Internet banking. Most of the victims are small and medium-sized businesses and public institutions such as municipal governments, schools, and court systems.

Typical schemes involve the secret insertion of malware, such as a keystroke logger program, onto the victim’s computer. The cyber thieves then use the information stolen by the keystroke logger to access the victim’s bank accounts themselves.  Many of the victim’s bank accounts were held at local community banks and credit unions.

Interestingly, the FBI noted that “the threat stems not only from the malware involved in these cases, but the vulnerabilities presented by the lack of controls at the financial institution…” In other words, poor Internet security systems at the bank often contributed to the problem.

InterComputer’s unique transaction insurance coverage covers both the bank and its clients in such cases. It completely resolves the security issues around Internet banking and relieves both the bank and its customer of liability for any losses caused by cybercriminals and ineffective security precautions on either side.

For more information, please click (http://www.ic3.gov/media/2009/091103.aspx), http://www.eweek.com/c/a/Security/FBI-Online-Banking-Attacks-Reach-100-Million-Mark-785125/ and www.intercomputer.com.