{"id":88760,"date":"2016-04-27T07:14:11","date_gmt":"2016-04-27T11:14:11","guid":{"rendered":"http:\/\/countingpips.com\/?p=88760"},"modified":"2016-04-27T07:14:11","modified_gmt":"2016-04-27T11:14:11","slug":"bank-heist-exposes-staggering-security-flaws","status":"publish","type":"post","link":"https:\/\/www.investmacro.com\/forex\/2016\/04\/bank-heist-exposes-staggering-security-flaws\/","title":{"rendered":"Bank Heist Exposes Staggering Security Flaws"},"content":{"rendered":"<div id=\"inves-591096394\" class=\"inves-below-title-posts inves-entity-placement\"><div id =\"posts_date_custom\"><div align=\"left\">April 27, 2016<\/div><hr style=\"border: none; border-bottom: 3px solid black;\">\r\n<\/div><\/div><p>By <a href=\"http:\/\/WallStreetDaily.com\/\"><u>WallStreetDaily.com<\/u><\/a> <img loading=\"lazy\" decoding=\"async\" class=\"attachment-home-th size-home-th wp-post-image\" style=\"display: block; margin-bottom: 5px; clear: both;\" src=\"http:\/\/www.wallstreetdaily.com\/wp-content\/uploads\/2016\/04\/bangladesh-central-bank-hacked.jpg\" sizes=\"auto, (max-width: 510px) 100vw, 510px\" srcset=\"http:\/\/www.wallstreetdaily.com\/wp-content\/uploads\/2016\/04\/bangladesh-central-bank-hacked-300x176.jpg 300w, http:\/\/www.wallstreetdaily.com\/wp-content\/uploads\/2016\/04\/bangladesh-central-bank-hacked.jpg 510w\" alt=\"bangladesh-central-bank-hacked\" width=\"510\" height=\"300\" \/><\/p>\n<p>If you like stories about daring bank heists, you\u2019re gonna love this.<\/p>\n<p>One of the greatest thefts of all time occurred earlier this year \u2013 one where the robbers managed to escape with an impressive $80 million haul.<\/p>\n<p>And yet, it could\u2019ve been avoided so easily.<\/p>\n<p>The story is an unusual combination of sophisticated genius and a grossly negligent lack of security and oversight by bumbling bankers.<\/p>\n<p>In fact, the robbers could\u2019ve actually made off with $900 million more.<\/p><div id=\"inves-1414064117\" class=\"inves-in-content inves-entity-placement\"><hr style=\"border: 1px solid #ddd;\">\r\n<div id=\"inpost_ads_header\">\r\n<p style=\"font-size:10px; float:left; color:#666;\">Free Reports:<\/p><\/div>\r\n<div id=\"inpost_ads\"> \r\n<p style=\"font-size:15px; float:left;\"><a href=\"https:\/\/goo.gl\/1ApBOV\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/investmacro.com\/wp-content\/uploads\/2018\/06\/graph_techs_PD.png\" align=\"left\" width=\"80\"  height=\"55\"\/><\/a>\r\n\t     <a href=\"https:\/\/goo.gl\/1ApBOV\"><b><u>Get Our Free Metatrader 4 Indicators<\/u><\/b><\/a> - Put Our Free MetaTrader 4 Custom Indicators on your charts when you join our Weekly Newsletter<\/p><br><br>\r\n<br>\r\n<br>\r\n<p style=\"font-size:15px; float:left;\"><a href=\"https:\/\/goo.gl\/f3RrHX\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/investmacro.com\/wp-content\/uploads\/2019\/01\/cot_pie_80.png\" align=\"left\" width=\"80\"  height=\"55\"\/><\/a>\r\n\t    <a href=\"https:\/\/goo.gl\/f3RrHX\"><b><u>Get our Weekly Commitment of Traders Reports<\/u><\/b><\/a> - See where the biggest traders (Hedge Funds and Commercial Hedgers) are positioned in the futures markets on a weekly basis.<\/p><br><br>\r\n<\/div>\r\n<hr style=\"border: 1px solid #ddd;\">\r\n<br><\/div>\n<p>So what happened?<\/p>\n<h2>The Most Ridiculous Thing You\u2019ll Hear All Year<\/h2>\n<p>Details are still emerging, but the basic story is that hackers got the passwords of Bangladesh\u2019s central bank to SWIFT \u2013 the international payments system used for global interbank transfers.<\/p>\n<p>Now, SWIFT is obviously a very secure system \u2013 or it was until last month.<\/p>\n<p>It\u2019s a closed system, which means you can\u2019t access it from the internet. To get in, you have to have control of one of the computers connected to its network. That\u2019s where the robbers\u2019 sophistication comes in.<\/p>\n<p>They spent weeks infiltrating the Bangladeshi computers, logging keystrokes, learning passwords, figuring out how to get from the internet to a SWIFT-connected computer.<\/p>\n<p>Needless to say, far from an easy task.<\/p>\n<p>But it was made much easier, thanks to some staggeringly stupid behavior on the part of the Bangladesh Central Bank.<\/p>\n<p>Normally, a connection from a secure to a non-secure computer is protected by a firewall \u2013 software written into computers, switches, and routers that detects which connection attempts are legitimate and which aren\u2019t.<\/p>\n<p>As you probably know, firewalls are so common these days that if you go to Best Buy and buy the cheapest computer, it will have a firewall pre-installed on it.<\/p>\n<p>Ready for the blindingly stupid part?<\/p>\n<p>The central bank had no such firewalls!<\/p>\n<p>In fact, Reuters reported that it used old switches, which sell for about $10 each.<\/p>\n<p>I\u2019m sorry\u2026 I know Bangladesh is a poor country, but it can afford better security than that when it\u2019s protecting $1 billion.<\/p>\n<h2>A \u201cSWIFT\u201d Getaway<\/h2>\n<p>Once into the SWIFT system, the robbers started sending requests to transfer nearly $1 billion from the Bangladesh Bank account at the New York Federal Reserve to banks in Sri Lanka and the Philippines.<\/p>\n<p>At first, bankers in New York approved the transfers. Why wouldn\u2019t they? They came over a secure network from a trusted, known connection.<\/p>\n<p>But they eventually became suspicious. Why?<\/p>\n<p>Because some of the requests were to personal bank accounts. This is a red flag, since large central bank transfers are generally to other central banks, other bank \u201chouse accounts,\u201d and occasionally to large companies like defense contractors.<\/p>\n<p>The Fed employees started to hold up the transfers and used SWIFT to ask the Bangladeshis for more information. But nobody answered.<\/p>\n<p>It turns out that the weekend in Bangladesh is on Friday and Saturday \u2013 and most of Bangladesh\u2019s bankers had gone home by the time the request came in.<\/p>\n<p>The robbers also complicated matters by shutting down Bangladesh\u2019s SWIFT terminals so that the skeleton crew on Fridays was unable to get into the system and see the Fed requests.<\/p>\n<p>But that crew <em>was<\/em> able to get into the system on Saturday \u2013 at which point, it asked the Fed to stop all payments until things were cleared up.<\/p>\n<p>But of course, Saturday is the weekend in the United States, too \u2013 and nobody saw those requests until Monday.<\/p>\n<p>By the time the scheme was discovered, it was mostly too late.<\/p>\n<h2>How a Typo Cost $20 Million<\/h2>\n<p>Over $100 million of fraudulent transfers had been approved and the money had been withdrawn from the destination accounts.<\/p>\n<p>One eagle-eyed banker in Sri Lanka did allow about $20 million to be recovered \u2013 but only because the robbers spelled the word \u201cfoundation\u201d incorrectly on the transfer order.<\/p>\n<p>Yep, a spelling error cost our brilliant (but stupid) culprits another $20 million!<\/p>\n<p>The other $80 million is still missing. But where?<\/p>\n<p>It was quickly removed from accounts in the Philippines and \u2013 believe it or not \u2013 used to buy casino chips.<\/p>\n<p>This is where the robbers got crafty again.<\/p>\n<p>You see, in almost every country where casinos are legal, they\u2019re required to cooperate with banking authorities on money-laundering matters. <em>Except in the Philippines.<\/em> So nobody knows who bought the chips. This was a weakness in the banking system that had been known for years.<\/p>\n<p>But this crime may yet be solved.<\/p>\n<h2>Fixes for a Flawed System<\/h2>\n<p>After all, $80 million is a big haul. Especially when it comes in the form of casino chips!<\/p>\n<p>So even if they\u2019re sold in the streets at a discount, a stream of people coming in and cashing in millions of chips might lead authorities back to the culprits.<\/p>\n<p>Regardless of how this tale ends, however, it points to several weaknesses in the international banking system \u2013 weaknesses that cost real money and undermine confidence in the banking system.<\/p>\n<p>But there are improvements that could be implemented to prevent another heist:<\/p>\n<ul>\n<li>There\u2019s no doubt that the Bangladesh central bank\u2019s security systems appear to be inexcusably weak. It\u2019s probably not the only financial organization there with porous security, either. Other banks must start demanding audits on the systems so that a weak link in the security chain doesn\u2019t cause a catastrophic failure somewhere else along the line.<\/li>\n<\/ul>\n<ul>\n<li>People need to monitor transactions around the clock. If that means staffing the bank on Friday in countries where Friday is a weekend day, so be it. And there needs to at least be a skeleton crew on hand at all times when there\u2019s the possibility of a transaction occurring.<\/li>\n<\/ul>\n<ul>\n<li>Computers need to be smarter. It was only when Fed officials became suspicious of the recipients of the money that the alarm was raised. Computers should flag this. For large transactions, the recipient\u2019s bank should be asked whether the destination account is one where a huge influx of money would be unusual \u2013 and that bank should be able to answer instantly, with no human intervention. If a credit card company can flag suspicious transactions for even small amounts, it should be a no-brainer to design a smart computer system for multi-million-dollar transfers.<\/li>\n<\/ul>\n<ul>\n<li>Get tough with money-laundering regulations. The Philippines declined to apply its rules to casinos because it wanted the industry to grow. But how about if the country were removed from the international banking system entirely for a few months? It wouldn\u2019t take long for it to figure out that a single industry\u2019s growth is less important than being involved in global trade and banking transactions.<\/li>\n<\/ul>\n<p>The story also highlights the critical need for greater cyber security in general \u2013 no matter where it is.<\/p>\n<p>And there\u2019s the problem.<\/p>\n<h2>How to Take Advantage of a Growing Global Problem<\/h2>\n<p>Spending on cyber security is sorely lacking \u2013 both on the part of governments, banks, and corporations.<\/p>\n<p>Yet security breaches are shooting 60% higher per year.<\/p>\n<p>We\u2019ve already seen the consequences of widespread, devastating cyber attacks many times \u2013 be they at government departments, banks, retailers, or elsewhere. It cripples productivity, compromises safety and security, and damages trust and loyalty.<\/p>\n<p>The U.S. government calls cyber security \u201cone of the most serious economic and national security challenges we face as a nation.\u201d<\/p>\n<p>You can see why, given that 90% of business assets are already digital, data generation continues to soar, and billions are pouring into the Internet of Things.<br \/>\nEverything is eventually going to be connected to the internet \u2013 and therefore, vulnerable to attack.<\/p>\n<p>Power grids, banks, hospitals, cars, airplanes, communication networks\u2026 the consequences of a crippling security hack are frightening.<\/p>\n<p>And it\u2019s not just possible\u2026 it\u2019s likely.<\/p>\n<p>This is a massive problem that needs serious attention\u2026 NOW.<\/p>\n<p>In our latest monthly issue of <em>Digital Fortunes,<\/em> we showed how investors can take advantage of this situation for profits via a super-diversified, market-leading investment. <a href=\"http:\/\/pro1.wallstreetdaily.com\/488057\/\" target=\"_blank\" rel=\"nofollow\">Go check it out here<\/a>.<\/p>\n<p>To living and investing in the future,<\/p>\n<p>Greg Miller<\/p>\n<p>The post <a href=\"http:\/\/www.wallstreetdaily.com\/2016\/04\/27\/bangladesh-central-bank-hacked\/\" rel=\"nofollow\">Bank Heist Exposes Staggering Security Flaws<\/a> appeared first on <a href=\"http:\/\/www.wallstreetdaily.com\" rel=\"nofollow\">Wall Street Daily<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By WallStreetDaily.com If you like stories about daring bank heists, you\u2019re gonna love this. One of the greatest thefts of all time occurred earlier this year \u2013 one where the robbers managed to escape with an impressive $80 million haul. And yet, it could\u2019ve been avoided so easily. The story is an unusual combination of [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-88760","post","type-post","status-publish","format-standard","hentry","no-post-thumbnail"],"_links":{"self":[{"href":"https:\/\/www.investmacro.com\/forex\/wp-json\/wp\/v2\/posts\/88760","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.investmacro.com\/forex\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.investmacro.com\/forex\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.investmacro.com\/forex\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.investmacro.com\/forex\/wp-json\/wp\/v2\/comments?post=88760"}],"version-history":[{"count":2,"href":"https:\/\/www.investmacro.com\/forex\/wp-json\/wp\/v2\/posts\/88760\/revisions"}],"predecessor-version":[{"id":88782,"href":"https:\/\/www.investmacro.com\/forex\/wp-json\/wp\/v2\/posts\/88760\/revisions\/88782"}],"wp:attachment":[{"href":"https:\/\/www.investmacro.com\/forex\/wp-json\/wp\/v2\/media?parent=88760"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.investmacro.com\/forex\/wp-json\/wp\/v2\/categories?post=88760"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.investmacro.com\/forex\/wp-json\/wp\/v2\/tags?post=88760"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}