Up to a dozen banks are reportedly investigating potential SWIFT breaches

The incidents are part of a larger trend of cybercriminals targeting financial institutions directly instead of customers

More banks have reportedly launched investigations into potential security breaches on their networks after hackers stole US$81 million from the Bangladesh central bank earlier this year through rogue SWIFT transfers.

Security firm FireEye, which was hired to investigate the Bangladesh bank attack, was also called in to look for possible compromises at up to 12 additional banks, Bloomberg reported Thursday, citing an unnamed source familiar with the investigations.

Most of the banks are from Southeast Asia but include banks in the Philippines and New Zealand, Bloomberg reported.

The Bangladesh bank heist was pulled off with the help of custom malware that was designed to interfere with the software used by banks to perform transactions on the SWIFT global financial network. Similar malware was later found on the systems of a bank in Vietnam.

The Brussels-based Society for Worldwide Interbank Financial Telecommunication (SWIFT), a cooperative society owned by thousands of financial institutions, recently warned customers it is aware of "a number of fraudulent payment cases where affected customers suffered a breach in their local payment infrastructure."

SWIFT’s own network, services, and software were not compromised, the cooperative said. But SWIFT launched an initiative to share cyberthreat information with customers and help them protect their own environments from intrusions and malware.

These latest attacks that sought to abuse the SWIFT infrastructure are part of a larger trend observed over the past two years in which cybercriminals have targeted financial institutions directly instead of going after their customers.

FireEye declined to comment on the new investigations mentioned in the Bloomberg report, but the company has recently published research about targeted attacks against banks in the Middle East.

Those attacks consisted of rogue emails with macro-enabled XLS attachments that downloaded a modified penetration testing tool called Mimikatz, which can be used to steal sensitive credentials from Windows systems.

Last year, security researchers from Kaspersky Labs identified three separate cybercriminal groups that used malware programs to infect bank systems and steal money. One of them used a malware program called Carbanak to steal millions of dollars from hundreds of financial institutions in at least 30 countries.

Security firm Trend Micro recently analyzed the malware used in an attempted cyber theft attempt at Tien Phong Commercial Joint Stock Bank in Vietnam. The malicious program was designed to interact with the SWIFT messaging system and had the SWIFT codes of eight banks hardcoded inside.

The Trend Micro researchers did not name the targeted banks but said six of them are located in the Asia Pacific region and the other two are from the U.S. and Europe.

"We believe that it’s no coincidence that most of their targets are based in Asia," the Trend Micro researchers said in a blog post. "These cyber crooks are perhaps familiar with the banking landscape and challenges of cybersecurity in the region. Despite major improvements in security, certain banks in Asia still lag behind those in U.S. and Europe."

Join the PC World newsletter!

Error: Please check your email address.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Essentials

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?