THE HILL
 
comment
Print

FBI warns cyber criminals are targeting banks to conduct wire fraud

By Jennifer Martinez - 09/18/12 12:57 PM ET

The FBI has issued a fraud alert warning that cyber criminals are hacking into the computer systems of banks and credit unions to send unauthorized wire transfers overseas that range from nearly half a million to one million dollars.

In the fraud alert released on Monday, the FBI said it has spotted "a new trend" where cyber criminals are using simple hacking tools such as spam and spear-phishing emails and keystroke loggers to compromise bank employees' computer accounts and steal their login credentials. With the stolen credentials, the hackers can then access a bank's internal networks and third party systems to initiate unauthorized wire transfers.

These illicit wire transfers have ranged from $400,000 to $900,000, the FBI said. Most of the reported cases involved small- to medium-sized banks, but a few large banks have also been affected, the agency added.

Increasing the cybersecurity of financial networks, electric supply, water systems and other critical infrastructure has been a top policy issue for the White House. The Obama administration is currently crafting a cybersecurity executive order that would create a voluntary program where companies operating this key infrastructure would verify that their computer systems meet a set of security standards.

The White House is taking action as Congress is gridlocked on cybersecurity legislation after Senate Republicans blocked a sweeping cybersecurity bill from Sen. Joe Lieberman (I-Conn.) this summer. They argued that it took too great of a regulatory approach and warned that it would prevent industry from properly securing their computer systems.

Financial institutions have generally argued that they're already taking the proper steps to safeguard their computer systems and networks from probing hackers. But breaches have happened from time to time, and the Wall Street Journal reported last year that federal investigators are looking into incidents where hackers have tapped into the computer network of the company that runs the Nasdaq Stock Market.

The FBI fraud alert raises fresh concerns about whether the right cybersecurity measures are in place at banks and credit unions to protect their consumers' money from cyber wire fraud.

The alert noted that in one case a hacker was able to raise the wire transfer limit on a customer's account so they were allowed to illicitly transfer a larger sum of money. Even more disconcerting, the FBI observed that most of the failed wire transfers didn't go through only because the hacker had entered the account information incorrectly.

The alert said hackers gain access to bank employees' log in credentials by sending targeted spam or spear-phishing emails to employees at financial institutions. These emails appear to be from someone the employee knows and prompts them to click on an infected link that lets the hacker compromise their account.

The hackers were able to use these login credentials to circumvent authentication methods used by financial institutions to spot fraudulent activity happening on their networks.

The FBI listed a series of recommendations in the alert that banks and credit unions can follow to prevent these authorized wire transfers. The recommendations included educating employees on the threats posed by clicking on links and attachments in unsolicited emails, not allowing employees to access email systems or the Web on the same computers used to initiate payments, and barring employees from accessing administrative accounts from their home computers.


Source:
http://thehill.com/blogs/hillicon-valley/technology/250095-fbi-warns-cyber-criminals-are-targeting-banks-to-conduct-wire-fraud
Phillip J. Bond’s ‘Tech Execs’ appears here on The Hill's Hillicon Valley Blog occasionally.

More Videos »

Hillicon Valley Twitter - Click to follow
More From The Web
bloglogo

More Briefing Room »

More Congress Blog »

More Pundits Blog »

More Twitter Room »

More Hillicon Valley »

More E2-Wire (Energy) »

More Ballot Box »

More On The Money »

More Healthwatch »

More Floor Action »

More Transportation »

More DEFCON Hill »

More Global Affairs »

More In The Know »

More RegWatch »

Get latest news from The Hill direct to your inbox, RSS reader and mobile devices.