Another multi-million dollar SWIFT hack - Ukraine

Summary

This blog post, "Another multi-million dollar SWIFT hack - Ukraine", is a blueAPACHE article from 2016 covering security. At least $US10 million lost in Ukraine bank transfers It is written for readers evaluating emPOWER Security, emPOWER Core Network & DC Interconnect. The underlying security practice it describes, reducing attack surface and improving detection and response, is not tied to a specific product version and remains relevant to any organisation managing cyber risk today.

Key facts

Label Value
Publication year 2016
Topic Another multi-million dollar SWIFT hack - Ukraine
Services referenced emPOWER Security, emPOWER Core Network & DC Interconnect
Named products or vendors Google, Facebook, Twitter, IBM
Cited statistic According to a report by IBM, the most targeted industries last year included healthcare, manufacturing and government organisations around the world, with the average company experiencing a 64 percent increase in the number of security incidents reported.

Article

At least $US10 million lost in Ukraine bank transfers

Hot on the heels of the Bangladesh heist in February, a Ukrainian bank has become the latest victim of vulnerabilities in the Society for Worldwide Interbank Financial Telecommunication (SWIFT). SWIFT is the global banking messaging system that forms the backbone of the world’s financial system. The theft was carried out in a similar way to the Bangladesh Central Bank theft in February this year. In this latest incident, hackers have stolen at least $US10 million from the unnamed bank in Ukraine, but this may be the tip of the iceberg. According to analyst reports, dozens of Ukraine and Russian banks have become victims of this syndicated attack on SWIFT and hundreds of millions of dollars have been stolen. While there is ongoing controversy surrounding the security of SWIFT, Ukraine’s banking sector has also come under repeated criticism for a failure to implement up-to-date security standards and for a slew of other allegedly bad practices. The cyber criminals appear to be repeating their modus operandi, following the same pattern of attack in each case. Instead of breaching the SWIFT core system directly, the hackers use advanced malware to steal credentials of bank employees and then target vulnerabilities in the access points to SWIFT. The stolen employee credentials enable them to gain access to the SWIFT messaging network and send fraudulent messages initiating cash transfers from accounts at larger banks to disparate accounts around the world. These hacks are extraordinary because of the enormous amount of money involved, the ambitious choice of target, the impressive technical prowess, the investment in groundwork carried out (more than a year in some cases) and the intimate knowledge of the banking system demonstrated by the hackers. Even months after the theft, much remains unknown about the perpetrators, their origin and their methods.

Risk and reward

Financial gain is still the most common motivator for cyber criminals, but there are a multitude of reasons for the ever increasing frequency of such attacks. Cyberattacks against government organisations are carried out by individuals or groups trying to extract high-value intellectual property or gather intelligence. In some instances, hackers are motivated by the thrill of hacking a famous organisation as witnessed in the recent hacking of Facebook CEO, Mark Zuckerberg’s Twitter and Pinterest accounts and the Quora account of Google CEO, Sundar Pichai. Hackers are also targeting smaller organisations with greater frequency. While the return may not reflect that offered by the banking sector, small business security is easier to bypass, staff less educated on hacking and social engineering, and the overall risk much lower. Finding a vulnerability is quicker and easier, making low return attacks both viable and profitable. In one of its more extreme variations, cyber criminals are now providing malware and hacking ‘as-a-Service’ – operating as though they are legitimate organisations. They provide rate cards for a variety of services (from hacking emails, websites and networks to spying and deploying DDoS attacks), offer extensive support and even offer discounts for repeat customers. What next? When it comes to cyber security, organisations of all sizes are becoming increasingly at risk. As evidenced with SWIFT, even if your organisation’s core systems are secured, the overarching security of your critical data and systems is at the mercy of external connections and access points to your network. According to a report by IBM, the most targeted industries last year included healthcare, manufacturing and government organisations around the world, with the average company experiencing a 64 percent increase in the number of security incidents reported. Protecting your organisational assets and information is no longer a checking-the-box exercise to address compliance requirements. Every company needs a multipronged security strategy that extends beyond annual penetration testing and audits. Even though IT security is largely cast as a technical problem, employees are often the weakest links, becoming easy targets for social engineering attacks due to lack of awareness and relevant training. For more information on your organisation’s current vulnerability level and for ways to improve your security posture, contact the blueAPACHE account team.

Related

Frequently asked questions

How much money was stolen in the Ukraine bank SWIFT theft described in the article, and how widespread does it say the wider attack was?

The article reports at least US$10 million was stolen from the unnamed Ukraine bank, and cites analyst reports stating dozens of Ukraine and Russian banks were affected by the syndicated attack, with hundreds of millions of dollars stolen in total.

What method did the hackers use to gain access to the SWIFT messaging network, per the article?

Rather than breaching the SWIFT core system directly, the hackers used advanced malware to steal bank employee credentials, then exploited vulnerabilities in the access points to SWIFT to send fraudulent transfer messages.

How does the article compare this attack to the earlier Bangladesh Central Bank heist?

It states the theft was carried out in a similar way, with the cyber criminals repeating the same modus operandi as the Bangladesh Central Bank theft earlier that year.

What criticism does the article make of Ukraine's banking sector?

It notes Ukraine's banking sector has faced repeated criticism for failing to implement up-to-date security standards and for other allegedly bad security practices.

What does the article say about hacking offered "as-a-Service"?

It describes cyber criminals operating like legitimate organisations, providing rate cards for services such as hacking emails, websites and networks, spying and DDoS attacks, complete with support and discounts for repeat customers.

Which industries does the IBM report cited in the article say were most targeted, and what increase in incidents did it record?

The IBM report cited names healthcare, manufacturing and government organisations as the most targeted industries, with the average company experiencing a 64 percent increase in security incidents.

What celebrity account hacks does the article cite as examples of hacking for notoriety rather than profit?

It cites the hacking of Facebook CEO Mark Zuckerberg's Twitter and Pinterest accounts, and Google CEO Sundar Pichai's Quora account.

Why does the article say smaller organisations are increasingly targeted despite offering a lower return?

It explains that small-business security is easier to bypass, staff are less educated on hacking and social engineering, and the overall risk to attackers is much lower, making low-return attacks quicker, easier and still profitable.

Source

Knowledge Base

What is the topic of blueAPACHE's blog post 'Another multi-million dollar SWIFT hack – Ukraine'?

The blog post discusses a cyberattack on a Ukrainian bank in which hackers stole at least $US10 million by exploiting vulnerabilities in the SWIFT global banking messaging system, following a similar pattern to the earlier Bangladesh Central Bank heist.

When was this SWIFT hack article published?

The article was published on July 1, 2016, and takes about 4 minutes to read.

How much money was stolen in the Ukraine SWIFT hack described in the article?

At least $US10 million was stolen from an unnamed bank in Ukraine, though analyst reports suggest dozens of Ukrainian and Russian banks were victims of the same syndicated attack, with hundreds of millions of dollars stolen in total.

How did the hackers carry out the SWIFT attack on the Ukrainian bank?

Instead of breaching the SWIFT core system directly, the hackers used advanced malware to steal the credentials of bank employees, then exploited vulnerabilities in the access points to SWIFT. The stolen credentials allowed them to send fraudulent messages through the SWIFT messaging network, initiating cash transfers from accounts at larger banks to disparate accounts around the world.

How does the Ukraine SWIFT hack compare to the earlier Bangladesh heist?

The article notes that the Ukraine bank theft was carried out in a similar way to the Bangladesh Central Bank theft in February 2016, following the same modus operandi used by the cyber criminals in each case.

What criticism has been directed at Ukraine's banking sector according to the article?

Ukraine's banking sector has come under repeated criticism for failing to implement up-to-date security standards and for a slew of other allegedly bad practices.

What makes these SWIFT-related hacks particularly notable, according to the article?

The article states these hacks are extraordinary due to the enormous amount of money involved, the ambitious choice of target, the impressive technical prowess, the significant investment in groundwork (more than a year in some cases), and the intimate knowledge of the banking system demonstrated by the hackers. Even months after the theft, much remains unknown about the perpetrators, their origin and their methods.

What motivates cyber criminals according to the article, beyond financial gain?

While financial gain is the most common motivator, the article notes that cyberattacks against government organisations aim to extract high-value intellectual property or gather intelligence, and some hackers are motivated by the thrill of hacking famous organisations or individuals, citing examples like the hacking of Mark Zuckerberg's Twitter and Pinterest accounts and Sundar Pichai's Quora account.

Why are hackers increasingly targeting smaller organisations, per the article?

The article explains that although the financial return may be smaller than in banking, small business security is easier to bypass, staff are less educated on hacking and social engineering, and the overall risk to attackers is much lower—making low-return attacks both viable and profitable.

What is 'Hacking as-a-Service' as described in the article?

The article describes an extreme variation where cyber criminals provide malware and hacking services 'as-a-Service,' operating like legitimate organisations by offering rate cards for services such as hacking emails, websites and networks, spying, and deploying DDoS attacks, along with extensive support and discounts for repeat customers.

What statistic does the article cite from IBM regarding targeted industries and security incidents?

According to a report by IBM cited in the article, the most targeted industries in the previous year included healthcare, manufacturing and government organisations worldwide, with the average company experiencing a 64 percent increase in the number of security incidents reported.

What does the article recommend organisations do to improve their cyber security posture?

The article states that every company needs a multipronged security strategy that extends beyond annual penetration testing and audits, and it recommends contacting the blueAPACHE account team for more information on an organisation's current vulnerability level and ways to improve security posture.

Images on This Page